Making security the Yes team

Making security the Yes team

Most organizations have had to accelerate their digital transformation strategies in the wake of COVID-19. Some in order to take advantage of emerging opportunities, and others as a survival strategy. For many companies, the need to allow most of their employees to work from home meant that priorities had to be reshuffled and new strategies devised.

For security teams, this has required re-examining the way they approach the task of keeping the organization, its people and infrastructure safe from the myriad of threats they face every day.

It’s no secret that cybercriminals are often better funded and, due to their singular focus, are often more skilled than security teams who have a broader scope and have to be able to defend against multiple attack vectors. The number of attacks is increasing on an almost daily basis and with more people working remotely, the strategies that security teams need to employ have to change.

In the past, IT security has been something of a closed group. While other parts of an organization would create their application strategy, at some point they would have to include the security team. Their task was to ensure that whatever plans were being made, they complied with the security policies that had been established. The reputation of the security team as the ‘No team’ emerged because of their mandate to ensure compliance with the policies created to protect the organization and its data.

In recent times we’ve seen a change in the way applications are developed, and security policies enforced. Instead of security being seen as a compliance check before an application is deployed, it’s become a more integral part of the application development process.

This has created a more open approach to IT security, with DevOps and Agile approaches to application development more inclusive, allowing development teams to adopt secure by design approaches. Security needs to be part of the design from day one, not simply bolted on at the end of the process.

By including security as a part of the development process, the long-established walls between the different teams are being broken down, moving security from being the ‘No Team’ to being the ‘Yes Team’.

Cooperation is critical for this approach, as each part of every team needs to work closely together to ensure that all bases are covered.

At the same time, the realities of a workforce that is operating in ways that were not envisaged even a year ago has resulted in security teams having to find ways to extend the scope of their coverage. While perimeter security was considered sufficient just a few years ago, today enterprise security has to cover infrastructure that is not only located on-premises, but also almost anywhere else. Embracing managed security services and cloud security allows them to support users anywhere, anytime with having to invest in new skills and systems.

The continued evolution of security means that they are able to take a more active role in determining the path of digital transformation and engaging in how security can help accelerate business performance.

Read our latest insights in the 2020 Global Threat Intelligence Report.



Dirk Hodgson

Cybersecurity | Data & AI | Business & Technology Transformation | Leadership

4 年

“Yes!!!”.... very well said Matt Gyde.

回复

要查看或添加评论,请登录

Matt Gyde的更多文章

  • Learning from a momentous year

    Learning from a momentous year

    A lot’s been written about how 2020’s been an extraordinary year but looking back I’m not sure we can truly comprehend…

    7 条评论
  • 2021: Now’s our time to get a step ahead of the scourge of cybercrime

    2021: Now’s our time to get a step ahead of the scourge of cybercrime

    2020 ? a year of unprecedented disruption, fear and uncertainty ? is rapidly drawing to its close. I’d like to take…

    3 条评论
  • Creating the team of the future

    Creating the team of the future

    The story of any successful organization is a story about teams. For any complex task to be performed people need to…

  • Creating a culture of innovation

    Creating a culture of innovation

    Innovation is a word that gets bandied about a lot these days. Every organization is looking to innovate in one way or…

    3 条评论
  • A Transformational journey

    A Transformational journey

    The past year has been one of the most exciting and challenging of my entire career. Not only did we have to manage the…

    6 条评论
  • Unpacking secure by design

    Unpacking secure by design

    Over the past few years we’ve seen organizations forced to take their security more seriously, moving from something of…

    3 条评论
  • Are you ready for the new view?

    Are you ready for the new view?

    There’s been a lot of talk about the new normal or the next normal, but it’s time to accept that whatever the world…

    6 条评论
  • Security policies need to evolve quickly to remain relevant post-COVID

    Security policies need to evolve quickly to remain relevant post-COVID

    There’s a lot of talk about the ‘new normal’, or the ‘next normal’ - the way business is going to be conducted in the…

    3 条评论
  • World Health Day 2020

    World Health Day 2020

    We at NTT Ltd. believe all hospitals should be secure.

  • Intelligent Cybersecurity

    Intelligent Cybersecurity

    The ever-evolving world of cybersecurity ? five trends to watch in 2020 that will drive a Secure by Design methodology…

    2 条评论

社区洞察

其他会员也浏览了