Why is information security necessary?
- Mar 9, 2022
- 3 min read
Updated: Mar 16, 2022
High-profile cyber attacks and data protection compliance failures have led to significant embarrassment and brand damage for organisations - in both the public and private sectors - all over the world.
An information security management system (ISMS) is necessary because the threats to the availability, integrity and confidentiality of the organisation’s information are great, and always increasing. Any prudent householder whose house was built on the shores of a tidal river would, when facing the risk of floods, take urgent steps to improve the defences of the house against the water.
It would clearly be insufficient just to block up the front gate, because the would get in everywhere and anywhere it could. In fact, the only prudent action would be to block every single possible channel through which floodwaters might enter and then to try to build the walls even higher, in case the floods were even worse than expected.
So it is with the threats to organisational information, which are now reaching tidal proportions. All organisations possess information, or data, that is either critical or sensitive. Information is widely regarded as the lifeblood of modern business. Advanced Persistent Threat (APT) is the description applied to the cyber activities of sophisticated criminals and state-level entities, targeted on large corporations and foreign governments, with the objective of stealing information or compromising information systems. Cyber attacks are, initially, automated and indiscriminate - any organisation with an internet presence will be scanned and potentially targeted.
Not surprisingly, the Pricewaterhouse Coopers (PwC) Global State of Information Security Survey 2015 said that ‘most organisations realise that cybersecurity has become a persistent, all-encompassing business risk’. This is because the business use of technology is continuing to evolve rapidly, as organisations move into cloud computing and exploit social networks.
Wireless networking, Voice over IP (VolP) and Software as a Service (SaaS) have become mainstream. The increasingly digital and inter-connected supply chain increases the pressure on organisations to manage information and its security and confirms the growing dependence of UK business on information and information technology.
While it is clearly banal to state that today's organisation depends for its very existence on its use of information and communications technology, it is apparently not yet self-evident to the vast majority of boards and business owners that their information is valuable to both competitors and criminals and that how well they protect their systems and information is existentially
important.
The 2015 PwC report stated that, although security incidents increased at a compound average growth rate of 66 per cent, security budgets were stuck at only 3.8 per cent of the total IT spend and that at most organisations the Board of Directors remains uninvolved! Perhaps it’s not surprising that, according to the UK Government's 2014 Information Security Breaches Survey (ISBS 2014), 70 per cent of organisations keep their worst security breaches secret.
There is no doubt that organisations are facing a flood of threats to their intellectual assets and to their critical and sensitive information. High-profile cyber attacks and data protection compliance failures have led to significant embarrassment and brand damage for organisations - in both the public and private sectors - all over the world.
In parallel with the evolution of information security threats, there has - across the world - been a thickening web of legislation and regulation that makes firms criminally liable, and in some instances makes directors personally accountable, for failing to implement and maintain appropriate risk control and information security measures. It is now blindingly obvious that organisations have to act to secure and protect their information assets.
‘Information security’, however, means different things to different people. To vendors of security products, it tends to be limited to the product(s) they sell. To many directors and managers, it tends to mean something they don’t understand and that the CIO, CISO or IT manager has to put in place. To many users of IT equipment, it tends to mean unwanted restrictions on what they can
do on their corporate PCs. These are all dangerously narrow views.


Comments