A Gartner Cybersecurity Report

Cybersecurity is really a Business Decision

 

Back in February Gartner produced published a cyber risk assessment entitled “The Urgency to Treat Cybersecurity as a Business Decision”[1]

In this paper, Gartner senior analyst Paul Proctor describes many important trends within the cybersecurity side of business, as companies are being forced to cope with emerging threats in an environment increasingly defined by government regulation and societal perception.

The paper warned that many of the most popular investments for bolstering company networks will fail.  This, said Proctor, is due to the growing “disconnect” between the field of cybersecurity and business needs.

The analysis presented by Gartner six months ago has proved nearly prophetic.

COVID-19

In the wake of the COVID-19 pandemic, the cybersecurity landscape has changed dramatically.  Many are taking advantage of this crisis. It has been estimated that possibly 80 percent of all cyber campaigns are now leveraging the COVID pandemic in some form or another.

Many aspects of the pandemic world have been capitalized on by cybercriminals. A central method of hackers is to observe behavioral trends online with which to mask malicious activity. COVID has provided several of these patterns. Hackers have used everything from malware-laden sick forms, fraudulent demands for ‘COVID insurance’ fees, and even fake messages from the World Health Organization.

But perhaps the single biggest liability has been created by changes in the global workforce.  Data security risks (for the company as well as the employee) have increased immensely with the new remote workforce.    One key concern is the security of home networks. The gamet of known router vulnerabilities has provided ample targets for hackers.  Home connections are rarely equipped with the same level of security features businesses will invest in corporate networks. Furthermore, home routers are by nature exposed to threats that are usually of no concern to a business environment.   These include additional devices being connected through the same router (TVs, game consoles, etc) and additional users having access to the network such as the employee’s family members.

While executives were focused on meeting complex compliance requirements, much more rudimentary steps with substantially higher business value–like enabling secure remote access technologies–were completely missed.

Data Protection Designed for Real-World Business

GTB’s DLP that Workstm solutions give companies the edge on managing their data security. Powered by artificial intelligence, GTB’s software learns your company’s system and operational flow to accurately identify the presence of viral programs and malicious activity.

With GTB, firms can engage confidently in today’s regulatory landscape, while at the same time addressing the real security needs of their business operations.

 

[1] The Urgency to Treat Cybersecurity as a Business Decision, Gartner, Inc.  Published: 12 February 2020 ID: G00466055     Analyst(s): Paul Proctor

adroll_adv_id = “UIOFH72HVBDSPBBLAJUZE6”;
adroll_pix_id = “HNO2CUNA4BAINCHLEPH2JH”;
/* OPTIONAL: provide email to improve user identification */
/* adroll_email = “username@example.com”; */
(function () {
var _onload = function(){
if (document.readyState && !/loaded|complete/.test(document.readyState)){setTimeout(_onload, 10);return}
if (!window.__adroll_loaded){__adroll_loaded=true;setTimeout(_onload, 50);return}
var scr = document.createElement(“script”);
var host = ((“https:” == document.location.protocol) ? “https://s.adroll.com” : “http://a.adroll.com”);
scr.setAttribute(‘async’, ‘true’);
scr.type = “text/javascript”;
scr.src = host + “/j/roundtrip.js”;
((document.getElementsByTagName(‘head’) || [null])[0] ||
document.getElementsByTagName(‘script’)[0].parentNode).appendChild(scr);
};
if (window.addEventListener) {window.addEventListener(‘load’, _onload, false);}
else {window.attachEvent(‘onload’, _onload)}
}());

Visibility: Accurately, discover sensitive data; detect and address broken business process, or insider threats including sensitive data breach attempts.

Protection: Automate data protection, breach prevention and incident response both on and off the network; for example, find and quarantine sensitive data within files exposed on user workstations, FileShares and cloud storage.

Notification: Alert and educate users on violations to raise awareness and educate the end user about cybersecurity and corporate policies.

Education: Start target cyber-security training; e.g., identify end-users violating policies and train them.

  • Employees and organizations have knowledge and control of the information leaving the organization, where it is being sent, and where it is being preserved.
  • Ability to allow user classification to give them influence in how the data they produce is controlled, which increases protection and end-user adoption.
  • Control your data across your entire domain in one Central Management Dashboard with Universal policies.
  • Many levels of control together with the ability to warn end-users of possible non-compliant – risky activities, protecting from malicious insiders and human error.
  • Full data discovery collection detects sensitive data anywhere it is stored, and provides strong classification, watermarking, and other controls.
  • Delivers full technical controls on who can copy what data, to what devices, what can be printed, and/or watermarked.
  • Integrate with GRC workflows.
  • Reduce the risk of fines and non-compliance.
  • Protect intellectual property and corporate assets.
  • Ensure compliance within industry, regulatory, and corporate policy.
  • Ability to enforce boundaries and control what types of sensitive information can flow where.
  • Control data flow to third parties and between business units.