All articles

Cybersecurity 2023: five measures that protect your organisation against the latest developments

When it comes to cybersecurity, many organisations cannot see the wood for the trees. What matters? What makes sense?

Thinking you are safe when you are not. It happens more often than you think. For example, Maersk's entire global transport operation was brought down by Russian-Ukrainian ransomware that went undetected. This NotPetya hack caused panic in Maersk's unsuspecting IT department, which saw all systems freeze after a routine upgrade.

How could Maersk have prevented this? And what awaits us in the future? Russia and China have, after all, proved unreliable and harbour armies of professional hackers operating under government protection.

Given these developments, the following cybersecurity measures are essential for a future-proof IT security policy:

  1. Examine your digital chains and guard against single points of failure
    Today, business processes depend almost entirely on IT. Everything is connected, synchronises with the cloud and processes data automatically. The security and privacy regulations businesses must meet are also very complex. An overview is often missing too: what runs where, and who can access it? Organisations depend on these digital chains. A single vulnerable entry point can affect a whole series of systems. Check whether your organisation has mapped these chains; if not, do so quickly.
  2. Secure access to scarce IT security knowledge
    Employees with cybersecurity knowledge are scarce. Meanwhile, companies are automating business and IT processes at a frantic pace, with cybersecurity continuing to play an important role. People with knowledge of and responsibility for IT security have more and more to do and need more specialist knowledge. Start by finding a reliable, specialist IT partner with the necessary expertise who keeps learning about your developments, wishes, challenges and market. Then bring in enough IT security knowledge. This can be through partners or temporary specialist external staff.
  3. Be prepared for demand for innovation from within the organisation
    Robotics, machine learning and big data bring valuable innovations and greater efficiency. More and more people work through external, hybrid cloud-based delivery models. Unfortunately, this also affects security: how do you maintain oversight of these new technologies? You need to stay on top of developments, prepare the organisation for future questions and meet employees' wishes and needs while maintaining cybersecurity.
    PRO TIP: draw up a list of minimum information security requirements for software and suppliers.
  4. Do not simply buy a new security solution out of fear or uncertainty
    More and more providers are adding their own flavour to cybersecurity. As a customer, you can no longer see the wood for the trees. Sometimes that flavour adds value; sometimes it is old wine in new bottles. Take a step back and assess whether the features really solve a problem. Also ask whether you already have enough equipment that you could use more effectively. Which measures would immediately increase the organisation's cyber resilience most? And perhaps most importantly, do you have enough people and/or expertise in-house to manage that equipment optimally and extract the right information? Unless you answer these basic questions first, you are more likely to fall for unnecessary cybersecurity measures that prey on your concerns.
  5. Do not rely on insurance alone: it can make cybercriminals see your organisation as a target
    Insuring against hacking can actually attract hackers' attention. This has not been scientifically proven, but incidents are known in which hackers realise that an organisation's insurance against hacking means money is assured. But money is not the only issue. Anyone who knows that Hof van Twente spent two years clearing up after a hack knows that the insurance payout was only a sticking plaster. Insurance can cover residual risks. First study the policy conditions, because if you have not secured things properly, you receive nothing. Use the insurance as a guide to check whether you meet basic cybersecurity requirements.

Conclusion: secure cybersecurity without a false sense of security

We see many organisations with tools and dashboards offering options for problems that do not exist. Meanwhile, there are real-time vulnerabilities that can easily be resolved with common sense and expert advice. Our standard advice is therefore always to start by listing what you already have and the specific threats to your organisation, employees, customers, locations, software and products. This gives you the greatest return on IT security without expensive overprotection.

A false sense of security is the area between underprotection and overprotection. Underprotected, you unknowingly run an enormous risk. Overprotected, you incur far too many costs. First go back to the drawing board and map the IT and processes you have, your dependencies and where your greatest risks currently lie. Then examine which cybersecurity measures are already running and whether you could use them more effectively or intelligently.

Want to get started yourself?

Request our checklist to analyse how your organisation can better defend itself against cybercriminals.


Back to all articles