Data Security – Secure vulnerable data
Geplaatst op: 8 January 2024

In this digital age it’s crucial to protect data against unauthorized access, alteration, or removal. This requires implementation of data security protocols during transfer and at rest, effective end-of-life remediation procedures, and consideration of data security measures and third-party warranties. It is also important to protect your systems from the increasing wave of ransomware attacks. From isolated and current to offline backups, this blog will show you how organizations are implementing a comprehensive data security framework.
Benefits of data security
Data security is important because it makes sure sensitive information stays protected against possible threats such as hackers or malware. It provides peace of mind by ensuring that data can be quickly restored in the event of a failure or outage. This can happen, for example, if a system is attacked by a virus or if the server on which the data is stored breaks down. By making regular backups and storing them in a secure location, access to critical data can be quickly restored even if the original data is lost. It is also important to secure old or reused storage media to prevent sensitive information from falling into the wrong hands, even after it has been deleted.
Best practices for protecting information and vulnerable data
- Identify the risks: To protect data effectively, it’s crucial to identify the risks and implement appropriate protection. Start with identifying which data is present, where it is stored, and which data is most sensitive. Consolidate data where possible and avoid storing unnecessary data. If you replicate or cache data, make sure all copies are adequately protected. Distributed data, such as files on users’ desktops, can be easier for attackers to find and harder to control.
- Secured, coded, and authenticated application protocols for data security: Ensure that data is properly protected in transit by using secure, encrypted and authenticated application protocols. Where necessary, use virtual private networks (VPNs) for network layer encryption. Apply physical and logical access controls to protect data at rest, including disk encryption on laptops and removable media. Use file encryption and digital rights management (DRM) solutions to restrict access to data, especially when data must be shared externally.
- Standardized cryptographic algorithms for data security: To properly protect data, it is important to use current standardized cryptographic algorithms. Old or non-standardized algorithms offer less protection and may provide a false sense of security. Ensure that cryptographic materials, such as certificates and keys, are protected from unauthorized access.
- Define interfaces for data security: Define interfaces for data security that allow access to sensitive information and only expose the necessary functionalities to reduce the chance of abuse by attackers. Limit access to bulk datasets and allow users to perform arbitrary queries on sensitive datasets only if there is a legitimate business need and it is carefully controlled.
- Get third-party guarantees for data security: Get third-party guarantees for data security if you rely on others to protect your data, such as with cloud services or in your supplier. Understand what steps you can take to protect your data and seek third-party assurances. Consider your legal responsibilities, including any regulations that apply to your industry.

Best practices for effective data backups for Data Security
Making a back-up of information and data is essential for data security. That way, an organization can recover more quickly after incidents or cyberattacks. Follow these best practices to ensure that back-ups are effective and reliable:
- Determine what data is essential to the business and ensure that it is backed up regularly. This includes business data as well as any configuration data necessary for the operation of the business systems.
- Store multiple backups of important files in different locations. That means you should have at least 3 copies of the data stored on 2 different devices, with at least 1 copy in a remote location.
- Keep an offline backup separate from the internal network or in a cloud service designed for this purpose. Restrict access to credentials and servers used for backups to prevent attackers from targeting the backups.
- Keep backups over a period rather than a single rolling backup. This provides better protection if a virus or damage to the system goes undetected before the backup is overwritten.
- Test backups regularly to ensure they are effective and reliable. Make sure you know how to restore files from a backup before you actually need to.
- Reduce the risk of reinfection when restoring data from backups by reinstalling executable files from trusted sources rather than restoring from a backup. Make sure operating systems and application software are up to date on the target systems and that files are scanned with up-to-date antivirus software when they are restored.
Proper sanitization ensures that sensitive data is securely and permanently deleted
- It’s important to have an extensive policy for the correct treatment of data and information when it’s no longer being used. This policy should address reusage, reparation, removal and destruction of all storage media and devices that are able to store data. Printers, photocopiers, monitors and TVs are also part of this.
- Ensure that redundant data and information get erased safely and permanently. Failure to clean storage media puts the organization at greater risk of data breaches, which can lead to legal and reputational damage.
- When purchasing devices, it’s important to keep in mind the costs and efforts involved in sanitizing data storage devices and/or media when they are no longer needed.
- In some cases, destruction is the only option. In such cases, remember to remove any labels or markings on the device or indicating the nature of the data even before the device is destroyed.
- The procedures and equipment for sanitization and destruction should be monitored and tested regularly to ensure they are effective and comply with relevant laws and regulations.
In short…
Robust backup and security policies are critical for organizations to ensure data security and increase confidence in recovery. By implementing best practices for data security and backup procedures, regardless of where the data resides, you as an organization ensure that your backups are reliable and effective. In the event of any incidents, this will help you recover a lot faster.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Identity- and access management (IAM): securing sensitive information from unauthorized users.
Geplaatst op: 8 January 2024

