Cybersecurity professionals are caught between a rock and a hard place, as they are tasked with keeping systems and users secure while not hindering the business in any way. As organizations and consumers do more business online and in the cloud, user experience is becoming a top priority. As the founder and CTO of a compromised credential detection company, I've found that security efforts are often hindered in favor of a positive user experience. In the security world, the "tree-falls-in-the-forest" question is this:
If a user doesn’t turn on a security feature, does it really matter how much more secure it is?
https://www.forbes.com/sites/forbestechcouncil/2019/09/17/balancing-user-experience-with-security-overcoming-resistance-to-two-factor-authentication/#772b35ca3b0e/
If you’re like most business leaders, you try to do everything you can to keep your company’s information safe.
You tell your employees to use strong passwords and offer regular trainings on phishing and the importance of internet security. You even make them change their passwords every six months or three months.
Although you know no system is foolproof, your rules should be as strict as possible in order to prevent a breach. Or should they? Evidence shows that stringent security measures can actually backfire, and can leave you more vulnerable than you were before.
https://www.helpnetsecurity.com/2018/08/21/stringent-security-measures/
“Security is everyone’s job now.” These are wise words from Amazon’s CTO Dr. Werner Vogels, especially for companies embarking on a digital transformation or accelerating their journey.
Why should we all consider this advice? A recent report released by McKinsey i » shows impressive figures: More than 100 billion lines of code are created annually, and hackers produce some 120 million new variants of malware every year. A strong Cybersecurity strategy is essential. Gartner research predicts that “By 2020, 60% of digital businesses will have suffered a major service failure.”
Is it any wonder, then, that Cybersecurity issues keep all of us up at night? The fundamental issue is not about developing new Cybersecurity capabilities as part of business strategy. Instead, it’s about integrating them seamlessly.
http://saudigazette.com.sa/article/538981/BUSINESS/3-steps-toward-cybersecurity-in-a-digital-world/