Cybersecurity in plain language (1 of 6)
Cybersecurity means that the information your business runs on is safe. Nobody sees what they should not see, nothing changes without anyone noticing, and everything is there when you need it. On this page I explain what that means in practice, without the jargon.
When people hear the word cybersecurity, most think of computers, viruses and an IT person installing updates. That is part of it. But what really matters is the information your business needs to keep working.
Think of your customer list, your quotes and invoices, your schedules, your accounting or the managing director's mailbox. Without that information your business comes to a halt. If it ends up in the wrong hands, you have a problem with your customers.
Three questions tell you whether your information is safe.
Can only the right people see it? Your payroll is not for every employee, and your customer data is not for outsiders.
Would you notice if something changed? If someone quietly changes the bank account number on an invoice, it costs you money, even though nothing was stolen.
Is everything there when you need it? A mailbox that is down for a week, or accounting records nobody can get to, brings your business to a halt, even if not a single piece of data has leaked.
Specialists call this confidentiality, integrity and availability. You do not need to remember those words. The three questions are enough.
Cybersecurity, IT security and digital security mean the same thing in practice: protecting your digital information. The difference that does matter is between those and information security.
Information security is broader. It covers all information, including what is on paper and what is in your people's heads. A folder of personnel files left open on a desk, or an employee who says too much on the phone, falls under it too.
ISO 27001, the standard I come back to later in this series, is about information security in that broad sense.
A good antivirus program helps. But many problems start with ordinary things: a password everyone knows, a new employee who gets access to everything, or a backup nobody knows actually works.
That is why cybersecurity is largely a matter of agreements and people, and only after that of technology. And setting those agreements is the job of whoever runs the business.