Balance Technology and People

From

editione1.0.0

Updated October 9, 2023
Security for Everyone

When we are approaching security for the first time, it can be daunting. Not only is there a lot to think about and cover, but many of the actions we need to take are associated with technologies or technical concepts that we may not be familiar with. Depending on your background and the role you play in your company, these can be a real challenge. It can be easy to dismiss security as something you can handle when you are technical enough or when you hire someone who has that specialist knowledge. In reality, sometimes it’s that delay or reluctance that makes us the most vulnerable. There is no right time to start security or perfect skill set that prepares you for it. The sooner we get started, the more small steps we can take to reduce our risk.

While technology has a role to play in securing our data, people, and systems, it is only part of the picture. Security requires us to balance technology, processes, and human actions to change the way we face situations that could cause us harm.

For example, take malicious or phishing emails. Buying a mail security product can feel like the answer to our problems. It should block suspicious email from reaching us. However, it takes more than buying a tool for this to work; without policy and process to configure and maintain that new tool, it will not prevent malicious email.

If we do not empower our people to identify and respond to emails that do slip through the cracks as we configure our defenses, we may still suffer from the consequences of this attack.

Make Lists of What Applies to You

​important​ We will encourage you to apply the advice here as you read by making your own lists of devices, accounts, and data. As your business grows bigger, it will become more and more important to be aware of these assets, so that you can make sure they are secure. The need for security will grow over time, and having a list you can call upon and reference can be helpful in the long run.

How you keep and manage those lists will be up to you. We don’t encourage you to keep other sensitive information with those lists (like account passwords). However, these lists will give you a bit of a “security blueprint” for yourself and your business. Keep it safe, as you would any other type of blueprint-like document. I am more of a “list on my Google Keep” or “Asana board shared privately with the SafeStack team” kind of gal, but there is nothing wrong with good old fashion pen and paper lists stuck to your home office whiteboard.

If you found this post worthwhile, please share!