Protecting a cybersecurity domain requires balancing accessibility with security, layering technical and organizational controls, and making informed risk management decisions. This overview introduces the core principles that shape an effective cybersecurity program.
Protecting Your Cyber Security Domain
There's this real tug-of-war between security and accessibility. What I mean by that is that when you increase one, you're actually decreasing the other, and so there's a real problem with this.
So let me give you an example. Let's say we have some data and we need users to be able to access that data, so we network all these computers so these users have access to that data. But because that data is confidential and only certain users can have access to it, we put these controls in place to be able to screen or protect that data from unauthorized access, from threats out there that want to access that data. So the most secure thing we can actually do to protect that data is just unplug everything. Just don't give anybody access to that data. That is the most secure thing that we can do. And so there's this real tug-of-war, with: well, that's not reasonable, because now what good is that data? It's useless data if people can't access it and use that data. And so we really have to find this balance between the two.
One reason why I bring this up is because it's a real challenge of IT departments and security departments, and your cybersecurity program, finding this right balance. So there are going to be times when you're going to have to listen to your users and find out what they're complaining about, and either pull back some of the security measures, or change some of the security measures, or maybe implement new security measures. There's some changes that you're going to have to make, because you have to facilitate the business doing business. That's what they're there for. And if you constantly are putting up blockers, then that's going to be problematic.
But the flip side is true as well. The flip side is, if you never say no to anyone, then is it really a security program? If every exception that comes along the way you approve, is it really a security program? So finding that right balance between security and accessibility is a pretty critical part to all of this.
Just a quick reminder: when I'm talking about cybersecurity, we can think of it in as strict a sense of the term as what cybersecurity is, or we're going to actually just define this as anything that falls under your umbrella. Anything that falls under your purview of control, anything that's expected that you are going to help implement security measures for. So that's how we're defining cybersecurity domain: anything that you're going to have to manage and be in charge of.
We'd also talked about that term defense in depth, which just means that we're going to put multiple safeguards in place for any particular resource. So for instance, if that resource is data, we're not going to just put the gate there, because the gate could be left open. We're going to also put a guard there, but the guard could also be bribed or blackmailed. And so we're going to also encrypt the data. So we're putting multiple measures in place to safeguard this data.
There are a lot of technical solutions that we're going to want to put in place to make sure we're safeguarding that data. We actually have a whole module on the technology, specifically around networking. And we're also going to talk about that when we talk about confidentiality, integrity, and availability.
You're going to want to have a fully functioning security program, because the only way that you're going to get a group of people and processes and systems all set up to be as secure as possible is if you have somebody that is looking at the overall picture from a security standpoint and figuring out where the weaknesses are, and doing the training and making sure the training is happening. Otherwise, you're relying all on the individual knowledge, from a security standpoint, of all the individuals. And one person who doesn't really know what they're doing can expose the whole company.
That security program has a bunch of controls on there to make sure that people are actually following through with what the policies say that they're going to follow through. It's not just enough to have a policy out there, but that the control actually backs it up to reinforce it, that there's some sort of disciplinary actions or some sort of consequences if things are not done in a secure manner.
One of the things that can help us implement those controls is some sort of framework — a framework that helps us set up our policies, standards, procedures, and controls to make sure that they're at a level that's acceptable for that business.
Really, a lot of this boils down to risk management. And that's because you could do everything right and things still go wrong, or you could do everything wrong and things still go right for you. So it's not as clear-cut as you would think it would be. There are certain things that you'll implement that help protect your networks, help protect your cybersecurity domain, but it's not foolproof.
And so what you do is you assess: what is the cost of implementing this? What is the risk if I don't implement this? And then you weigh those out to determine what things you're going to implement and what things you're not going to implement, or at least put things into a priority order. So a lot of this is around risk management.
What we went over is things like security versus accessibility and how there's a balance between those two. We talked about the cybersecurity domain and what that looks like. We talked about defense in depth, and making sure you're protecting your resources from multiple angles, multiple ways. We just briefly mentioned technical solutions. And then we talked about a cybersecurity program, the fact that you really need a cybersecurity program for businesses. And then we wrap things up talking about, or just mentioning really, risk management.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →