"Information security" sounds like something technical, best left to IT. In fact it is much simpler, and much closer to every person in the company, than it seems.
Many companies think they have security because they have an antivirus and an IT person. It is like saying you take care of your health because you own a first aid kit. Good to have, but far from the whole thing.
Information security is really the care you take of the important information in the company: contracts, customer data, prices, recipes, plans. Whether it sits on a server, a laptop, on paper, or in the head of an employee talking on the phone on a train.
Everything information security does revolves around three simple ideas. You will find them everywhere, under the names confidentiality, integrity and availability.
Any incident damages one or more of these three things. If you remember these, you already understand half of the subject.
This is the trap most companies fall into. They buy expensive technology and think they are done. But security rests on three legs, and technology is only one.
We wrote more about the people side in the article on security culture and in the human factor.
You do not have to invent everything from scratch. There is an international standard, ISO 27001, that describes how a company sets up its information security and keeps it alive over time. In practice, it is a checked list of things to think about, from rules and roles to people and technology.
You are not required to get certified to make use of it. You can take its structure as a map: it helps you not to miss whole areas and not to jump into technology before you know what you are protecting. We wrote separately about how the standard handles the people side, in human resource security in ISO 27001.
Not with shopping. With an honest look at what you have.
At INFOSHARE we walk exactly this path together with companies, step by step and in plain terms. See our information security service, audits and testing, and for a practical guide, the article on business resilience.
Information security protects any important information, in any form: on a computer, on paper, in a conversation. Cybersecurity is a part of it, the part that protects data and systems in the digital world. In other words, cybersecurity is included in information security, not the other way around.
They are the three things information security protects. Confidentiality means the information is seen only by those allowed to. Integrity means the information is correct and has not been changed secretly. Availability means the information is there when you need it. A security problem damages one or more of these three things.
No. Technology is only one part. Information security rests on three legs: people, processes and technology. Most incidents start with a human error or a missing rule, not with a weak firewall, so if you leave it all to IT, you only solve a third of the problem.
With a simple question: what information do I have, and what would happen if I lost it or it reached the wrong people. Once you know what you have to protect and what hurts the most, you put the first measures on what is riskiest: good passwords, backups, role-based access and trained people. You do not need a big budget to start, you need a clear order.
We start from what you have to protect and build, step by step, a set of measures everyone in the company can understand.