The moving target of data security

We’ve covered data security extensively on this blog, including questions of disaster recovery, resilience, and how to use archiving and backups to better organize your organizations’ data with security in mind. One thing that isn’t necessarily clear, though, is how the moving target of data security changes considerations on the fly.

Why is data security a moving target?

Keeping your data safe and secure seems a simple and logical step in the modern day. But for many organizations, this ends up not being so simple at all. The issue is severalfold:

  1. Setting up a secure set of systems to store, manage and categorize your data is not necessarily a cheap endeavor. Once that system is in place, the costs involved mean there’s some degree of lock-in and changing things is rarely on the cards.
  2. Organizations may keep on rolling with their existing infrastructure so long as it seems to work well enough – they rarely change until some force acts on them and impels that change, be it legal action, government mandate or an active cyberattack.
  3. Figuring out what priorities to target and what gaps are acceptable is a large portion of preparing your organization’s cybersecurity posture.
  4. This is the big one – threats, defenses and detection are continually evolving around one another. It’s difficult to ever state you’re secure because the nature of the threat you face may have changed without you even knowing.

Is there such a thing as being safe?

The simple answer is – No. Safety is never going to be an absolute metric or measure. With sufficient resource investment and effort expenditure, any system can be breached. A decent example is the claimed recent attack on a CyrusOne data center, where the point of failure appears to have been the building itself.

Instead, it is significantly more productive to speak in terms of cyber risk appetite – the degree of risk you are willing to expose yourself to. Or in other words, the amount of effort and resources you are willing to expend to make yourself safe, and what opportunities you are willing to let slip past you because they’d expose you in some way.

As touched on in this Cybernews article, this is not something that is necessarily well understood or communicated by organizations out there. This makes hitting the moving target of data security all the harder, since the desired end state is not well defined.

What can we do differently?

  • Define your risk appetite – what compromises are you willing to make, when and why?
  • Keep aware of developments in the field – this will allow you to take steps proactively.
  • Allocate a budget to your security – invest into your future.
  • Ensure that you have a disaster recovery plan and a system capable of executing it.

 

Your Data in Your hands – With TECH-ARROW

by Matúš Koronthály

Image generated by Canva