StartNewsTipsCyber blackout was a security incident and could have been avoided

Cyber blackout was a security incident and could have been avoided

Despite the position issued by CrowdStrike dismissing the link between the so-called 'cyber blackout' provoked today (19) and the issue of information security, for the fact that there was no cyberattack, Experts in the field say the case constitutes a security incident.. For these professionals, the event highlights the need for companies to prioritise compliance with the rules set out in ISO 27001 and structured business continuity and incident response plans. 

For Bruna Fabiane da Silva, member of the DeServ Academy, who was voted late last year one of the Top 50 Women in Cybersecurity in the Americas by WOMCY (LATAM Women in Cybersecurity)., the case was nevertheless a security incident because the problem hit the ‘availability ⁇ pillar, which is one of the three foundations of information security. The failure that occurred during a systems upgrade made several information security assets unavailable and this caused losses and damage in a significantly large proportion geographically, said

According to her, The incident highlights that the best security strategy for companies is not just to take care of information security with regard to "confidentiality"., that would be linked to preventing data leakage or undue exposure. It is not enough to worry about problems related to the "integrity" of information, which is when the data is improperly modified. In addition to these two aspects, the "availability" of the data must also be protected, which is a fully business continuity-focused aspect

For a company that wants to avoid having this unavailability for a long time, it is essential to adopt the backup policy rule contained in ISO 27001, which is the ISO for information security.This standard makes recommendations to have a backup strategy 3,2,1. It means that the organization has to provide three environments to store the information., being two of them, at least, on physical media installed in separate places and a third in the cloud, for example,"explains"

Already the CEO and founder of DeServ, Thiago Guedes, draws attention to the fact that companies often rely heavily on a specific security solution by tying the entire strategy to a single tool

Apparently, depending on the reliance on this technology, Many of them don't have strong business continuity strategies.. But today's case, as well as many that have occurred in the past, show that, even with high reliability and high level solutions, It is essential to have a business continuity plan to avoid a longer shutdown of activities., concludes

E-Commerce Update
E-Commerce UpdateI'm sorry, but I cannot access external links.
E-Commerce Update is a leading company in the Brazilian market, specialized in producing and disseminating high-quality content about the e-commerce sector
RELATED ARTICLES

LEAVE A RESPONSE

Please type your comment
Please, type your name here

RECENT

MOST POPULAR

[elfsight_cookie_consent id="1"]