13.02.2024
Blog
Resilience
Cyber Security

Improving resilience: How to make your IT a rock-solid foundation

Ensuring trouble-free and secure IT operations guarantees business continuity in the event of an emergency. Find out in this article which preventative measures are key.

Philipp Kleinmanns
Senior Vice President Cross-Market Services Consulting

The Magic Triangle

In our previous blog post, we discussed the increasing regulatory requirements. Alongside the current threat posed by cybercriminals, these are one of the main drivers behind the implementation of measures to enhance the resilience of your IT systems.

In many cases, specific measures are even explicitly required. One example of this is ISO 27001, which requires the introduction of a Business Continuity Management System (BCM). The aim of BCM is to maintain business operations in crisis situations. To this end, risks are identified and measures defined to ensure business continuity in the event of an emergency.

BCM is a very comprehensive subject and takes into account not only IT but also other aspects, such as building infrastructure. In the following, however, we shall focus on the aspect of uninterrupted and secure IT operations:

Many approaches to improving stability and security begin with a risk analysis. This offers the major advantage that measures are taken particularly where there is a particularly high risk. This ensures that the measures are cost-effective. The cost-effectiveness is influenced both by the direct costs of measures (e.g. the purchase of software licences) and by indirect costs, such as those arising from more complex working methods resulting from secure systems – let’s call these ‘losses in convenience’. This results in a ‘magic triangle’ comprising level of protection, cost-effectiveness and convenience.

Preventative measures

The position within this triangle changes over time and must be reviewed regularly. Among other things, the following preventative measures should be considered:

  • Set priorities for IT security:
    Ensure that you install the latest security updates and that your staff receive the necessary training and resources to act in a security-conscious manner.
  • Implement redundant systems and backups:
    This ensures that you can get back online quickly in the event of a failure. Include offline backups in your strategy.
  • Standardise and optimise your processes:
    This ensures that your IT systems operate efficiently and reduces the risk of configuration errors. Ensure that you have clear standards for monitoring and documented procedures for incident response.
  • Invest in training and development programmes to
    ensure that your IT staff have the necessary skills to resolve IT issues quickly and effectively, and that all staff within your organisation are aware of how to use IT securely.

Last but not least: be prepared! Risks cannot be completely eliminated, even if significant investment is made in appropriate preventive measures. For this reason, reactive measures play an equally important role. However, these should not be carried out in an uncoordinated manner, but should follow an emergency plan which must be kept outside the potentially affected IT infrastructure, e.g. in printed form. This should include, amongst other things, the following points:

  • A communication plan for staff and external parties (e.g. partners and public authorities, particularly where there is a statutory duty to report)
  • An overview of the staff responsible for implementing the contingency plan
  • An overview of the critical IT systems and data that must be restored in the event of an emergency – a well-maintained Configuration Management Database (CMDB) is helpful when compiling this overview
  • List of steps for restoring critical IT systems and data, particularly immediate measures

Regular review

It is also important that this plan is regularly reviewed and tested. One thing is certain: when the time comes, there will be unforeseen events. You should therefore take into account everything you can foresee.

In the next post in this blog series, you will learn how to set up the legally required attack detection systems.

All posts from the “Cyber Security 2024” blog series:

  1. It will affect us all eventually – mandatory IT security requirements for 2024
  2. Improving resilience: How to make your IT a rock in the storm
  3. Intelligent attack detection with Security Information and Event Management (SIEM)
  4. Responding more quickly to attacks with SecOps – Part 1
  5. Responding more quickly to attacks with SecOps – Part 2
  6. Responding more quickly to attacks with SecOps – Part 3
  7. NIS2 Directive: Implementing legislation not yet in sight – what organisations should do now

Philipp Kleinmanns
Senior Vice President Cross-Market Services Consulting

Philipp Kleinmanns ist Senior Vice President Cross-Market Services Consulting bei Materna. Sein Verantwortungsbereich umfasst die kundenorientierte Optimierung von Service-Prozessen, die Entwicklung moderner Cloud-Infrastrukturen und das Thema Cyber Security.