You are currently viewing Risks Don’t Wait. Neither Should We.

Risks Don’t Wait. Neither Should We.

I had the op­por­tu­ni­ty to at­tend the IT Se­cu­ri­ty Day hos­ted by IHK Rhein-Ne­ckar, un­der the the­me “Re­co­gni­ze risks, de­fend against th­re­ats” and glad to have been part of it. 

A few to­pics re­al­ly stuck with me th­roug­hout the day: the cur­rent th­re­at si­tua­ti­on for SMEs, how to prepa­re for emer­gen­ci­es, re­gio­nal in­ci­dent ma­nage­ment, cy­ber insu­rance, re­du­cing at­tack sur­faces in prac­ti­ce, IT se­cu­ri­ty around GAIA‑X, and the up­co­ming Cy­ber Re­si­li­ence Act. 

One point that came up around di­gi­tal so­ve­reig­n­ty: the dis­cus­sion touch­ed on open-source so­lu­ti­ons as one ap­proach to re­du­cing ex­ter­nal de­pen­den­ci­es, an ang­le that cle­ar­ly spark­ed some de­ba­te in the room.

I also en­joy­ed see­ing how dif­fe­rent com­pa­nies ap­proach the­se chal­lenges in prac­ti­ce, for ex­am­p­le DEFENDERBOX as a vir­tu­al ap­pli­ance, BCM360 as a vir­tu­al cri­sis training tool, and a hands-on cy­ber­se­cu­ri­ty role-play by Wi­thS­ecu­re that made things feel a lot less abstract.

And just as nice were the breaks : with cof­fee, drinks, cake, and a pro­per lunch, the­re was ple­nty of time to chat with other attendees.

What made the day even more in­te­res­t­ing for me: around the same time, I was pre­pa­ring a uni­ver­si­ty case stu­dy on a long-es­tab­lished, tra­di­tio­nal com­pa­ny that was dri­ven into in­sol­ven­cy by a sin­gle cy­ber­at­tack. Working th­rough that pro­ject, the same ques­ti­ons kept co­ming up. Did they have a busi­ness con­ti­nui­ty plan, and was it ever ac­tual­ly tes­ted? Were logs be­ing mo­ni­to­red, and if so­me­thing su­s­pi­cious show­ed up, did an­yo­ne act on it in time? The hard part is: the­se are­n’t exo­tic ques­ti­ons. They’­re the ba­sics. And yet for that com­pa­ny, the ans­wers came too late.

Did they have a busi­ness con­ti­nui­ty plan, and was it ever ac­tual­ly tes­ted? Were logs be­ing mo­ni­to­red, and if so­me­thing su­s­pi­cious show­ed up, did an­yo­ne act on it in time? The hard part is: the­se are­n’t exo­tic ques­ti­ons. They’­re the ba­sics. And yet for that com­pa­ny, the ans­wers came too late.

The hard part is: the­se are­n’t exo­tic ques­ti­ons. They’­re the ba­sics. And yet for that com­pa­ny, the ans­wers came too late.

Thank you to IHK Rhein-Ne­ckar and ever­yo­ne in­vol­ved for put­ting this together.

Close Menu