| | November 2021ENTERPRISE SECURITY8IIN MY OPINIONn the cyber world, a continuous war is playing out between the Defender and the Attacker (White hat and Black hat). The job of the defender is to ensure safeguards are in place to prevent, detect or recover from cyber-attacks and data breaches. These safeguards cover Process, People and Technology. As defenders improve safeguards, the attackers evolve their game plan to target the weakest defences. For example, the defender may reduce their patching cadence to 72 hours (process) and implement machine learning based intrusion detection (technology), but if staff security awareness remains weak, then social engineering will become the predominant attack vector.The 2021 Verizon Data Breach Investigations Report highlights that 85 percent of data breaches involved a human element. By human element, they mean actions such as phishing attacks, using easily guessed passwords and human error. Similarly, the Cloud Security Alliance (CSA) recently released a report on the top cloud security threats The Egregious 11. According to this report, the biggest threats now come from issues like misconfigurations and insufficient identity and access management, where the customer is solely responsible for security. For example, a By Steve Williamson, Head of Internal Audit for Information Security and Data Privacy, GSKIn today's hyper-connected world, organisations build their cyber defence using layers of safeguards covering People, Process and TechnologySteve WilliamsonStrengthen Cyber Defences Through Culture Change
<
Page 7 |
Page 9 >