Blog: Cybersecurity month October: Keep your colleagues alert

Blog: Cybersecurity month October: Keep your colleagues alert

2023-10-03 | Blog| Ronald VerbeekMonday 02 October 2023

For several years now, October has been cybersecurity month. Bring the topic to the attention of your colleagues too; cybersecurity concerns us all!

Digital technology and networks (cyber) offer a very attractive way for malicious actors to put pressure on almost any organisation. After all, from a protected location, the whole world can be reached. Moreover, many systems are vulnerable, due to poor security of the technology itself, incorrect implementation, overdue maintenance, inattentive use or a combination of these. In addition, detecting and bringing these malicious actors to justice is extremely complicated.

The motives of malicious actors can mostly be grouped under the headings of 'demanding attention' or 'exerting pressure'. Drawing attention, for example, is about demonstrating the actor's skill, or his ideological goal. Exerting pressure often involves obtaining money or getting the attacked organisation to change its behaviour. To exert pressure, for example, ransomware is deployed, a denial-of-service attack is carried out or (threatened with) sabotage. And even if your organisation is not the target of an attack, it can still become a victim, for example because an attack is deployed in an untargeted way, or because a chain partner is affected by the attack and unavailable. In short: every organisation is a potential victim of cyber misfortune and should prepare accordingly.

What to do.
There are many tools outlining how to approach cybersecurity, from standardised ISO standards and NIST frameworks to lists of basics. They roughly boil down to the following:

  • Know what you need to protect: what are malicious actors potentially after and what knowledge and systems are crucial for your organisation to continue to exist. In other words, what are your assets to protect?
  • Make a plan to protect these assets from cyber threats. Outline measures you should take, and in what order. A roadmap. Keep in mind that this will not be a static plan, threats evolve and your plan should take that into account: cybersecurity is an arms race!
  • Keep an eye on your assets. Know what is normal behaviour in your organisation and its digital systems, make sure you spot deviant behaviour quickly and can assess whether it is harmful behaviour or not.
  • Make sure there is a plan for when something does happen that disrupts normal operations. How will you act then, which parties do you need and how do you reach them? Practice this also with the colleagues involved.
  • Evaluate incidents and learn from them, adjusting systems, responsibilities and processes if necessary.

Who is next up?
We all are. Everyone who works with digital technology has a role, even if only to alert experts in case of deviant behaviour. Directors and internal supervisors also have clear roles, including around ensuring cyber security policies, culture and investment. It is important that roles are defined and that everyone knows clearly what role(s) they have. Only then can you be in control.

This blog is a summary of a more extensive article written primarily for directors. Share it with them and so give cybersecurity month a push in your organisation too!

I wish you a safe and resilient month!

Ronald Verbeek
Director
CIO Platform Nederland

« Back

More news

Quite some attention for VMware letter

2023-06-26 | NB | CIO verenigingen roepen Breton op tot actie EUCS voorstel brengt grote gevolgen voorFriday 05 April 2024 The four CIO associations' joint letter to the European Commission regarding the impact of Broadcom's acquisition of VMware on our members, has generated a lot of interest. full story

ICT experts, entrepreneurs and scientists shared their insights with State Secretary Alexandra van Huffelen.

ICT-experts, ondernemers en wetenschappers deelden hun inzichtenThursday 28 March 2024 27th of March, ICT experts, entrepreneurs and scientists shared their insights with State Secretary Alexandra van Huffelen and us on how to be less dependent on non-European countries for cloud services and to become stronger in this technology ourselves. full story

Business IT users condemn Broadcom's market behaviour and call on European Commission for appropriate action

2023-06-26 | NB | CIO verenigingen roepen Breton op tot actie EUCS voorstel brengt grote gevolgen voorThursday 28 March 2024 Today, CIO Platform Netherlands and its three European sister associations sent a joint letter to the European Commission following possible market-distorting behaviour by Broadcom since its acquisition of VMware. full story

Arjen Boersma and Edward Cox join the board

2024-01-11 | Nieuwe BestuursledenThursday 28 March 2024 We would like to welcome Arjen Boersma, CIO ProRail and Edward Cox, CIO Louwman Group, to the board of CIO Platform Nederland. full story

View all news items through the archive

Close