The protection of information assets and their relevance to business success and health
That information assets are among the most valuable elements for businesses is a reality that few dispute anymore. Without their customer database, order records, warehouse inventory control, billing management, communication with customers and suppliers, or the product design and descriptions that give them a competitive edge, among other things, they could hardly operate or even survive.
- Tangible: a person, a computer, a smartphone, or a server.
- Intangible: a database, an email address, or data from colleagues and clients
Causes of data loss
Many studies indicate that there are several causes of data loss in companies. Specifically in the “Study on the Cost of Data Loss 2016A study conducted by the Ponemon Institute, based on a survey of 383 companies worldwide, concludes that 48% of incidents are due to malicious actions or cyberattacks With viruses and malware in general, 25% are caused by human factors and the remaining 27% to errors in the systems, including IT and business process failures.
Cost of data loss
According to the “Global Survey on the State of CybersecurityAccording to a study by the consulting firm PwC, losses in Spanish companies resulting solely from cyberattacks could average around 1,4 million euros in 2016If we focus on the case of SMEs, the insurer Mapfre, based on various studies, puts that amount between €20.000 and €50.000 on average.
All these losses of information can represent a high cost for companies, not only in terms of the interruption of activity, but also in the loss of image, trust, and even customers, and the recovery of information assets themselves.Although this amount depends on the company's activity and the sensitivity of the lost data, the same study estimates that the average recovery cost of a data record lost due to a cyberattack is €152. This amount is significantly higher than that resulting from system errors or human factors, estimated at between €119 and €123 respectively. These figures give us an idea of the significant impact that losing several thousand records of sensitive business information can have on a company.
The risk in numbers: 12 cyberattacks per second worldwide
In Spain, around 105.000 cyberattacks were recorded in 2016, double the number from the previous year and five times more than in 2014. Of these, almost 70% were directed to small and medium-sized enterprises, as reported in the “International Business Report 2017” by the consultancy Grant Thornton.
How to prepare and protect yourself on the Internet
The question, therefore, is no longer, "Could it happen to me?" but rather, "Will I be prepared enough to continue my business in the best possible conditions when it happens to me?"
And the answer is yes, you can be prepared. Several security experts, including the one himself, have confirmed this. INCIBE o Grant ThorntonThey agree on the need to view security within the company as a whole and always aligned with the specific needs of its business. They emphasize the importance of implementing a proper security plan. security policy on the following main axes:
- Properly analyze the information needs for the business, its criticality and importance, and the risks to which it may be subjected.
- Develop the projects and initiatives to be implemented based on the priorities defined in the risk analysis.
- To involve and raise awareness of company security throughout the entire organization, from top management to all employees, taking it beyond the technical factor to the "human factor".
All that remains is to truly understand the importance of cybersecurity or information asset security for the company and get to work on it.
At EPUNTO Interim Management, we can help you. As Interim Managers with over 15 years of experience, we have the necessary knowledge and experience to lead the change in the direction and management of the security of your organization's information systems.
I am Santiago Muñoz, a dedicated and passionate professional with over 20 years of experience in the application of ICT technologies, and I can help you be prepared to face the risks of digital transformation. DO WE SPEAK?