{"id":47,"date":"2023-10-09T12:00:00","date_gmt":"2023-10-09T12:00:00","guid":{"rendered":"https:\/\/lloydsun.espain.center\/?p=47"},"modified":"2026-09-07T21:18:13","modified_gmt":"2026-09-07T21:18:13","slug":"ways-to-incorporate-cyber-resilience-in-your-business","status":"publish","type":"post","link":"https:\/\/lloydsun.espain.center\/?p=47","title":{"rendered":"Ways to incorporate cyber resilience in your business"},"content":{"rendered":"<p class=\"cart_p\">\n<p dir=\"ltr\" style=\"text-align:justify\">Few of us today are unaware of the significance of cybersecurity and the threat of cyber-attacks on our computers, smartphones and other devices. We are constantly being reminded never to disclose passwords and to be on the look-out for spam and phishing e-mails that attempt to manipulate you into divulging personal information\u202f\u2013 such as those passwords, bank details, social security or medical information.\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">This form of identity theft, although troubling, becomes even more sinister when it is directed at governments and other major institutions. \u201cSeeing is deceiving\u201d is the tagline of a popular BBC TV series,\u00a0<em>The Capture<\/em>, which explores the impact of deepfake technology \u2013 described as the 21<sup>st<\/sup>\u00a0century\u2019s answer to Photoshopping \u2013 threatening national security, shaking the foundations of state, destroying trust and making us doubt reality.\u00a0\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">Far-fetched in many respects, perhaps, but as we move deeper into the era of the Fourth Industrial Revolution, the show highlights the potential risks and threats from rapidly changing and ever-more sophisticated technologies.\u00a0\u00a0<\/p>\n<h3 dir=\"ltr\" style=\"text-align:justify\">Prioritizing the risk\u00a0<\/h3>\n<p dir=\"ltr\" style=\"text-align:justify\">According to the World Economic Forum report\u00a0<em><a href=\"https:\/\/www.weforum.org\/reports\/global-cybersecurity-outlook-2022\/\">Global Cybersecurity Outlook 2022<\/a><\/em>, infrastructure breakdown as a result of a cyber-attack is the number one concern for cyber leaders, ahead of identity theft. The report also indicates that while 85\u202f% of cyber leaders agree that cyber resilience is a priority for their organization, gaining decision makers\u2019 support when prioritizing such risks against many others remains a big challenge. This challenge should not be taken lightly.\u00a0<em>CyberCrime Magazine<\/em>\u00a0says cyber-attacks could potentially disable the economy of a city, state or entire country and it claims the\u00a0<a href=\"https:\/\/cybersecurityventures.com\/hackerpocalypse-cybercrime-report-2016\/\">global cost of cybercrime<\/a>\u00a0will reach USD\u202f10.5 trillion annually by 2025.\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">Cybersecurity is not new, but in our increasingly interconnected\u202f\u2013 and fragmented\u202f\u2013 world, the risks to people, organizations, services and systems from cyber-attacks have never been greater. As technology has grown in sophistication, so, too, have cybercriminals. Uncertainty is rife and trust is at a premium. Confidence and assurance that our systems are safe is now a basic requirement and two International Standards\u202f\u2013\u00a0<a href=\"https:\/\/www.iso.org\/standard\/72891.html\">ISO\/IEC\u202f15408\u00a0<\/a>and\u00a0<a href=\"https:\/\/www.iso.org\/standard\/72889.html\">ISO\/IEC\u202f18045<\/a>\u00a0for information technology\u202f\u2013 can help to restore that trust.\u00a0\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">The standards work together \u201clike the pedals of a bicycle\u201d, says Miguel Ba\u00f1\u00f3n, an expert in cybersecurity evaluation and certification, and Convenor of the working group on security evaluation, testing and specification, operating under the joint stewardship of ISO and the International Electrotechnical Commission (<a href=\"https:\/\/iec.ch\/homepage\">IEC<\/a>). ISO\/IEC\u202f15408 establishes evaluation criteria for IT security, while ISO\/IEC\u202f18045, the companion document, defines the methodology for IT security evaluation. For practical purposes, however, they are the same thing.\u00a0<\/p>\n<h3 dir=\"ltr\" style=\"text-align:justify\">Timely revision\u00a0<\/h3>\n<p dir=\"ltr\" style=\"text-align:justify\">The recent revision of the standards could not have been more timely, evolving to meet the complex new needs of the age. \u201cThe working group is focusing on technology assurance, testing certification and providing the standards to ensure that the technology itself is secure,\u201d Ba\u00f1\u00f3n says. \u201cThis is a significant part of the solution.