thecybersecurityreview

JULY - DEC 2017CYBERSECURITY REVIEW8 Corporate security has often been an afterthought in many industries. Although companies are quick to introduce new software applications, improve network architecture, and adopt cloud for storing data, security aspects of these technologies is put on the back burner. For example, many companies have adopted modern software development frameworks such as Agile/DevOps. A better approach should be on implementing DevSecOps wherein security is an important constituent in the entire scheme of things. DevSecOps takes a security-driven approach from the outset. Lack of focus on security is partially due to the shortage of skilled security individuals in the industry. The need to ramp up the talent pipeline--to focus on the growing importance of IT security--is slowly picking up pace and will hopefully be an essential forethought for business in the future.Consider the insurance industry which currently relies on a reactive approach wherein clients buy insurance for tangible goods; however, we find ourselves in an ethereal position when it comes to IT security and the potential loss of data. This is demonstrable in the Wannacry ransomware attack in May 2017, where a company reported potential loss of up to $300 million. The company then looks to an actuary that is required to stipulate a specific amount of money which could vary depending on the type of and amount of data that was compromised. Personal Insights on IT Security and Governance Sector48 of the 50 states in the U.S. have their own data privacy laws. It is essential to ensure that data security policies are developed and adhered to within a company. That said, it is crucial to ensure that these data privacy policies By Tom Watson, VP IT/Digital, Global CISO Sealed Air CorporationBANKING ON TRUST: THE ROLE OF SECURITYIN MY OPINION
< Page 7 | Page 9 >