Cybersecurity in plain language (5 of 6)
Cybersecurity is a decision for senior management, not for the IT manager. On this page I explain why, the pattern I see at many companies, and why a certificate on its own does not make you secure.
When I talk to business owners about cybersecurity, I keep hearing the same reactions. "That's something for our IT department." "IT knows what they're doing, let them decide." "Why am I responsible for something that isn't part of my business?"
Those reactions are understandable. They are just not right.
The questions a security system asks are business questions. Which information can we not do without? How long can we manage without our order management? Which risks do we accept, and which do we not? Your IT manager can prepare many of the answers. The choice between what you protect and what you accept remains a choice for senior management. ISO 27001 asks for exactly that: senior management owns the system.
The pattern I see most often is subtler. The management team is presented with a well-prepared proposal, finds it sound and approves it. "It's well prepared, let them carry on."
The preparation is not the problem. But if you do not put time into it yourself, you have not really decided. The system then belongs to whoever prepared it, and not to the organisation that has to own it.
"Once we have the certificate, we're secure." I hear that one regularly too.
A certificate says that an independent organisation confirmed, at a given moment, that your system meets the standard. That is valuable. It says nothing about what happens if nobody uses the system afterwards.
So my advice is simple. Do it properly and make sure your security system is a living part of your organisation, or do not start at all. A system that only exists on paper gives a false sense of security. And sooner or later, that will catch you out.