top of page

The nature of information security threats

  • Mar 9, 2022
  • 2 min read

Updated: Mar 17, 2022

Information security threats are a 'clear and present danger', and strategic responsibility for ensuring that the organisation has appropriately defended its information assets cannot be abdicated or palmed off on the CIO, CIOS or head of IT.


Data or information is right at the heart of the modern organisation. Its availability, integrity and confidentiality are fundamental to the long-term survival of any 21st-century organisation; in survey after survey, 9 out of 10 organisations make this claim. Unless the organisation takes a comprehensive and systematic approach to protecting the availability, integrity and confidentiality of its information, it will be vulnerable to a wide range of possible threats.


These threats are not restricted to internet companies, to e-commerce businesses, to organisations that use technology, to financial organisations or organisations that have secret or confidential information. They affect all organisations, in all sectors of the economy, both public and private. They are a 'clear and present danger', and strategic responsibility for ensuring that the organisation has appropriately defended its information assets cannot be abdicated or palmed off on the CIO, CIOS or head of IT.


In spite of surveys and reports which claim that boards and managers are paying more attention to security, the truth is that the risk to information is growing more quickly than boards are recognising. The 2015 Verizon Data Breaches Report gathered data from 80,000 data breaches (which occurred in a 12-month period) across the world to conclude that 700 million compromised records were the cause of financial losses of some $400 million.


Information security threats come from both within and without an organisation. The situation worsens every year, and cyber threats are likely to become more serious in future. Cyber activism is at least as serious a threat as is cyber crime, cyber war and cyber terrorism. Unprovoked external attacks and internal threats are equally serious. It is impossible to predict what attack might be made on any given information asset, or when, or how.


The speed with which methods of attack evolve, and knowledge about them proliferates, makes it completely pointless to take action only against specific, identified threats. Only a comprehensive, systematic approach will deliver the level of information security that any organisation really needs.


It is worth understanding the risks to which an organisation with an inadequate ISMS exposes itself. These risks fall into three categories:


  • damage to operations;

  • damage to reputation;

  • legal damage.


Damage in any one of these three categories can be measured by its impact on the organisation's bottom line, both short and long term. While there is no single, comprehensive, global study of information risks or threats on which all countries and authorities rely, there are a number of surveys, reports and studies, in and across different countries and often with slightly differing objectives, that, between them, demonstrate the nature, scale, complexity and significance of these information security risks and the extent to which organisations, through their own complacency or through the vulnerabilities in their hardware, software, and management systems, are vulnerable to these threats.

 
 
 

Recent Posts

See All

Comments


bottom of page