
![]() |
Tips for C-level employees when managing IT security risksAlthough most companies have invested in IT security solutions focussing on mitigating threats like viruses and malware, many fall short of addressing more sinister risks such as fraud, identity theft and espionage. ![]() Charl Ueckermann These are damaging threats that can put a company’s reputation and business continuity at risk and can have serious financial implications. It is only when IT security-related risks are considered as business risks that the relevance of addressing them with proactive, strategic and appropriate solutions really becomes apparent – and this has to come from the top. I believe, cyber risks should be treated as business risks and should form part of a company’s overall risk management strategy. This has to be a top-down drive; from C-level employees, for whom the cost of a breach or leak is highest, to everyone else in the organisation that has access to information systems. Cybercrime is burgeoning rapidly, not only in volume but sophistication as well; while 70% of threats faced by enterprises are known, 30% are unknown, advanced threats that traditional signature-based security technologies alone cannot tackle.[1] Ransomware, a type of malware that encrypts data and either prevents or limits users from accessing their systems, is typically targeted at C-level employees as well as departments dealing with sensitive information, such as accounts and human resource departments. These types of advanced, targeted cyber incidents are becoming more prevalent – even in South Africa. For me, it becomes quite clear that organisations need a multi-disciplinary approach that is aligned with their specific risk management requirements and includes the implementation of appropriate IT security solutions, ongoing monitoring, analysis of IT security intelligence, and employee education. Regardless of how expensive or robust the IT security technologies are, they will not be fully effective unless everybody throughout the enterprise, starting at the top, understands the risks and supports the IT security strategy. Advice to C-level employeesI would like to offer some advice to C-level employees when managing IT security risks in organisations:
I want to put organisations at ease with the fact there are various computer-based training products available that leverage modern learning techniques and address all levels of the organisational structure. We must realise that every individual in the organisation using a computer is responsible for IT security, not just the IT department. And that cybersecurity awareness and education are, therefore, fundamental to the effectiveness of your risk management strategy. References:
About Charl UeckermannCharl Ueckermann currently serves as chief executive officer at AVeS Cyber Security and assists organisations with strategic IT solutions. He has more than 25 years' in-depth experience in the IT industry, specialising in banking, government, automotive, manufacturing and telecom industry verticals. He has a proven track record in IT and business strategy in the SMB and enterprise markets. View my profile and articles... |