Five actions to secure organisation networks and infrastructure

Maintain ongoing security
Piecemeal, annual security training for employees just isn’t good enough. There’s a need for constant training and intel about threats and products. Business leaders need to continuously monitor their estate to spot breaches and respond quickly to alerts.
They need to get the basics right, such as pro-active security patching and integration of logs into their existing solutions. Then, they need to avoid data loss and to remain compliant as they migrate services to the cloud.
To maintain security, exercises such as “assume breach” − expecting a sophisticated attacker will find a way into your estate and manage to stay hidden for some time − can reduce the risk of an organisation becoming complacent about its IT security. Assuming the attacker is already inside changes your goal to making it harder for them to move about - and easier for you to detect. “Wargaming” (a simulated cyber incident focusing on how members of an IT department and other departments respond to an incident) can also be useful.
Now that many businesses have developed a highly distributed architecture, having visibility over their assets is even more important. “Threat management” services, the best of which combine security expertise, context-aware threat intelligence and tools to monitor (or even hunt for) and manage critical incidents can oversee your infrastructure and traffic to identify and deal with any suspicious activity that could indicate a cyber-attack.
Clarity over security threats and how to deal with them can help boost boardroom confidence in security technology and may bolster arguments for increasing security spending.
If executives we interviewed were given an immediate 20% increase in their information security budgets, what would they spend it on? Rodion Varynskyi, Director of Network Operations at J2 Global, an Internet information and services company, says that he would split the additional funds between spending on the “stability and integrity” of the company’s IT systems and data. “I’d spend the other 10% on researching more cutting-edge things, such as the best new cyber security technologies that we could use or adapt for our business. I’d focus on where our business is going in the next five years or so and any new cyber security threats on the horizon.

Rodion Varynskyi,
Director of Network
Operations | J2 Global

If given an immediate 20% increase in our information security budget, I would split the additional funds between spending on the “stability and integrity” of the company’s IT systems and data. I’d spend the other 10% on researching more cutting-edge things, such as the best new cyber security technologies that we could use or adapt for our business. I’d focus on where our business is going in the next five years or so and any new cyber security threats on the horizon.
Share this page