OCTOBER 2020ENTERPRISE SECURITY| | 19CIO INSIGHTSBy Ramón Serres, CISO, AlmirallThere is a lot of literature on Cybersecurity nowadays, and therefore it is really a challenge to provide value when writing an article. The following lines go straight into that precisely, into that sort of advice that comes along experience, successes and failures. Probably the sort of recommendations I would like to receive if I now started my career in Cybersecurity. This is for sure far from a complete CISO guide. It doesn't intend to be so. Missing the big pictureThere is a clear risk of missing the big picture in terms of risk. And missing the big picture may drive you to make the wrong decisions, overstating the importance of something that from a global perspective is not so important, overseeing a risk that is outstanding from a global perspective. This goes to the very core or risk management.The recipe to this is to constantly make the effort of maintaining the big picture in mind. And even if we may have to drill down to fully understand a certain risk, always go back to putting things into the whole perspective of how important is this risk in the complete risk map of the company. Call it relativisation if you want. Forgetting the basicsFortunately enough, there is a huge amount of very valid information going around the internet and professional social media like linked-in that can help companies to address their information security risks, particularly for SME where there is very limited budget or no budget at all to spend on security consulting. All the better for those who can't afford a Consulting firm. But the point is: are you putting into practice all this good advice. E.g. You hear about patching, you hear about personnel awareness as the first line of defence. Eight Common Pitfalls in Cybersecurity
<
Page 9 |
Page 11 >