\u201d The standards also help to manage information and take a holistic approach, but the basic foundation is that the technology is secure.\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">In order to succeed in the market, you have to achieve the trust of your customers. This is as true for technology as it is for any other product. With a dizzying array of new products coming on to the market very quickly, such as connected vehicles for example, how can you rely on a connected vehicle that drives by itself if you don\u2019t have assurance that it\u2019s going to work properly?\u00a0\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">As Ba\u00f1\u00f3n says, with ISO\/IEC\u202f15408 and ISO\/IEC\u202f18045, \u201cwe are providing the best and the only way, which is internationally agreed, on how to test and evaluate the security of products and systems\u201d. He points out that what was once a niche area is now becoming mainstream and the market itself is putting cybersecurity upfront as a requirement. Decision makers and leaders now have to step up and prioritize cyber-risks.\u00a0\u00a0<\/p>\n<h3 dir=\"ltr\" style=\"text-align:justify\">Building resilience\u00a0<\/h3>\n<p dir=\"ltr\" style=\"text-align:justify\">At government level, this is something that is being increasingly recognized. Ba\u00f1\u00f3n says that one positive outcome of this explosion of cybersecurity concerns has led, for example, to new and forthcoming legislation in the European Union to strengthen cybersecurity systems. \u201cThe EU Cybersecurity Act provides a framework for European-wide certification schemes. In the past, if you had to certify the security of your product, you could do that based on national schemes,\u201d he says. \u201cNow, for the first time, there will be a pan-European certification scheme for products and this new scheme is based on ISO\/IEC\u202f15408.\u201d\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">As he points out, IT security is not new and the past application of the standards has had a positive impact on products in the market. He says: \u201cThose products that have typically achieved compliance with the standards, such as operating systems or network devices, have evolved and improved to the extent that the hackers have had to target \u201ceasier\u201d products\/attack surfaces.\u201d\u00a0<\/p>\n<p dir=\"ltr\" style=\"text-align:justify\">Compliance with ISO\/IEC\u202f15408 requires a high level of maturity, a high level of resistance against attacks. When we hear news of major cybersecurity breaches today, Ba\u00f1\u00f3n says there is a high chance these hackers are exploiting products that have not been certified or analysed by this standard. \u201cIf you\u2019re a hacker, you tend to look for the weakest link in the chain, and today, the easiest route is via products that have not been certified according to the standard.\u201d\u00a0<\/p>\n<h3 dir=\"ltr\" style=\"text-align:justify\">Independent and impartial\u00a0<\/h3>\n<p dir=\"ltr\" style=\"text-align:justify\">It\u2019s all a matter of trust. Ba\u00f1\u00f3n says: \u201cIn our standards, trust is provided after a very rigorous, independent and impartial review of a product and after a process of evaluation and certification.\u201d Just as you can\u2019t \u2013 and wouldn\u2019t want to \u2013 buy a washing machine that doesn\u2019t comply with safety requirements, compliance with these standards, \u201cwhich are driven by market needs and are the basis of the most successful cybersecurity schemes all over the world\u201d, offers protection from nasty shocks and will deliver peace of mind.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Read more<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-47","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=\/wp\/v2\/posts\/47","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=47"}],"version-history":[{"count":2,"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=\/wp\/v2\/posts\/47\/revisions"}],"predecessor-version":[{"id":112,"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=\/wp\/v2\/posts\/47\/revisions\/112"}],"wp:attachment":[{"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=47"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=47"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lloydsun.espain.center\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=47"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}