Business Can Minimise Cybersecurity Risks And Drive Profit

An astonishing 70 percent of the companies on the Fortune 500 a decade ago are no longer listed. The reason is simple: digital disruption.

There's not a CIO on the planet today that isn't expected to deliver on the promise of digital technologies to transform customer-facing services and internal processes. This means supporting new cloud and mobile-led ways of working while controlling risk in a digital world full of menacing new threats.

To make this a reality, IT and security must come together to harmonise the twin aims of profit and risk management. Their secret weapon is none other than that frontline IT stalwart the service desk, supported by automation and endpoint management.

Adapt or Die

The cautionary tales of Blockbuster, Kodak and BHS on the one hand, and the success stories of Airbnb and Uber on the other, are perfect examples of the power of digital transformation.

It's true that the US and Europe have approached this from opposite sides: the former focused on profit and the latter on protecting consumer privacy and improving security. The post-Brexit UK sits somewhere awkwardly in the middle, depending on whether or not it harmonises its laws with Europe after the split.

Whatever the nuances, enabling new digital ways of working has undeniably led to an explosion in the number of endpoints organisations need to manage – especially mobile devices.

And this is leading to an increased risk of data loss and/or theft. The Ponemon Institute recently polled over 18,000 US IT professionals and 69 percent claimed BYOD had significantly increased endpoint risk.

Whether we're talking about enterprise mobility or other parts of the organisation, new digital ways of working introduce new risks, both from external malfeasance and insider negligence. Some 18 million new malware samples across the board were recorded in Q3 2016 alone.

Financially motivated cyber-criminals, sophisticated state-backed cyber spies and publicity seeking hacktivists all represent a major threat today.

Unpatched vulnerabilities remain a bountiful attack vector for them, and the impact of resulting breaches or service outages can be massive. TalkTalk was breached last year via a simple SQL injection bug which should have been patched. The firm has admitted that the total cost after remediation, along with the impact on trading and customer retention, could be as high as £80 million.

The insider risk can be malicious, but most often it's accidental. Something as simple as clicking on a malicious ransomware link in an email, losing a BYOD device in a bar, or downloading an unapproved app could expose the organisation to unnecessary risk. A FoI request revealed 62 percent of data breach incidents reported to the ICO in the first few months of 2016 came as a result of human error.

Arming the Service Desk

A median post-breach dwell time of 146 days in 2015 tells us that security and IT teams still don't talk to each other enough. CIOs and CISOs will have to collaborate far more closely if they're going to support digital transformation strategies effectively.

The answer is to tool up the service desk with unified endpoint management covering multiple layers of protection, to deal with the varied threats facing organisations.

This approach should include: automated patch and configuration management to enhance stability and close down attacks exploiting known bugs; app whitelisting to mitigate the risk of zero day threats; encryption to protect data if it gets into the wrong hands; tools to automatically apply security policies to removable media and all corporate and staff-owned devices; and AV to deal with ‘background noise' malware.

Automation is key here, enabling the IT team to extend security right out to all endpoints and free up individuals to focus on more critical tasks. And it's the perfect role for a service desk which has unrivalled visibility into ‘incidents', which means it's often the first to acknowledge events which may herald a serious breach/attack. It's in the right place to escalate to security teams, but on the other side, security needs close communication lines into the service desk.

The service desk is also in a great position to monitor and report on ongoing efforts, supporting compliance and even fostering a security-first culture among staff.

In the end, effective digital transformation needs to balance agility and speed on the one hand with security and compliance on the other. This won't just require automated endpoint management led by the service desk.

It will require a cultural change, an IT team willing to listen to staff and ensure any changes don't block productivity. Fail on this front, and the creeping hand of shadow IT will undo all its hard work to support the business.

SC Magazine:                    CIOs Are Neglecting Process & Most Efficient Options:

Company Boards Need To Get A Grip:

 

« Spanish Police Arrest Banking Malware Suspect
Stuxnet, Secrecy & The New Era of Cyber War »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Cyber Security Recruiters

Cyber Security Recruiters

Cyber Security Recruiters is a niche recruiting firm who finds impact players for our clients in the Information Security Space.

Cyber Security Expo

Cyber Security Expo

Cyber Security EXPO is a unique one day recruitment event for the cyber security industry.

Information Technology & Cyber ​​Security Service (STISC) - Moldova

Information Technology & Cyber ​​Security Service (STISC) - Moldova

STISC is a public institution whose purpose is to ensure the administration, maintenance and development of the information technology infrastructure in Moldova.

Information Systems Security Partners (ISSP)

Information Systems Security Partners (ISSP)

ISSP is a specialized system integrator focused on the information security needs of its corporate clients and providing best in class products and services for securing organizational information.

National Authority for Electronic Certification and Cyber Security (AKCESK) - Albania

National Authority for Electronic Certification and Cyber Security (AKCESK) - Albania

AKCESK ensures security for trusted services, in particular reliability and security in electronic transactions between citizens, businesses and public authorities.

Inavate Consulting

Inavate Consulting

Inavate Consulting are experts in defining and implementing information assurance solutions and governance frameworks. Our ISO27001 consultants are the most experienced in the industry.

Prolimax

Prolimax

Prolimax deliver innovative solutions to IT Manufacturers, Distributors, Resellers and End-users including Data Erasure and secure IT Asset Disposition (ITAD)

Cyturus Technologies

Cyturus Technologies

Cyturus Technologies delivers cybersecurity business risk quantification services using our proprietary Adaptive Risk Model (ARM).

TRU Staffing Partners

TRU Staffing Partners

TRU Staffing Partners is an award-winning contract staffing and executive search firm for cybersecurity, eDiscovery and privacy companies and professionals.

NASK SA

NASK SA

NASK SA is an integrator of telecommunications services. We provide advanced ICT security services, collocation and hosting, data centre services, and build corporate networks.

Apex Systems

Apex Systems

Apex Systems is a world-class technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions.

NANO Corp

NANO Corp

At NANO Corp, we keep your network visible, understandable, operational and secure with state-of-the-art technology.

Intuitive Research & Technology Corp

Intuitive Research & Technology Corp

Intuitive Research and Technology is an aerospace engineering and analysis firm providing services to the Department of Defense, government agencies, and commercial companies.

SektorCERT

SektorCERT

SektorCERT is the cybersecurity center for the critical infrastructure sectors in Denmark. We help detect and handle when critical infrastructure is exposed to cyber attacks.

SPYROS Information & Technology Consulting

SPYROS Information & Technology Consulting

SPYROS specializes in providing highly qualified professionals in Computer Network Operations, Signals Intelligence, Technical Training and Certifications, Network Administration and Security.

GAM Tech

GAM Tech

GAM Tech is a Managed IT Service Provider that serves small and medium sized businesses in Alberta, British Columbia, Ontario and Quebec.