Has cybersecurity pushed information protection into the background?

Home Blog Cybersecurity

In recent years, the information security discussion has shifted strongly toward cybersecurity. People talk about technical solutions, preventing attacks, SOC services, and various advanced monitoring mechanisms. At the same time, one may ask whether the original core idea of protecting information has been pushed into the background.

When looking at Nordnet’s recent events and the discussion around them, it becomes clear that technical solutions are continuously being developed, but the fundamental question is often overlooked: what is actually being protected?

Cybersecurity vs. Information Security – what is being protected?

When we talk about cybersecurity, the discussion usually revolves around protecting technology and systems. Key questions include, for example:

  • Is the network protected?

  • Is access management in order?

  • Have attacks been detected in time?

The original concept of information security, however, does not focus only on technology, but on what the information in systems means and how it is protected throughout its entire lifecycle.

Key questions in protecting information include:

  • Who owns the information and who has access to it?

  • Is the information accurate and available when it is needed?

  • Is the information confidential and protected at the right level?

  • What about the long-term retention of information and deleting data as needed?

In today’s information security field, the emphasis has shifted to protecting systems, and the information itself may be overlooked.

What did the Nordnet case teach?

When Nordnet’s customer data ended up being visible to the wrong users, it was a clear information security issue, but above all a data management and protection issue.

A technical solution may have failed, but it was the management of the information itself that led to the crisis. The confidentiality and governance of information are essential, but too often they remain in the shadow of the technical protection of systems.

GDPR and other regulations have tried to bring this perspective more strongly to the fore – this is not only about technical information security, but also about people’s rights and protecting the business’s information capital.

Is it time to shift the focus back to information?

When cybersecurity is discussed, should the conversation be brought back to the original idea of information security – protecting information?

This would mean that organizations would not focus only on protecting their systems, but also:

  • Clearly define what information is protected and why

  • Create processes that ensure the integrity and availability of information

  • Take into account the entire lifecycle of information – not only attack prevention, but also how information is handled, archived, and deleted

Protecting information is still an essential part of information security, but with the rise of cybersecurity it must not be relegated to a secondary role. Now is a good moment to examine how organizations can ensure that there is a balance between information security and cybersecurity in which the protection of information itself remains at the center.

Markku Arvekari

Markku Arvekari

Digital Transformation Expert

Evästeasetukset

Tämä verkkosivusto käyttää evästeitä parhaan mahdollisen käyttökokemuksen tarjoamiseksi. Evästeet tallennetaan selaimeesi ja ne auttavat meitä tunnistamaan sinut, kun palaat sivustolle. Ne myös auttavat tiimiämme ymmärtämään, mitkä verkkosivuston osat ovat sinulle mielenkiintoisia ja hyödyllisiä.