Businesses today are grappling with rising cyber risks, tougher regulations, and the challenge of securing vital data and operations during crises. We address these concerns with Ivo Popardowský from ABAS IPS Management, who explains why effective corporate security requires robust risk management practices and readiness for crisis situations.
How does ABAS IPS Management identify critical infrastructure within an organisation, and what criteria do you apply to prioritise protection for the most at-risk and expensive assets?
We do not decide what counts as critical infrastructure for our clients; sometimes, however, we prefer to draw the client’s attention to a potential oversight. Indeed, most organisations are now already subject to regulations such as GDPR, cyber laws, and DORA that mandate identifying critical assets. These rules require internal risk assessments covering processes, infrastructure, and personnel.
ABAS delivers methodology and implementation assistance while emphasising that all businesses need disaster recovery plans. The key is risk management, which matters for all organisations, no matter what industry they are in.
When thinking about a typical cyber incident that could stop operations, where do companies usually fall short in their readiness: leadership decisions, system architecture and backups, supply chain vulnerabilities, or linking physical and digital security? What minimum measures should be in place to respond to incidents without chaos?
The big problem with cyber incidents is that threats keep growing and changing – attacks that seemed outdated can suddenly work again in new contexts. Management cannot avoid responsibility anymore; laws now make executives directly liable for data protection. Securing data requires both digital and physical measures: “protect the data on storage devices and the devices themselves”. Many companies do not understand the value of their data, cannot assess the importance of their information, and therefore cannot decide how much to invest in protection. For automated processes, security costs should not exceed 30% of the potential damage. Yet the biggest threat still comes from a company’s own staff.
What does effective blackout preparation involve: which operational dependencies and scenarios need testing, how do you establish crisis communication with limited connectivity, and when does an incident stop being just an “IT problem” and become a comprehensive security and reputational threat to the entire enterprise?
Companies preparing for blackouts typically rely only on backup generators. Short outages (under 4 hours) can be managed with UPS systems for safe shutdowns. Longer outages are different – generators typically only have enough fuel for 24 hours, and water supplies fail too, making it impossible for employees to stay. The best strategy is to secure data in a protected off-site location and evacuate. Experience shows “people and information are a company’s most valuable assets”, so protecting them is paramount. ABAS offers methods for handling crisis scenarios and setting up decision-making and communication when connectivity is poor. We also have access to world-class external consultants for this purpose..
Businesses today are grappling with rising cyber risks, tougher regulations, and the challenge of securing vital data and operations during crises. We address these concerns with Ivo Popardowský from ABAS IPS Management, who explains why effective corporate security requires robust risk management practices and readiness for crisis situations.
