Everyone, from the small business owner, to senior enterprise executives are confronting a seemingly insurmountable problem: Fixed and rising cyber security breaches. It appears no matter what we do, there’s always somebody that was hacked, a new vulnerability exploited, and thousands and thousands of dollars lost.

In an effort to stem the tide folks have tried everything: From throwing money at it by buying the latest and greatest tech gizmos promising security, to outsourcing cyber security administration, to handing it over to the IT folks to deal with it. And, every time the result is money misplaced, productivity decreased, and the attacks continue.

Many enterprise folks complain that we’re not just dropping a battle right here and there. We’re shedding the war. Is that true? The reality is that those that keep losing their cyber battles and risk shedding the war are making three critical mistakes:

1. They think cyber security is a technology problem.

2. They comply with a cyber security check list once-and-done.

3. They don’t have a cyber security awareness training program in place.

First, cyber security isn’t a technology problem. Removed from it. It’s a enterprise-critical problem, and more importantly: It’s a people problem, and we have to address it at that level.

Second, cyber security is a consistently evolving battlefield. The threats evolve, the attacks take new paths, the underlying applied sciences change. A static check list solves yesterday’s problems, not immediately’s, and certainly not tomorrow’s.

Finally, if people don’t understand the threat they will not even see the attack coming, a lot less be able to respond and protect themselves. Cyber security awareness training is the only way to arrange everyone for the new reality we live and work in.

Remember: Cyber security isn’t an IT problem. It is a risk management problem, a stay-in-enterprise problem. This is less complicated to understand in you work in a regulated industry. There, the concept, language, even governance of risk administration is a part of the day by day lexicon.

Not so with small and mid-market business less familiar with the risk management function. It doesn’t assist that the very nature of the menace and the way the “payload” of the attack is delivered is by way of info technologies. It almost makes sense to have IT deal with cyber security. However the victims should not the computers. The victims are the businesses and their people.

More importantly: An organization’s Info Technology generates Value. It does so a myriad different ways depending on the business you’re in, from the actual delivery of products to clients (e.g. software businesses, data companies, media and technology businesses etc.) to complementing, enhancing, and realizing the mission and vision of the company (law firms, manufacturing, logistics, healthcare, etc.)

Cyber security, like all risk management, is there to protect value. Therefore, you’ll be able to never have cyber security (the value protector) report to IT (the value creator). That creates a conflict of interest. Just like IT reports directly to the CEO, so must cyber security. They are parallel tracks keeping the enterprise train aligned and moving.

After you have the reporting structure accurately in place, you should empower it with executive buy-in and engagement. Cyber security wants your direction on company goals and risk appetite so they can develop the precise strategy to protect the corporate’s assets. Cyber security professionals, working with the board and executives, together with IT and enterprise units, will develop the correct defense-in-depth strategy that’s right for the company.

For those who have any kind of questions about wherever and also tips on how to employ Information Security United Kingdom, it is possible to contact us with our web site.

Leave a Reply

Your email address will not be published. Required fields are marked *

Registration option not enabled in your general settings.