Increasingly, geopolitical tensions are not only played out on the physical battlefield, but they are also realised in the information space, as cyber-attacks. Cyber and information risk represents a key vulnerability for organisations. No organisation can be totally secure. Having appropriate levels of data management and security in place are essential.
The most significant cyber-related threat to any organisation remains the individual. In times of volatility, it is easier to reduce your guard; to forget to question the email address; to trust the email and click on the link. The damage is done. Within the culture of the organisation, now is the time to reinforce the need for good data and information security management.
Mitigation and recovery plans need to be in place which are integrated into broader continuity plans. The complexity of the challenges that organisations face mean that plans focused upon single failures are no longer sufficient. These must have been tested and evaluated on a regular basis.
Cyber-attacks may represent one threat, but the information war also embraces other forms of intervention such as fraudulent claims and invoices.
Disruption to the organisation may include changed working patterns for individuals. These organisational changes can create information security risks, should the necessary policies and procedures not be in place.