«Apply cybersecurity processes and govern them is no longer an option»

Foto del autor

By Jack Ferson

deep

How do you value Iron ijertis Does the evolution of the digital transformation and cybersecurity services in recent years?

The digital transformation processes and cybersecurity management constitute somewhat indissoluble. The technological involvement in corporate processes for the improvement of productivity at all levels is undeniable. As is the fact of the growth of the number of cyber attacks, where as an example the figures speak of more than 1,900 weekly attacks in our country in the first quarter of the year.

The increase in technology use implies an increase in the attack surface. At the same time, cyber attack groups are transforming. Changing their methodologies, many entities are suffering different impacts as produced years ago. Entities apply cybersecurity, but perhaps not adapted to the current moment. In addition, in such an interconnected scenario with a supply chain reaching dimensions never seen, cybercrime has found a lateral input form in strongly protected entities.

How important is the cybersecurity area in relation to the provision of customers services and what strategy has been adopted?

Undoubtedly, cybersecurity management by entities is no longer an option. And if there were doubts, recent European directives in cybersecurity speak for themselves. Dora in El Financiero, the Act in the management and responsibility of the service of AI, the CER in critical entities or the evolution of the NIS, affecting sectors so far regulated, demand a governance of cybersecurity. Resilience, detecting preventively, reacting to them or communicating impacts are a legal imperative. Not to mention what entities considered supplies chain are also subject to these standards.

Apply cybersecurity processes and govern them is no longer an option. Being aware of this in Izertis we had put ourselves for two years to work in a strategy thinking among other aspects in these normative changes. The result of this are some facts that have been seen during this year. For example, support for an entity that has received the first certification in Dora. Or ourselves that we have been the first technological consultant to certify her AI management system.

With this strategy, as well as the consolidation of the traditional services that we already had, the weight of cybersecurity therefore has a high value in itself due to the typology of activities and with a growth by 2025. But we must consider another fundamental aspect as a cybersecurity area. The transversality of security in any action causes the area to be involved in any service provided by Izertis. It is not only worth delivering the best possible service, if not doing it with the highest safety standards demanded by the market.

Sidertia is presented as the «First Integral Cybersecurity tool» by Izertis. How is it different from other consolidated platforms?

In that medium -term strategy, where the publication of the different regulations has proved us right, we have taken into consideration different scenarios and contexts. Many market solutions focus on one of them. For example, the internal context, ignoring others such as external. However, the governance required by the norms requires a complete vision. Not only is it worth knowing the security status of the exhibition surface, but being aware of what cybercriminals over us know or handles. That we are applying a good cybercraft strategy and measure it with current standards.

With years working on highly sensitive environments we knew that a point was missing to give what the industry did not find. We started working on a solution where to dump that experience and knowledge at all levels.

In which R&D projects are Izertis involved to apply artificial intelligence to threat analysis and abnormalities detection?

In different and of different nature. Some are implicit in the Sidertia tool itself, where AI is essential to identify risks and potential security failures taking into account a current vision of the attacker. Others are focused on concrete sectors such as defense, which has its peculiarities and where we have been collaborating with key entities at national and international levels.
In addition, this year an innovation initiative has been launched where professionals from all areas of Izertis, including non -technical ones, make up work teams to generate prototypes that can be useful in different sectors of society. Izertis’s commitment to R&D is part of our DNA.

What sectors show greater appetite for outsource cybersecurity and why?

If this question had been asked some years ago we would have focused on specific sectors such as financial or defense. Historically, cybercriminals and sponsorized groups by state.

But today with a regulation such as the NIS2 that affects multiple sectors and its supply chain, we can say that everyone has the need to outsource their operations with expert knowledge. The difference varies in its investment capacity, but in terms of need, all companies are aware that they must include cybersecurity as an essential part of their technological culture.

What weight currently does AI, Machine Learning and analysis in the detection of threats and what role do you think they will play in the coming years?

A highly significant weight. The increase in the exposure surface, attack techniques against them, heterogeneous environments or relationship with third parties makes managed processes with a high degree of automation. An example is that years ago good vulnerabilities management was feasible with specialized personnel. With the enormous amount of findings so diverse it is only feasible to reach sustainable and valid results with optimal automation processes. We incorporate this into our processes and in our solutions.

Managing vulnerabilities, aligning them to business needs and evaluating possible impact scenarios, is only sustainable with the use of AI -based systems and Machine Learning.

Deja un comentario