The world of today is an interconnected one which makes companies, now more than ever, trust on technology and data. This dependence on technology lead to an increase in cyberattacks an security breaches A way of avoiding these security incidents is through Identity and Access Management (IAM). This blog covers the basics of IAM and its importance in the world of cybersecurity.
What is identity- and access management?
Identity- and Access Management refers to the process of managing digital identities and controlling access to resources within an organization’s network. This involves ensuring that the right people have access to the right information at the right time and that unauthorized users do not gain access to sensitive information. IAM includes various components such as authentication, authorization and user management.
IAM-process steps
- Provision of identities: The first step in the IAM-process is creating digital identities for employees, partners and customers. Data such as name, e-mail address, position and role are collected for this purpose.
- Authentication: The next step if verifying the identity of the user by authentication mechanisms such as passwords, biometrics or multifactor authentication (MFA).
- Authorization: When the identity of the user has been verifies, access to sources is granted based on role and responsibilities within the organization. In this step, permissions and privileges are assigned to users.
- Monitoring and reporting: The final step in the IAM process is to monitor user activity and generate reports on access and usage. This step helps detect any anomalies or suspicious activity that may indicate a security breach.
The importance of identity- and access management in cyber security
IAM plays a crucial role in maintaining the security of an organization’s network and data. Here are some reasons why IAM is important for cyber security:
- Improved security: IAM helps improving security by ensuring only authorized users have access to sensitive information. This helps prevent data breaches and security incidents.
- Compliance: IAM helps organizations to comply with various regulations such as HIPAA, PCI DSS and GDPR. These regulations require organizations to take measures to protect sensitive information and ensure that only authorized users have access.
- Increased efficiency: IAM helps increase efficiency by automating the process of creating and managing digital identities. This reduces the workload of IT teams and ensures that access is granted quickly and accurately.
- Cost savings: IAM can help organizations save money by reducing the risk of security incidents and data breaches. This can prevent costly legal fees, fines and reputational damage.

What do you need to do for identity and access management?
- Appropriate policies and processes: For secure access to systems and data, it is important to develop appropriate identity and access management policies and processes. The policy should clearly define who has access to what resources, why and under what circumstances. It should also take into account different types of users such as full-time and part-time staff, contractors, volunteers, students and visitors.
- Guidelines for acquiring audit data: The policy should include guidelines for acquiring audit records, how they are secured against tampering and identification of processes to be performed or authorized by more than one person. It is important to note that the policy should cover not only systems that an organization controls, but also all places where organizational identities may be used.
- Single sign-on (SSO): the use of organizational identity should be implemented for online services to help control access to those services and revoke access when someone leaves the organization. Temporary accounts created to test processes should also be removed or suspended when no longer needed.
Multifactor authentication, to improve the security of privileged accounts
To improve user account security, it is important to consider multifactor authentication (MFA) for all user accounts. It is important to choose authentication methods that are proportionate to the risk and support the ways people naturally work. User-to-service, user-to-device and device-to-service authentication should be considered when implementing MFA.
- MFA for online services: This has to be applied on all accounts for online services to protect against password guessing and theft. Users must have the ability to choose between different factors of self-authentication, such as SMS- or E-mail messages, biometrics or physical tokens, since none of these is a one-fits-all method.
- Password policy: Password policies should be implemented that balance usability and security. The goal should be to minimize the number and complexity of passwords users need to remember, for example, by using single sign-on or allowing password managers. This discourages insecure practices such as reusing passwords, choosing easy-to-guess passwords or writing them down.
- Technical security measures: Such as MFA, account restrictions or blocks, monitoring of suspicious behavior and preventing usage of weak passwords all have to be implemented to prevent password related attacks. References must be adequately protected, both at rest and during transfer, to ensure safety.
In conclusion, considering multifactor authentication for all user accounts, choosing appropriate authentication methods, implementing password policies and using technical controls are essential steps to improve user account security. By doing so, organizations can reduce the risk of unauthorized access and protect sensitive data.
In short…
Identity- and access management (IAM), is an essential part of any organization’s cyber security strategy. It helps prevent security incidents, improve compliance, increase efficiency and save costs. By implementing IAM, organizations can ensure that only authorized users have access to sensitive information and reduce the risk of security breaches.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Vulnerability Management: Proactively protecting your organization
Geplaatst op: 8 January 2024

