Has cybersecurity pushed information protection into the background?

Home Blog Cybersecurity

In recent years, the information security discussion has shifted strongly toward cybersecurity. People talk about technical solutions, defending against attacks, SOC services, and various advanced monitoring mechanisms. At the same time, one can ask whether the original core idea of protecting information has been pushed into the background.

When looking at Nordnet’s recent events and the discussion surrounding them, it becomes clear that technical solutions are being developed continuously, but a fundamental question is often overlooked: what, exactly, is being protected?

Cybersecurity vs. Information Security – what is being protected?

When we talk about cybersecurity, the discussion usually revolves around protecting technology and systems. Key questions include, for example:

  • Is the network protected?

  • Is access control in order?

  • Have attacks been detected in time?

However, the original concept of information security does not focus only on technology, but on what the information in systems means and how it is protected throughout its entire lifecycle.

Key questions in protecting information are:

  • Who owns the information and who can access it?

  • Is the information intact and available when it is needed?

  • Is the information confidential and protected at the right level?

  • What about long-term retention of the information and deleting data as needed?

In today’s cybersecurity landscape, the focus has shifted to protecting systems, and the data itself may be overlooked.

What did the Nordnet case teach?

When Nordnet’s customer data ended up being visible to the wrong users, it was a clear information security issue, but above all a problem of information governance and protection.

The technical solution may have failed, but it was information governance itself that led to the crisis. The confidentiality and management of information are central, but too often they are overshadowed by the technical protection of systems.

GDPR and other regulations have tried to bring this perspective more strongly to the forefront – it’s not just about technical cybersecurity, but also about people’s rights and protecting a business’s information capital.

Is it time to shift the focus back to information?

When talking about cybersecurity, should the discussion be brought back to the original idea of information security – protecting information?

This would mean that organizations would not focus only on protecting their systems, but also:

  • Would clearly define what information is protected and why

  • Would create processes that ensure the integrity and availability of information

  • Would take into account the entire information lifecycle – not only preventing attacks, but also how information is handled, archived, and deleted

Protecting information remains an essential part of information security, but with the rise of cybersecurity it must not become secondary. Now is a good time to consider how organizations can ensure there is a balance between information security and cybersecurity, where the protection of the information itself remains at the core.

Markku Arvekari

Markku Arvekari

Digital Transformation Expert

Please wait. This content has not yet been translated into the selected language, so it is being translated now. This may take a moment.
Markku Arvekari
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.