Cybersecurity in plain language (3 of 6)
A security system is not a program you install. It is a fixed way of working, built from agreements, people, technology and follow-up that together keep your information safe. On this page I explain what it is made of and how the parts work together.
The word system makes many people think of software. Here it means something else: a set of agreements about who does what, and a way of checking whether those agreements work. Specialists call this a management system.
Compare it with your accounting. There are fixed rules, someone carries them out, and at set times someone checks that everything adds up. A security system does the same, but for your information.
Agreements set out what is and is not allowed, who gets access to what, and what happens when someone starts or leaves. Short and clear, not in a thick manual nobody reads.
People bring those agreements to life. Someone is responsible, and employees know why the agreements exist. An agreement nobody understands gets worked around.
Technology carries out part of the agreements: backups, updates, the second lock on the mailbox.
Follow-up means regularly checking whether the agreements still make sense and whether people follow them.
If one of the four is missing, the whole thing wobbles. Technology without agreements is arbitrary. Agreements without follow-up are just paper after a year.
A security system is never finished. It goes round in four steps.
First you plan: you decide what matters, what can go wrong and which agreements you make for it. Then you put those agreements into practice. Next you check whether they work: does what was agreed actually happen, and does it deliver what it promises? You adjust what does not work, and you take into account whatever has changed in your business.
Then the cycle starts again. That way the system grows along with your business, instead of gathering dust in a cupboard.
A good system does not start with technology, but with a question: what can go wrong, and how bad would that be? Specialists call this a risk assessment. In plain terms, you list what would bring your business to a halt, and choose what to tackle first.
That way you spend your time and money on what matters to you. No more, and no less.