The Information Security landscape
- Mar 9, 2022
- 3 min read
Updated: Mar 14, 2022
Faced with constant and fast-evolving threats to information security, and with a growing exposure to cyber risk, managers at all levels and in organisations of all sizes need a robust IT governance system.
The proliferation of increasingly complex, sophisticated and global threats to information security, in combination with the compliance requirements of a flood of computer- and privacy-related regulation around the world, is driving organisations to take a more strategic view of information security. It has become clear that hardware-, software- and/or vendor-driven solutions to individual information security challenges are, on their own, dangerously inadequate.
While most organisations believe that their information systems are secure, the brutal reality is that they are not. Not only is it extremely difficult for an organisation to operate in today's world without effective information security, but poorly secured organisations have become risks to their more responsible associates.
The extent and value of electronic data are continuing to grow exponentially. The exposure of businesses and individuals to data misappropriation (particularly in electronic format) or destruction is also growing very quickly. Ultimately, consumer confidence in dealing across the web depends on how secure consumers believe their personal data are.
Data security, for this reason, matters to any business with any form of web strategy (and any business without a web strategy is unlikely to be around in the long term), from simple business-to-consumer (b2c) or business-to-business (b2b) e-commerce propositions through enterprise resource planning (ERP) systems to the use of email, social media, mobile devices, Cloud applications and web services. It matters, too, to any organisation that depends on computers for its day-to-day existence or that may be subject (as are all organisations) to the provisions of data protection legislation.
Newspapers and business or sector magazines are full of stories about criminal hackers, viruses, online fraud, cyber crime and loss of personal data. These are just the public tip of the data insecurity iceberg. There is growing evidence of substantial financial losses amongst inadequately secured businesses and a number of instances where businesses have failed to survive a major disruption of their data and operating systems. Almost all businesses now suffer low-level, daily disruption of normal operations as a result of inadequate security.
Many people also experience the frustration of trying to buy something online, only for the screen to give some variant of the message 'server not available’. Many more, working with computers in their daily lives, have experienced (once too) many times a local network failure or outage that interrupts their work. With the increasing pervasiveness of computers, and as hardware/software computing packages become ever more powerful and complex, so the opportunity for data and data systems to be compromised or corrupted (knowingly or otherwise) will increase.
Information security management systems (ISMSS) in the vast majority of organisations are, in real terms, non-existent, and even where systems have been designed and implemented, they are usually inadequate. In simple terms, larger organisations tend to operate their security functions in vertically segregated silos with little or no coordination. This structural weakness means that most organisations have significant vulnerabilities that can be exploited deliberately or that simply open them up to disaster.
For instance, while the corporate lawyers will tackle all the legal issues (nondisclosure agreements, patents, contracts, etc), they will have little involvement with the data security issues faced on the organisational perimeter. On the organisational perimeter, those dealing with physical security concentrate almost exclusively on physical assets, such as gates or doors, security guards and burglar alarms. They have little appreciation of, or impact upon, the ‘cyber' perimeter.
The 1T managers, responsible for the cyber perimeter, may be good at ensuring that everyone has a strong password and that there is internet connectivity, that the organisation is able to respond to malware threats, and that key partners, customers and suppliers are able to deal electronically with the organisation, but they almost universally lack the training, experience exposure adequately to address the strategic threat to the information assets of the organisation as a whole. There are many organisations in which the IT managers subjectively set and implement security policy for the organisation on the basis of their own risk assessment, past experiences and interests, but with little regard for the real business needs or strategic objectives of the organisation.


Comments