A high-level executive does not need to know everything about cybersecurity in a corporate network, but he or she has legal responsibility and must be aware of the realities of the company in which he or she works.Thinking in this context, Vernon Poole, head of business consultancy Sapphire and former head of security at Deloitte Europe/UK, has prepared some advice for executives who are concerned about the cybersecurity of their networks and who are interested in collaborating on data management.
1- Align IT with business strategies
The first is to create and maintain a corporate security system policy, aligned with corporate priorities. The leader must show commitment to this policy and reinforce the need for good communication between the departments involved.
2- The leader must support the company security system policy
It is necessary to explicitly support this process because the rules and controls that will be implemented will impact people’s power and require new responsibilities. Furthermore, it has the role of promoting a common understanding on the importance of security issues. This means that its role is also to ensure that the company understands the main definitions of security. Keywords like requirements, vulnerabilities, and threats provide practical and educational examples to discuss with your team.
3- Establish a risk management policy
Poole’s advice also includes the need to establish a risk management policy, defining what is tolerable and what is above expected limits. The idea is for the company to create a table highlighting the risks it is vulnerable to, the options for resolving them, and who would be responsible for finding a solution if the threat materializes. In addition to raising awareness among collaborators, the table anticipates possible crisis risks on the network.
4- Continuously monitor the network infrastructure
Another role of the leader is to continuously identify and monitor infrastructure components and know the right time to upgrade or invest in new equipment.
5- Clear and transparent relationship with people who are not part of the team
In relation to suppliers and outsourcers, leaders must have clear and transparent communication to increase cooperation between parties and explore exactly the needs of the business.
6- Know your equipment and what the main data emptying points are
Internally, with his team, the leader must be aware that the insider – collaborator who has access to privileged information in companies – can be the main source of risks to the security of company data and that too many collaborators are largely responsible for sharing company information, even if they do not know what they are doing. Other ways to empty company information are attacks by criminals and bad actors.
7- Pay attention to legal requirements
Finally, the business owner must be attentive to the legal and regulatory requirements that affect their IT business, such as data privacy, copyright, piracy and internal control requirements.
8- Have an IT specialist by your side
This executive must have a manager who specializes in the area at his side to assist him in the decision-making process. He is the professional who will ensure that the company security system policy is adequate for the objectives of the organization and, consequently, meets the needs of all the staff involved; Make a plan and monitor those actions. This professional can be the security manager and must be a person trusted by the manager, once analyzing the problems at the source, creating alternatives and proposing specific solutions to the vulnerable points and with investments appropriate to the risks.
This professional must act with agility and be able to plan integrated security systems, as well as execute strategic policies for the protection of company information. Perform risk analysis, create a technical plan for the daily management of a company. He is a professional who must be updated on market developments and who can be a consultant on security issues.
In summary, to implement a corporate security system policy, the leader needs to know the entire corporate context, even if he is not a specialist. It is necessary to know the regulations, involve the team in network security issues, be attentive to the system infrastructure, also have clear communication with suppliers and outsourcers, as well as constantly carry out internal and external analyzes of the vulnerabilities and risks that companies are facing
latest posts published
Personal Branding or cult of personality?
6 Key SEO Steps Before Launching a New Website
Communicating during the financial crisis
11 good resolutions to give a boost to your 2019
It all starts with an idea
6 marketing and creativity books to read this year!
Content Marketing: Do You Really Have to Offer All Your Content?
Entrepreneurs and content marketing: 16 quotes to encourage you
9 tips to increase your blog audience!
