Al Maranon & Sarah Celovsky

14 August 2024
Topics in this article
  • Data & Digital
  • Technology
  • Technology Sourcing

In today’s rapidly advancing digital world, where data and technology are integral to every corner of an organization, cybersecurity has become a top concern for technology leaders. The World Economic Forum forecasts that the global economic cost of Cyber Threats will exceed $10.5 trillion by the end of 2024.

As businesses continue to adopt digital solutions for big data, artificial intelligence evolves (for better and for worse), and the trend of bring-your-own-device (BYOD) grows, technology leaders face numerous Cybersecurity risks. These include state-led cyberattacks, the proliferation of social media, and hacktivism—where socio-political motivated attackers seek attention through computer hacking.

To combat these challenges, typical solutions include:

  • Antivirus Software: Detects, prevents, and removes malicious software from computers and networks, enhancing security controls.
  • Firewalls: Acts as a barrier between internal and external networks to filter traffic and communication.
  • Intrusion Detection Systems: Monitors traffic for suspicious or unauthorized activity, sending alerts when potential Cybersecurity incidents are detected.
  • Encryption Tools: Maintains the confidentiality of sensitive data.
  • Endpoint Security Protection: Secures individual devices (endpoints) like mobile devices and laptops, with antivirus and device encryption.

Although the above solutions provide adequate protection against known Cyber Threats, no Cybersecurity strategy can guarantee 100% security from unknown threats. Best practices are relatively simple to implement, but staying on top of an ever-evolving challenge requires great diligence and a thorough understanding of the procurement process for these solutions.

Focusing on the following five areas will help you stay ahead of the curve:

1. regular patching

Keeping software and systems up to date is crucial, yet many companies fall behind on updates to avoid costs. However, outdated software can lead to falling out of support coverage and significant risks such as system crashes, downtime, productivity loss, and, ultimately, Cybersecurity incidents. A robust Cybersecurity assessment can highlight these gaps. According to a recent study conducted by IBM, large enterprises face significant Business impact due to unplanned application outages, resulting in revenue losses of over $400,000 per hour on average. Even more staggering is that 35% of organizations experience such outages monthly. Procurement can help build appropriate SLAs (Service Level Agreements) into contracts to set expectations and hold providers accountable for regular updates. Additionally, building relationships with suppliers and understanding their patch release schedules and policies ensures continuity of the support required to safeguard against potential cybersecurity incidents.

2. Robust authentication 

As hackers become more sophisticated, relying on a single password increases your vulnerability to Cybersecurity threats. Organizations using phishing-resistant multi-factor authentication (MFA) have a reduced attack surface, offering greater protection for the organization and peace of mind for security teams. When selecting authentication solutions, procurement can, in conjunction with the business, prioritize requirements that offer robust MFA capabilities and consider factors such as ease of implementation, compatibility with existing systems, and vendor support for ongoing updates. This process should be aligned with overarching Cybersecurity frameworks to ensure a comprehensive approach to business security.

3. consistent backup & recovery

In an imperfect world, where human error, natural disasters, and hackers pose constant threats, consistent backup and recovery protocols are essential Cybersecurity measures. Data loss incidents can be expensive to remedy, lead to significant downtime, cause compliance issues, and result in reputational damage and operational disruptions to Business operations. These disruptions can also impede business continuity, making it essential to integrate consistent backup and recovery into your Cybersecurity program. Procurement teams can build contractual protections into agreements that include penalties for downtime and disruptions and engage in negotiations to keep costs down while ensuring alignment with Business objectives.

4. keeping up with trends & solutions

In a rapidly evolving environment of Cyber Threats, staying informed about new technologies can be overwhelming. Reliance on cybersecurity SMEs, OEMs, and even VARs not only helps identify products aligned with your current cybersecurity practices but also enables strategic procurement decisions. Engaging with these experts allows businesses to proactively mitigate emerging Cybersecurity risks while optimizing costs and long-term value. Regular cybersecurity assessments and updates to detection processes are vital to maintaining a strong defense against potential cybersecurity threats. By keeping up with trends and solutions, you also enhance your incident response plan and safeguard critical systems from unauthorized access.

5. training & more training

In the ongoing battle against Cybersecurity threats, education plays a crucial role. Most providers offer training on their security tools, including an overview of best practices and detection processes. While this training comes with a cost, procurement professionals can negotiate these services, often at no additional charge. Employee error is a significant cause of data breaches and other cyber risks, so educating employees equips them as the first line of defense against potential cybersecurity threats. Consistent training also ensures that your cybersecurity efforts are continually reinforced, reducing the risk of unauthorized access and other Cybersecurity incidents.

For more information on how our procurement consultants can help your business address the challenges of changing technologies, understand best practices in cybersecurity posture, and protect against a potential cybersecurity event, get in touch now.

Let’s talk.

If you are looking to drive purposeful and profitable change, get in touch.

Contact us