APRIL - JUNE 2022CIOAPPLICATIONSEUROPE.COM8IN MYOPINIONs technology evolves, new threats emerge. Even though such changes are quite fast and frequent the basic principles for IT Security function hold. In my opinion, the fundamental one, at least for commercial enterprises, stays solid - IT Security needs to be the business enabler that allows for avoiding threats and pursuing new opportunities in risk acceptable way.Just to refer to the most recent example Covid-19 was a unique situation for the whole IT. The logistics industry was no different here. Thousands of people were forced to start working remotely. Technology allowed for this transition in a relatively secure manner. IT Security's focus was to ensure IT services availability and data protection. In most cases, it went so smoothly that users didn't question why this was even possible. Success was secured by a combination of multiple factors just to name ­ reliance on cloud services, centralized identity management, transparent cloud VPN. The other aspect that proved value was the IT Security Awareness Program that helped users to find themselves in a new situation or find an acceptable response to new threats.Focusing on the last one. End-user awareness, at all levels of an organization, is still and will be the biggest challenge to IT Security. Basically,users demand more and more functionalities, easy ways to use technology. Unfortunately, they do not know how to do it properly or just make simple mistakes. Technology that allows protecting data became so transparent that for some is hard to recognize what is acceptable. Just to add, due to the current situation, users working from remote locations are missing direct IT support contact or without the supervision of more experienced colleagues have the challenge to recognize threats.Challenging is also a constant increase of devices like mobile computers, mobile telephones, smartwatches, basically the "Internet of Things" (like IoT) that allow us to access information. Obviously, from a risk management perspective, we can block access to functionalities. Unfortunately, these functionalities are just "what our business wants." This makes the whole IT environment extremely complex, its configuration volatile and hard to control. This makes users even more vulnerable ­ we do not need zero-day hacks as long as we can use social engineering to persuade users to give us what we want. That is why we see an increasing number of such incidents like phishing or surprisingly USB device-related attacks. Both of them are quite cheap to execute in comparison to potential gain for the adversary in case the enterprise is successfully compromised.The Talent shortage we struggle with in IT Security does not help here. I believe the whole THE FUTURE FOR IT SECURITY WILL BE CHALLENGINGMICHAL NIEZURAWSKI, HEAD OF GLOBAL IT SECURITY COMPETENCE CENTER, DB SCHENKERATechnology that allows protecting data became so transparent that for some is hard to recognize what is acceptable
< Page 7 | Page 9 >