Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

BlackBerry
Keiron Holyome, Vice President – UKI, Middle East and Africa
Identifying Gaps In Cybersecurity To Reduce Organizational Risk


One of the essential threats organizations face today is a shortage of cybersecurity skills. They lack the resources because there are not enough well-trained cyber specialists available to manually spot and mitigate threats and, as recent reports show, we could be seeing a Great Resignation in technology jobs. Organizations and governments must certainly create more new resources and initiatives to encourage the younger generation to think about a career in cybersecurity, but nevertheless they must continue to protect every endpoint even while this talent shortage continues. The challenge here involves the process element; the shift from traditional architecture to a cloud-native app model requires careful planning to ensure there are no blind spots in defences which attackers can (and will) exploit.
Technology is the third most prominent concern. Technology deployment and utilization must be completed with the utmost diligence for businesses to remain productive and complete their work. However, technology is always evolving and becoming more disruptive, particularly in the field of digital infrastructure. This makes it challenging for people processing technological elements to pin down a silver bullet of architecture. This is why cloud based security, with constant updates as threats are detected by research and intelligence teams, are a vital investment.
What are some of the methods that industry leaders or executives need to fill that talent gap or develop better infrastructure?
In my opinion, making security a board-level concern, understanding your security maturity trajectory, and having an execution strategy for all of these are of great importance. Industry leaders must be aware of the security risks in the current digital era and elevate this in a clear and actionable way to board-level. As a result, they will be better able to control the risks involved in their decision-making. Half of the job is done once board-level individuals recognize the serious risks associated with cyber actors and threats.
The next crucial step is to grasp the organization's risk appetite. Small and medium businesses (SMBs) and startups face difficulties deploying security as resources are typically expensive. However, it’s important to know that traditional antivirus may leave SMBs exposed, and that successful cyber attacks could put SMBs out of business, permanently. SMBs face upwards of 11 attacks per device per day, according to recent research in BlackBerry’s 2022 Threat Report. A comprehensive approach to endpoint security and management, alongside a zero trust attitude across the business, is essential to protect against and remediate cyber threats, while providing visibility across all endpoints. Managed service providers (MSPs) can also help SMBs access these services without the need to hire internal cybersecurity staff.
The AI component of cybersecurity is differentiation for us from a security standpoint, and it’s what drew me to BlackBerry. We have a great model in which our real, next-generation AI skills provide our customers a big advantage over cyber attackers, improving their security posture to the point where they can foresee and stop daily cyber occurrences before they happen.
In terms of the next aspect of business to protect, automated workflows are increasingly popular: we’re seeing businesses testing the limits of various workflow procedures, which results in great complexity and a significant surface area footprint that gives attackers more opportunities to exploit the business. Building security into these workflows will serve modern customers in the most modern way possible.
At BlackBerry, we are also highly passionate about enabling innovation in connected technologies found in multiple industries, from internet-of-things (IoT) tech in medical devices to the future of connected electric cars. Our technology, based on world-class engineering, is unlocking the potential of the IoT across many industries, and our foundation in cybersecurity is ensuring all innovation is done with security at its core.
Could you tell me any case scenarios that helped your client get the best outcome?
Cybersecurity specialists know that attacks are incredibly frequent; the ones that hit the headlines are just a fraction of the successful attempts that can cause chaos for any business.
I believe organizations and governments need to create more new resources and initiatives to encourage the younger generation to think about a career in cybersecurity.
Any organization that experiences a hack should use the opportunity to go further to prevent repeat attacks by doing a compromise assessment to understand what caused the breach, strengthen its security posture, and deploy a preventative solution. Repeat attacks are very common: the truth is that once one attacker has found a way in, more will do the same unless a huge effort is made to block that route.
Any advice to share with your peers in the cybersecurity space, or executives so that they can improve their infrastructure?
The most crucial factor for every organization is deploying cyber security not just as a perimeter defence but in depth, throughout the entire organization. That includes beyond the office and into homes where employees work remotely and might have smart devices such as phones and smart speakers connected to the same networks as work data; new BlackBerry research reveals that 75% of European businesses take no steps to secure home internet connection of their workers, meaning attackers could find their way to lucrative business data through these devices. I believe that if you put security first and are aware of where you are in the security journey, you are moving in the right direction. In addition, having a plan in place in case an attack does happen will mean you can spare yourself the panic by contacting the professionals, addressing the problems, and patching the vulnerability before it’s attacked again.

