
In June I had the honour to act as chair at the IoTTechExpo for the IoT Innovations and Privacy and Security track at Amsterdam. It was a busy event organized around topics as IoT, Artificial Intelligence and Blockchain. When chairing the day dedicated to cybersecurity in the area of IoT innovations I found it striking to see that still so few people in the audience are aware of the risk of cybercrime especially related to the Internet of Things.
I recently published and article about the rising awareness of IoT Security. People involved professionally with IoT should be aware of the security impact, was my assumption, also due to the media presence of the DDoS and ransomware attacks that received much media attention. How wrong could I be? A representative in the audience of an IoT start-up asked a question which touched me. ‘I am aware of the security risks and have taken all kind of measures, still I am unsure what can I do to protect my start-up against state actors (hackers)?’ The drive in his approach, but also uncertainty whether he did the right thingmoved me to write this blog about my personal top 5 tips to start with as a start-up to implement a security measure immediately.
To reach a security level of 100% is not possible and also not a clever thing to do from a cost perspective. I think that it should absolutely be clear that it’s almost impossible to protect your start-up with limited means against state actors. And this should also not be your first priority. Focus on the basics first. A well-known statement among security professionals is the fact that a security plan should be top down and cost effective. Which means it should be related to the business goals first and their should be a solid business case. As for start-ups this is a tricky thing as the revenues are still small and the team focuses on the product or service first. Can security than be overlooked? No, absolutely not, but I do understand the need to prioritize. However getting the basics in security right should keep you in business. As the most common mistakes make you the most vulnerable this should be reasonable for every start-up up to fix.
My personal top 5 recommendations:
There is much more to tell about cyber security and setting the defence, but the main thing is to be aware of the risks and get a sound understanding of what you could do to protect your business. Cyber security is considered to be complex and costly and that’s understandable … information security is a technical field of expertise and risk prevention is not on most people priority list. Unknown makes unloved. Do not hesitate to consult an expert to help you out or to reach out to your peers in the industry for help.
The best thing to do in life is be prepared and think one step ahead.
I do not have the illusion of delivering a comprehensive plan for the security of a startup. This is only a recommendation. I like to hear general tips, comments and reactions.
#startup #disruption #cybersecurity #IoT # Internet of Things #security #information security