
The technology problems facing the military are obviously different from those facing a plumbing company, law firm, medical practice, or manufacturer. But the underlying challenges are surprisingly similar: How do we protect our information? How do we keep operating when something goes wrong? How do we know whether our technology is actually secure? And how do we keep up when technology is changing faster than our organizations can?
Below are three takeaways.
Cybersecurity is a business issue, not just an IT issue
One of the clearest themes is that cybersecurity can’t simply be handed off to the IT guy and forgotten. Organizations are going to have to become more intentional about understanding and managing their technology risk, rather than simply hoping the IT guy has it covered.
As we have said before here, cybersecurity isn’t the same as IT. IT and cybersecurity are cousins, but businesses must begin to assess their cyber risk in addition to simply asking if their IT is managed. The old days of simply trusting antivirus for protection have been over for two decades.
Whether or not you are legally required to meet CMCC compliance requirements, your business requires some level of cyber risk assessment and management. Cybersecurity is not an “above and beyond” step anymore, but a baseline fundamental for every business.
That applies to defense contractors at TechNet, but it also applies to the 25-person company down the street.
Resilience matters as much as prevention
Another theme that continues to build in importance is the idea of resilience.
The military obviously has a very different definition of “business interruption” than most companies do. If a military communications system goes down, the consequences can be enormous.
But the basic question is the same for your business: What happens when something important stops working? Maybe your email goes down. Or your server gets encrypted. Your accounting system becomes unavailable. Your internet connection fails. An employee accidentally deletes something important.
Your business doesn’t get extra points because you had a good excuse. You still have customers waiting, you still have employees who need to work, and you still have bills to pay.
That’s why the conversation is gradually shifting from simply preventing every possible problem to building systems that can withstand problems and recover from them quickly. It simply isn’t realistic to become 100% foolproof against cyberattacks.
Good cybersecurity tries to keep bad things from happening. It locks your digital doors. But good resilience recognizes that some bad things are going to happen anyway, and it means being prepared with a plan to ensure your business can continue to function to protect your revenue and your reputation.
Your technology vendors are part of your security perimeter
One of the topics at TechNet was securing the defense supply chain and strengthening contractor and third-party cybersecurity.
Again, you don’t have to be a defense contractor to understand the lesson. Your company isn’t an island. Your payroll company, accounting firm, and software vendors have access to vital information. Your cloud applications store information, and your employees may be accessing company information from home, from their phones, and from devices you don’t directly control.
The question isn’t simple: “Is my company secure?”
It is increasingly:
“How secure is the ecosystem that my company depends on?”
You don’t necessarily need to eliminate every vendor that could possibly introduce risk. You do, however, need to understand what access they have, what information they handle, and what happens if they are compromised.
This also speaks to the importance of the already-discussed idea of resilience. You cannot control what your vendors and employees do. Even if you conduct your due diligence, the possibility exists that some of your information will be caught up in a vendor’s cyber laps. Again, you need to be prepared with a plan for what to do in that case.
Looking forward
Perhaps the biggest takeaway from TechNet Augusta isn’t any particular technology.
It is the direction of travel. Technology is becoming more deeply intertwined with how organizations operate, and that means technology risk is becoming business risk.
Cybersecurity isn’t going away, nor is AI, third-party risk, compliance, and (unfortunately) cybercrime
The answer isn’t to become paranoid about technology or to spend enormous amounts of money trying to eliminate every conceivable risk. The answer is to become intentional in managing that risk: know what tech you depend on, have reasonable safeguards in place, and know what to do when something goes wrong.
And, perhaps most importantly, don’t wait until something happens to figure all of this out.
The military has an enormous incentive to think about these questions before a crisis occurs because the cost of discovering a weakness at the wrong time can be enormous. Businesses should take the same lesson from a very different environment.
Whether or not you need a military-grade technology environment, you DO need to know whether your business is prepared for the technology problems that are coming and already here.
