The seriousness of cyberthreat was rammed home by a recent global bank risk management survey where 72 percent of bank CROs rated cybersecurity as the top near-term risk, ahead of credit risk.
Where nothing is predictable, the certainty of an expanding threat landscape looms large. Cybercrime is expected to cost us a whopping $8 trillion this year and $10.5 trillion by 2025. That’s more than the combined GDP of the world’s fourth and fifth largest economies. And it is hitting every sector: malware alone accounted for 15 million incidents daily in 2022, attacking everything from educational institutions to government organizations to healthcare providers.
Trends, such as the rapid digitization of everything and transition towards hybrid work, are fuelling the fire by providing criminals with an expanding attack surface and massive data pools to exploit. The concern is that as enterprises switch to hyperscale offerings to support automation or remote work, they are compounding the risk by not matching these initiatives with commensurate cybersecurity and governance measures. For example, in the latest Cloud Radar survey, 40 percent of respondents say their organizations do not have adequate policies to govern cloud deployment. This, along with a spike in the number of cloud vendors and fragmented cloud ownership decisions, is adding to cloud cost and confusion, and also creating unseen security threats.
Here are some ways in which organizations can stay on top of cybersecurity, now and in the future:
Guardrails for good governance
A key advantage of a hyperscale solution, such as public cloud, is that business users can provision infrastructure on demand, without waiting for IT support. But if there aren’t clear guidelines for who can buy, deploy or secure cloud within the organization, it can create a host of problems, including a governance nightmare and security vulnerabilities. Hence establishing guardrails for cloud governance is a must. In addition, automating enforcement by standardizing security and data management policies across environments (on-premise/ cloud/ hybrid) would lead to better governance.
Also, as enterprises increase their cybersecurity exposure by scaling capabilities, such as generative AI and Internet of Things, their IT and business leadership should work together to ensure the current technology estate is properly monitored and managed, and the organization is prepared for future risk scenarios. It is a good idea to create an internal team of legal, risk, and technical experts not involved in application development, to evaluate various solutions from a security, transparency or ethical perspective. Enterprises should create systems for maintaining documentation on guidelines, rulebooks for validation and testing, and reference architectures for responsible deployment. A review board should conduct regular audits and compliance inspections. But to be fully effective, cybersecurity should be democratized by educating employees on how to use various technologies in a secure, ethical and responsible manner.
Secure tech assets with tech guardrails
Solutions, such as DevSecOps and API-based security, help to build “secure thinking and design” into various processes. When it comes to securing AI solutions, Open Source Large Language Models do come with some safeguards preventing the generation of harmful content. In addition, enterprises should build a fortification layer to monitor both input prompts and outputs for ethical or privacy infringement. This layer can prevent sensitive or confidential information from being fed into the model, and also validate generated content before exposing it to the user.
Since there are several options, enterprises need to choose the tools and components based on whether they are looking to address security vulnerabilities, identify misinformation, weed out harmful content, etc.
Self-regulate and collaborate towards greater security
The reality is that government regulation, industry recommendations and company policies for cybersecurity will always lag digital evolution. Therefore, a compliance-driven approach to security is not enough; enterprises must also practice self-regulation. This applies to technology providers, for example AI companies, who should adopt a risk management framework to build trustworthiness across the design, development, use, and evaluation cycle of AI offerings, and also to user organizations, who must spread awareness about ethical and responsible AI practices to mitigate risks. Further, security must be democratized by encouraging all employees to share their concerns and ideas, and also by collaborating with system integration partners, academic institutions, industry associations, policymakers and government agencies to improve AI safety and governance.
Good governance needed. Now.
The proliferation of digital technologies and data – not to mention the rising sophistication of hackers – has made cybersecurity one of the biggest threats the world is facing today. It is estimated that the average enterprise encounters about 200,000 security events each day. What’s worse, organizations are compounding their risks by following inadequate security and governance practices. They need to correct this immediately by putting governance and technical guardrails in place, and by practicing self-regulation.
##
ABOUT THE AUTHOR
Anant Adya, Executive Vice President, Infosys
Anant Adya and his team are responsible for designing solutions to help customers in their digital and cloud journey. They use a combination of AI-led solution sets combined with capabilities from partner and startup ecosystem to design best solutions for customers. Cloud and Infrastructure Service line include infrastructure operations, security, data center and network transformation, cloud (public, private and hybrid), workload migration and service experience.





