How does a security system fit together?

A security system is not a program you install. It is a fixed way of working, built from agreements, people, technology and follow-up that together keep your information safe. On this page I explain what it is made of and how the parts work together.

← Cybersecurity in plain language

It is a way of working, not a product

The word system makes many people think of software. Here it means something else: a set of agreements about who does what, and a way of checking whether those agreements work. Specialists call this a management system.

Compare it with your accounting. There are fixed rules, someone carries them out, and at set times someone checks that everything adds up. A security system does the same, but for your information.

Four parts hold it together

Agreements set out what is and is not allowed, who gets access to what, and what happens when someone starts or leaves. Short and clear, not in a thick manual nobody reads.

People bring those agreements to life. Someone is responsible, and employees know why the agreements exist. An agreement nobody understands gets worked around.

Technology carries out part of the agreements: backups, updates, the second lock on the mailbox.

Follow-up means regularly checking whether the agreements still make sense and whether people follow them.

Agreements What is allowed, who gets access to what
People Someone is responsible, everyone knows why
Technology Backups, updates, the second lock
Follow-up Do the agreements still hold?
Together they keep your information safe
The four building blocks of a security system

If one of the four is missing, the whole thing wobbles. Technology without agreements is arbitrary. Agreements without follow-up are just paper after a year.

It runs in a cycle: plan, do, check, adjust

A security system is never finished. It goes round in four steps.

1PlanWhat matters, what can go wrong
2DoPut the agreements into practice
3CheckDoes it deliver what it promises?
4AdjustFix what fails, take in what changed
Never finishedThe system grows along with your business
The cycle that keeps the system alive

First you plan: you decide what matters, what can go wrong and which agreements you make for it. Then you put those agreements into practice. Next you check whether they work: does what was agreed actually happen, and does it deliver what it promises? You adjust what does not work, and you take into account whatever has changed in your business.

Then the cycle starts again. That way the system grows along with your business, instead of gathering dust in a cupboard.

It starts with what is at stake for you

A good system does not start with technology, but with a question: what can go wrong, and how bad would that be? Specialists call this a risk assessment. In plain terms, you list what would bring your business to a halt, and choose what to tackle first.

That way you spend your time and money on what matters to you. No more, and no less.

Next: What is ISO 27001, and why do customers ask about it?