Cyber attackers tend to target publicly disclosed vulnerabilities to exploit systems and networks. Therefore, timely installation of security updates is crucial, especially for systems accessed via the Internet. Prioritizing vulnerability management, also called vulnerability management, is essential to address the most serious vulnerabilities first, as some may be more difficult to fix than others.
By implementing a robust process for vulnerability management, you are able to gain a deeper understanding of the severity of vulnerabilities and take proactive measures to protect your organization.
In today’s technology-driven world, cyber security is extremely important for both companies and individuals. One of the most important aspects of cyber security is vulnerability management, which includes identifying, prioritizing and fixing vulnerabilities in a system or network. In this blog we’ll tell you all about vulnerability management in cyber security and the importance of it when protecting your digital assets.
What is vulnerability management?
Vulnerability management the process of identifying, assessing and tackling vulnerabilities in a system or network. It involves several steps, including:
- Identification: The first step is identifying vulnerabilities in the system or network. This can be done with vulnerability scanners, network-mapping tools and other security software.
- Prioritizing: Once the vulnerabilities have been identified, the process of prioritizing starts. Vulnerabilities need to be prioritized based on their severity and potential impact on the system. This helps deciding which vulnerability needs to be tackled first.
- Recovering: The next step is recovering the vulnerabilities, either by patching the system, updating the software or implementing additional security measures.
- Verification: After the vulnerabilities have been tackled the system needs to be tested to make sure the vulnerabilities recovered properly.

The critical role of vulnerability management in protecting your digital assets
Vulnerability management is an essential aspect of cyber security for several reasons:
- Protection against attacks: By identifying vulnerabilities and taking care of them, organizations can prevent cyber attacks from happening. This can help by protecting sensitive information and data and prevent financial loss or reputation damage.
- Compliance: Many industries must comply with regulations and standards that require vulnerability management. By implementing an effective vulnerability management program, organizations can ensure they meet these requirements.
- Proactive approach: Vulnerability management is a proactive approach to cybersecurity that can help identify and address vulnerabilities before they are exploited by cybercriminals.
- Cost-saving: Addressing vulnerabilities in a timely manner can be much more cost-effective than dealing with the consequences of a successful cyberattack.
Protecting your systems: essential steps for effective vulnerability management
Update everything regularly – strengthen your cyber security.
- It is crucial to ensure that systems stay up-to-date to maintain their security. Enabling automatic updates for operating systems and software can be practical, and you can phase in updates and implement a rollback strategy to mitigate any problems caused by problematic updates.
- By using managed services like a Software as a Service (SaaS) solution (From a reliable supplier) the burden of management can be reduced and systems will be updated regularly.
- It’s essential to check the update status of devices, understand when updates may fail, and ensure that all systems have a software update strategy.
- This updated strategy should detail how and when updates are applied, who is responsible for performing and monitoring the updates, and take into account system availability requirements and relevant dependencies while striving to minimize the time before updates are applied.
- It is also crucial to use software products that are supported by the supplier and switch to newer products as the end of the support period of older products approaches to avoid any security risks associated with unsupported products.
Best practices for developing an effective vulnerability management process
- Determine the scope: Identify the assets and infrastructure that need protection and determine the scope of the vulnerability management process.
- Make an inventory: Compile an inventory of all hardware, software and applications running on the network and keep track of the versions and configurations of each component.
- Assess the risk: Determine the potential impact and likelihood of each vulnerability to determine which ones require immediate attention.
- Plan solutions: Develop a plan to address the identified vulnerabilities based on the risk assessment and determine the most appropriate solution options.
- Implement solutions: Implement patches, updates or other mitigation techniques to eliminate vulnerabilities.
- Verify solutions: Confirm that the vulnerabilities have been dealt with and that the solutions are effective.
- Monitor for new vulnerabilities: Keep monitoring for new vulnerabilities and reassess the risks to ensure that the vulnerability management process stays up to date.
- Communicate effectively: Keep stakeholders informed during the process, from identifying vulnerabilities to implementing recovery measures.
- Document the process: Document all steps taken during the vulnerability management process, including risk assessments, remediation plans and verification results.
In short…
Vulnerability management is an essential component of cyber security that can help organizations protect their digital assets from cyber threats. By identifying, prioritizing and addressing vulnerabilities in a timely manner, organizations can prevent cyberattacks, comply with regulations, take a proactive approach to cyber security and reduce the overall cost of cyber security. So make sure you implement an effective vulnerability management program to protect your digital assets.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Architecture and configuration: an important aspect for cyber security
Geplaatst op: 8 January 2024

