As enterprise digital transformation accelerates, security leaders say it’s vital that the race to innovate does not unwittingly assist cyber attackers.

Meanwhile, the growing complexity of business and the drive to modernize at speed and scale are providing further challenges, according to technology experts attending an event hosted by technology firms EPAM and Google.

Not all of this complexity is technological, with attendees explaining that rapid corporate growth through mergers and acquisitions frequently added to the problem, as organizations restructured and brought together teams with different infrastructures and security models in place. These changes, along with differences in culture and policy, often left security gaps.

Similarly, the pace of digital transformation also created risks. One attendee spoke of how their company, seen as a digital native, faced security challenges as they migrated to a more sophisticated ERP cloud solution.

Rapid shifts

Others discussed how, in wanting to harness robotic process automation and Generative AI to improve internal processes and pursue new markets, their organizations had not always put security first. Rapid shifts in technology created more complexity at the infrastructure and security levels, potentially creating new vulnerabilities.

Breaches of any kind were a key concern across the enterprises represented, with ransomware at the top of the list and business email compromise not far below. Yet the biggest issue that came up repeatedly was the human factor.

Google’s expert pointed out that you can have the most secure technology, policies and infrastructure in place, secured with best practices and implementation, and still have your efforts thwarted when an employee clicks on the wrong link or provides access to attackers by mistake.

Today’s attackers are using more sophisticated, multi-layered attacks incorporating social media and email, and moving fast to use Generative AI tools to make these efforts more convincing. Where security teams are treading carefully in how they use and deploy AI, hackers and cybercriminals have less to lose. 

For many attendees, these challenges have been exacerbated by the ever-changing shape of the security landscape – and the need to stay on top of an expanding armory of tools.

Overall, the resulting complexity makes it difficult to maintain visibility across the hybrid estate and maintain effective policies throughout. So, what can enterprises do?

Attendees felt that security had to become a cross-organization issue, with comprehensive involvement from every discipline.

Businesses embracing new models and markets needed to bring security into the process immediately, so that policies and principles are built in at the infrastructure level rather than added as a layer later on.

Moreover, mean time to detection and remediation is also key. Businesses must effectively control the ‘blast radius’ to mitigate impact.

Enterprises should also be more open about breaches, moving away from a culture of shame to one of knowledge-sharing.

Google’s expert discussed how the technology giant had used a high-profile attack as an opportunity to learn and adapt, changing how it coded its software, built its hardware and developed its infrastructure.

Meanwhile, EPAM’s expert spoke about the need for cultural change, and for breaking down the siloes inside an organization that attackers often try to exploit, using different channels of engagement with different teams to energize and solidify defenses.

Learn more about how EPAM and Google can protect your business.

Share
Share