Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Data Breach
  • Is any organisation risk and data breach free?
  • Data Breach

Is any organisation risk and data breach free?

4 years ago Tripwire Guest Authors
Is any organisation risk and data breach free?

I walked into a business the other day. After a long conversation about the client’s need for cybersecurity and the implementation of the ISO27001 security standard, we talked about their risk appetite.

“We don’t accept any risk. We’re risk-averse” said the CEO. But, is this achievable?

Given the complexity of our modern world, with diversity in the people, locations, services and technologies, can any organisation be totally risk-free, and therefore, can any business be totally free of the risk of a data breach?

The simple answer is no. It’s not possible.

What is Risk?

Why is the topic of risk so important? Because it is at the heart of everything, we do. We are ALL risk managers and risk takers. Allow me to illustrate:

  • Going for a jog? – Risk of injury, health issues arising, being late for a meeting.
  • Crossing the road? – Risk of tripping, being hit by a car/pedestrian/cyclist
  • Making a cup of tea? – Risk of burns, spillages, not getting it right for your partner!
  • Starting a business? – Risk of failure, growing too quickly, neglecting personal life.
  • Going on holiday? – Risk of bad hotel or terrible weather.
  • Driving to work? – Risk of accident, car problems, traffic delays.
  • Running a business – Risk of wrong/poor services, losing clients, data breaches.

These are just some of the possible examples. But the list goes on. We are taking risks from the moment we wake to the moment we go to bed at night.

Risk is unavoidable; therefore, we have to accept some level of risk and focus on the ones we cannot fully control. What we are actually looking to do is manage our exposure to risk.

Can organisations be free from the risk of a data breach?

Even though I’m a cybersecurity consultant, helping organisations to implement frameworks like ISO27001, ISO27701 and others, I am at pains to tell people there is no such thing as 100% secure. 

If this news shocks you, please refer to the previous section – There is no such thing as ‘Risk-free’. Look back at the previous list, and you’ll see that the majority of the examples I’ve given rely solely on you and the decisions you make. Except for the last three; Going on holiday, driving to work and running a business. Consider all the ‘moving parts’ involved in driving to work, going on holiday or running a business. You’re relying on forces beyond your control, such as the weather, local or national disturbances, industrial disputes, other road users, vehicle maintenance, market fluctuations, the economy, clients, suppliers, technology and your own employees.

Risk would be so much easier to manage if you were making all the decisions and taking all the actions. But most often, you’re not. In business, it’s impossible to operate in a vacuum; therefore, the risk of something going wrong is exponential based on the size and complexity of your infrastructure (both physical and technical).

If Data breaches are an inevitable risk, what can we do?

At this point, I’m going to sound as if I’m contradicting myself; I’m not saying you are 100% guaranteed to have a breach. I am saying that you’re 100% more likely to have a breach unless you manage the risk appropriately. 

This may sound like semantics but managing risk of any kind is about understanding the likelihood of something occurring and what the impact will be on you and those you care about. 

Therefore, we are trying to reduce either the likelihood or impact of the risk occurring. It’s rare to affect both, but if we can reduce the possibility of a risk occurring, that’s a great place to start. If we feel the risk is inevitable, then reducing the impact of that risk is where we should focus our attention.

The key here is to have some form of risk management process in place, where risks are identified, their impact and likelihood assessed, and the controls you have in place to manage the risk fully understood.

Conclusion – We are ALL in the business of risk

When organisations tell me that they don’t have a risk management approach, I know that typically it means it is not formalised or documented. We are all in the business of managing risk. We need to manage our exposure to the risks we face, and demonstrate that we have done something to control them.

In the UK, the Information Commissioners Office (ICO) governs the UK Data Protection Act and UK GDPR. If you are unlucky enough to have a data breach, they will fundamentally want to know four things;

  • What happened?
  • What did you do to prevent it?
  • What did you do when it was discovered?
  • What are you doing to prevent a reoccurrence?

Having a good answer to each of these is incredibly important. But the answer to the second point should focus on the fact that you considered the risk and put in place appropriate technical and organisational controls to reduce the likelihood or impact of it occurring.

Risk is an inevitable part of life. If we accept the fact that there is no such thing as ‘risk free’, the only question we have to answer is; “What are we doing to manage our risks appropriately?”


About the Author: Gary Hibberd is the ‘The Professor of Communicating Cyber’ at ConsultantsLikeUs and is a Cybersecurity and Data Protection specialist with 35 years in IT. He is a published author, regular blogger, and international speaker on everything from international security standards such as ISO27001 Dark Web to Cybercrime and CyberPsychology. He is passionate about providing pragmatic advice and guidance that helps people and businesses become more secure.

You can follow Gary on Twitter here: @AgenciGary

Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” Is any organisation risk and data breach free?” appeared first on TripWire

Source:TripWire – Tripwire Guest Authors

Tags: Compliance, Encryption, Finance, Medium Severity, TripWire

Continue Reading

Previous Novel Malware Hijacks Facebook Business Accounts
Next Malicious IIS Extensions Gaining Popularity Among Cyber Criminals for Persistent Access

More Stories

  • Data Breach

[Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automate

2 hours ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Data Breach

When Cloud Outages Ripple Across the Internet

5 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks

7 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach

Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox

11 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

12 hours ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users

23 hours ago [email protected] (The Hacker News)

Recent Posts

  • [Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automate
  • When Cloud Outages Ripple Across the Internet
  • APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware Attacks
  • Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox
  • Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT