CYBERSECURITY REVIEW 19 AUGUST - 2023too many problems. With multiple ongoing things and a dearth of solutions, it is not possible to hold one person responsible for the issues.From the engineering perspective, industrial engineers are adept at running the infrastructure. But issues arise from the cybersecurity perspective. Such critical problems can have deep implications for the public. WHAT WOULD BE YOUR WORD OF ADVICE FOR YOUR PEERS IN THE INDUSTRY? The first piece of advice would be to remain true to your words when speaking with other guys. Do not give into fear and offer them the real picture since you have a problem. Even if you show them the real picture, admit that you have run into some problems, but they can be overcome easily. If you are not part of the solution, you are part of the problem. Overcoming your fear can help you achieve a lot of things. With too many tasks, you would require all the support you get. Of course, it is not easy to discuss such topics with the upper management level. The upper management level does not only handle internal security problems. There are thousands of other problems and risks that they face. Even though you might not be the only one concerned about safeguarding the organization, you should not write that off as a risk. HOW SIGNIFICANT IS IT FOR COMPANIES TO DISCOVER THE RIGHT TALENT AND EXPERTISE IN CYBER SECURITY?There are two ways how you can access the work. The first would be strategic planning and architecturing. To implement these, you need to have a team in sight because these are very people besides the company who knows the latter inside out the mentality and everyday activity of the company, the day-to-day problems, etc. Such teams set the right direction for the company to move on. So from my point of view, accounting and outsourcing CSOs will give you momentum as a company. Of course, it is not easy to find the right person. The ideal CSO would have the perfect technical knowledge and soft skills balance. It isn't easy to find a person with this kind of expertise in the market. Of course, too many novices are filling up the positions instead. It is up to the companies to debate the right team, but unfortunately, there is a huge shortage in the market.WHAT KIND OF TEAM EXPERTISE ARE YOU FIXATING ON?First, you must have someone with strategic knowledge and the ability to speak before upper-level management. Besides, he must have someone in the internal team who can understand technical architecture and orchestrate outsourcing. He must be in a position to report to the CSO directly, and of course, there must be someone from the GRC perspective to run the risk-based approach, the risk assessments, and the compliances. In the end, all these must be in complete alliance with IT and end IT personnel. TO IMPLEMENT THESE, YOU NEED TO HAVE A TEAM IN SIGHT BECAUSE THESE ARE VERY PEOPLE BESIDES THE COMPANY WHO KNOWS THE LATTER INSIDE OUT THE MENTALITY AND EVERYDAY ACTIVITY OF THE COMPANY, THE DAY-TO-DAY PROBLEMS, ETC. SUCH TEAMS SET THE RIGHT DIRECTION FOR THE COMPANY TO MOVE ON
<
Page 9 |
Page 11 >