Design for the users, not against them

Issue 4 2021 Editor's Choice, Information Security, Infrastructure

Security remains a critical priority for the modern organisation. The radical increase in attacks throughout the course of 2020, thanks to the surge to work from home and an explosion of unplanned business vulnerabilities, has taken its toll. The Mimecast State of Email Security 2020 report found that six out of 10 companies experienced a ransomware attack, there was a 64% increase in email threats and 79% of organisations were negatively impacted by their cybersecurity limitations. The threat actors are perpetually testing new threat vectors and no organisation, no sector and no industry is safe.


Henk Olivier.

This constant pressure has ignited even deeper industry interest into solutions that embed the principles of security by design. Principles that engineer software, systems, hardware and platforms for security from the foundation upwards. That ensure every part of the security system is designed to connect with the others, mitigating the risk of siloes and unexpected vulnerabilities, while allowing for a more elastic approach to overall security posture.

Security with users in mind

Security by design starts with IT security. Here, in the bowels of the system and infrastructure, is where the security of the business should be designed around the user, making access more efficient and capable. Users are possibly the greatest threat to any organisation’s security and their education, training and access must be constantly managed and monitored to ensure the business remains tightly shut to attack. The so-called human firewall is ultimately managed by ongoing training and awareness, but it is supported by a security system that puts the user at the heart of the experience.

To fully realise the challenges that may lie in your organisation and to create a security posture that is relevant to your unique requirements, start with a cybersecurity audit. This will unpack the risks that your company faces, expose potential holes and vulnerabilities and help you to fully realise the scale of your security investment. An audit can be used as both a short- and long-term springboard from which to evolve security investment and strategy and should be undertaken on a regular basis to ensure that new vulnerabilities or unexpected holes are caught and plugged.

Security by design is not exclusively for the enterprises that leverage the Internet of Things (IoT), artificial intelligence (AI), automation and robot process automation (RPA), but it certainly is critical for industries that do. Manufacturing, mining, supply chain, logistics: companies in these sectors that are looking to embrace these emergent technologies to improve processes and streamline expenditure, must pay close attention to security at every touchpoint and layer of their implementation.

For organisations looking to evolve their security best practice and to shore up the defences over the coming year, adopting a security by design approach can transform long-term spend and security posture. By unpicking every knot and redefining the foundational factors that make up your security systems and approaches, you can strengthen your stance and significantly improve your company’s ability to fend off attack. Ultimately, this is not security that’s slapped on at the end of the technology implementation process, it is security woven into the fabric of the organisation and that’s capable of evolving to meet changing demands, security parameters and attack vectors.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AI-enabled tools reducing time to value and enhancing application security
Editor's Choice
Next-generation AI tools are adding new layers of intelligent testing, audit, security, and assurance to the application development lifecycle, reducing risk, and improving time to value while augmenting the overall security posture.

Read more...
2024 State of Security Report
Editor's Choice
Mobile IDs, MFA and sustainability emerge as top trends in HID Global’s 2024 State of Security Report, with artificial intelligence appearing in the conversation for the first time.

Read more...
Cyberthreats facing SMBs
Editor's Choice
Data and credential theft malware were the top two threats against SMBs in 2023, accounting for nearly 50% of all malware targeting this market segment. Ransomware is still the biggest threat.

Read more...
Are we our own worst enemy?
Editor's Choice
Sonja de Klerk believes the day-to-day issues we face can serve as opportunities for personal growth and empowerment, enabling us to contribute to creating a better and safer environment for ourselves and South Africa.

Read more...
How to spot a cyberattack if you are not a security pro
Editor's Choice
Cybersecurity awareness is straightforward if you know what to look for; vigilance and knowledge are our most potent weapons and the good news is that anyone can grasp the basics and spot suspicious activities.

Read more...
Protecting IP and secret data in the age of AI
Editor's Choice
The promise of artificial intelligence (AI) is a source of near-continuous hype for South Africans. However, for enterprises implementing AI solutions, there are some important considerations regarding their intellectual property (IP) and secret data.

Read more...
Super election year increases risks of political violence
Editor's Choice
Widening polarisation is expected in many elections, with terrorism, civil unrest, and environmental activism risks intensifying in a volatile geopolitical environment. Multinational businesses show an increasing interest in political violence insurance coverage in mitigation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
Enhance control rooms with surveillance and intelligence
Leaderware Editor's Choice Surveillance Mining (Industry)
Dr Craig Donald advocates the use of intelligence and smart surveillance to assist control rooms in dealing with the challenges of the size and dispersed nature common in all mining environments.

Read more...