Global organizations still fail to integrate cybersecurity training into their digital transformation efforts from the beginning, according to experts, putting their projects at risk and their businesses at greater risk.
During a panel discussion at Infosecurity Europe today, Camilla Winlow, head of data privacy at Gemserv, said that despite digital transformation accelerating in the pandemic years, organizations have forgotten the basics and some companies are It claimed it had failed to update its work-from-home policy. From 2020 and before.
“It’s amazing to see how companies can act so quickly.” [digitally]but what’s a little disappointing is that while we’re aware of the service implications, we haven’t thought about the ball that fell in the process,” she explained.
“So, while we appreciate your quick action, please make sure you have a complete list of things that need to be covered and don’t focus too much on technology solutions.”
To learn more about security by design, CISA asks manufacturers to prioritize cybersecurity in product design.
Training employees to use new digital technologies in an effective, secure, and compliant way is an important part of security-by-design best practices. But in some organizations, new technology initiatives may roll out without all staff undergoing initial training, Winlow said.
“Remembering technology, forgetting people. It’s always people who cause problems,” she added.
Santander International CISO David Cartwright argued that organizations can avoid further risks by consulting end users during the development process of new technologies.
“It’s strange that we forgot about users because we went from DevOps to DevSecOps and we haven’t reached DevSecUserOps yet. I think we need to get there he added. “If they had been involved in how it was built from the beginning, the need for training would have been reduced in many cases.”
The experts who participated in the panel discussion agreed that a “fail-fast” strategy for digital transformation could be an effective way to avoid cyber risks.
“From a data protection perspective, if a failure occurs in a quick and agile manner, we should be able to mitigate the impact of the failure, which is very important,” said Wimlo. “They have to get in there to fail and have controls in place to roll things back if they fail.”
While awareness of security and data protection by design has improved since the GDPR took effect, Cartwright argued that DevSecOps still has a long way to go before it is fully embedded in most organizations.
Separately, a new F5 study released today found that only 4% of organizations currently rank at the highest level of digital maturity, while 31% are classified as “digital bastards.” It turns out.