What is Cybersecurity? According to CISA.gov it is “the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information.” Ok well that’s clear as mud. Technically that is absolutely correct, but practically what does it mean? Let’s break it down.
Cybersecurity is often associated with hackers, phishing, antivirus, firewalls, spam filters, and countless other prevention tools. But it is much more than those things. Complete cybersecurity is a combination of technical tools, processes, and human intelligence to manage the risk of technology and data we depend on.
First let’s look at some of the technical tools. We’ve grown accustomed to hearing about antivirus over the years. But as cybersecurity threats have evolved, so has antivirus. To combat today’s threats, the traditional antivirus software has evolved into predictive, cloud-connected platforms. Security teams now rely on advanced tools like EDR and MDR to stop fast-moving cyberattacks before they cause catastrophic damage.
Firewalls provide protection at the edge of the network, preventing access into your internal system when rules are broken. Spam filters work to prevent malicious email messages from reaching your inbox. One of the best protections in cybersecurity is stopping the malicious attack before it gets in front of the user.
The processes of cybersecurity aren’t discussed as frequently as the tools, but they are extremely important. Examples include risk assessment, patch management, identity and access management, incident response, security awareness training, and data backup and recovery. All of these are critical components of the cybersecurity process.
All the buzz in technology today seems to revolve around Artificial Intelligence. That magical tool that’s supposed to solve all your problems for you without any effort on your part. We don’t have enough time in this blog for me to express my opinion around that statement, so let’s focus on something we can discuss today. Human Intelligence, and how that relates to cybersecurity.
Let me be clear, you do not have a long lost relative who is a prince in a foreign country that is going to give you $100 million dollars just for you giving them approval to wire their $10 billion fortune into your bank account. I know, that stings. I’ll give you a minute to recover from the shock.
We use that reference all the time as an example of what not to do. But it’s not that easy anymore. AI (yes that AI) makes it much harder for you to detect scam email messages just by relying on human intelligence. You can be the smartest person in the room, but that intelligence alone does not protect you from a well crafted scam email that is designed specifically to play on your emotions.
Human intelligence is not just about catching the AI-crafted attacks. Human intelligence is about not doing those questionable things that expose you to unnecessary risk. Responding to the “prince’s” email, clicking on the ad that promises a crazy amount of money but little to no work, visiting that website you know is risky but you just want to see what it’s all about. These are the human intelligence actions that you can, and should, avoid.
All of these elements are part of an overall cybersecurity plan. It’s no longer enough to just have antivirus software. Today you need a full suite of tools, processes, and human intelligence to manage the risks you are facing.
Be sure to follow our weekly Tech Tips every Tuesday. You can subscribe to our Tech Tip Tuesday email digest or listen live on the radio every Tuesday at 8:35am EST. Here’s how: Subscribe Now and WRDO.
This Week's Focus Points
- Antivirus is no longer enough.
- Tools have evolved.
- Processes are critical.
- Human intelligence can't be replaced.