Blog
The need for a 'cyber defense strategy'
By Walter de Kok

It is every business owner's worst fear. You arrive at work in the morning and switch on your computer. You cannot get into the system and nothing works the way it did. A message appears on your screen telling you to pay a hefty sum to regain access to your systems and data.
Attackers are getting smarter, and criminal groups are becoming larger and more professional. According to the National Coordinator for Security and Counterterrorism, more and more companies and organisations are facing a serious threat. Ransomware, but also data breaches, are increasingly becoming a major problem. Below you will find an overview of the various risks you run as a business.

Consequences
Financial damage
The consequences range from paying a ransom to regain access to systems, to production facilities grinding to a halt, to paying to protect the data of staff. Criminals lock networks and only release them once a ransom has been paid. Ransom demands vary from 0.5% to 2% of turnover, which often comes to large sums. On top of that, rebuilding the IT system so that people can get back to work is very complex and expensive for companies.
Reputational damage
News reports about attacks like these often lead to negative publicity. A company becomes known as one that does not have its security in order. Nobody wants to do business with a company like that any more, which makes the financial damage described above even greater.
Loss of trust
As an organisation, you spend years building your relationships with customers and partners. If they are not satisfied with the level of the measures you take to protect their data and systems, they lose trust and go looking for another party that does have this in order.
What can you do?
Network security: Securing a computer network against intruders, whether targeted attackers or opportunistic malware.
Application security: focuses on protecting software and devices against threats. An infected application can give access to the very data it was designed to protect. Successful security starts in the design phase, well before a program or device is installed.
Information security: protects the integrity and privacy of data, both in storage and in transit.
Operational security: covers the processes and decisions for handling and protecting data assets. The permissions users have when they connect to a network and the procedures that determine how and where data is stored or shared are topics that fall under this category.
Disaster recovery and business continuity is the category that defines how an organisation responds to a Cybersecurity incident or any other event that causes a loss of operations or data. Disaster recovery policy sets out how the organisation restores its operations and information to return to the same operating capacity as before the event. Business continuity is the plan the organisation can fall back on while it tries to operate without certain resources.
End-user training addresses the most unpredictable factor in Cybersecurity: people. Anyone can accidentally introduce a virus into an otherwise well-secured system by not following good security procedures. Users learn to delete suspicious email attachments, not to plug in unidentified USB drives and various other important lessons that are crucial to the security of any organisation.
Cyber Defense Strategy
Developments have meant that no business can do without an IT system any more. Unfortunately, this also means that every business is vulnerable to a cyber attack. Businesses need to defend themselves against threats and invest enough in security. Prevention is better than cure. Stop your business from being held hostage by having the right cyber defense strategy in place.
Want to be sure your business is secure? Feel free to contact us.
Wondering what Infodatek can do for you?
A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.