In today’s digital age, security is of paramount importance when designing, building, maintaining and managing systems. An important aspect of ensuring the security of systems is to pay close attention to the architecture and configuration of the system. In this blog, we will explore the importance of architecture and configuration in designing, building, maintaining and managing secure systems.
Architecture
A system’s architecture determines how its components and subsystems are organized and interact with each other. A well-designed architecture can make a system more secure by reducing the attack surface and making the system more resistant to attacks.
One approach to designing a secure architecture is to follow the principle of least privilege. This principle states that a system should grant only the minimum permissions a user or process needs to perform its tasks. Following this principle reduces the attack surface because any malicious activity is limited to the permissions allowed.
Another approach to designing a secure architecture is the concept of “defense in depth.” In this approach, multiple layers of security measures are implemented that work together to protect the system. Examples of these security measures include firewalls, intrusion detection systems and access control mechanisms. By implementing multiple layers of security, a single security flaw is unlikely to result in a breach of the system.
Configuration
A system’s configuration refers to the specific settings and options selected to make the system work. Configuration plays a crucial role in system security because misconfigured settings can make a system vulnerable to attack.
One approach to securely configuring a system is to follow industry best practices. Many organizations and regulatory agencies publish guidelines for securing systems, and following these guidelines can help ensure that a system is properly configured. Examples of these guidelines include the Center for Internet Security’s Critical Security Controls (CIS Controls) and the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework.
Another way to securely configure a system is to conduct regular security audits. These audits can reveal any misconfigurations or vulnerabilities in the system and help prioritize necessary security measures to mitigate risks. Regular security audits also ensure that the system remains secure as new threats emerge.

Benefits of building a good architecture and configuration
- Protective approach
A proactive approach to security from the very beginning of development. This can help create systems that are easier to keep secure and minimize the need for costly remediation work later.
- Trust
When a system is properly designed and configured, it inspires confidence that the security measures in place effectively mitigate the risks an organization considers important.
- Constantly monitoring and assessing
It’s not enough to just build a secure system. Managing and maintaining security over time is just as important. By constantly monitoring and assessing or auditing the security of a system, organizations can stay ahead of new threats and ensure their systems remain secure.
What measurements need to be taken?
To guarantee the safety of a system, various steps need to be taken:
- Understand what you’re building and why
It’s essential to understand what you’re building and why before designing a system. This means taking time to understand the context in which the system will function, including the risks your organization is and is not willing to accept, as well as a threat model for the system. By identifying the critical systems and components in relation to your organization’s objectives, you can focus your efforts on the most important areas.
- Follow a risk-based approach
When selecting security controls, it’s important make choices based on the risks identified and their effectiveness in mitigating the types of attacks expected based on your threat model. It’s not enough to simply implement all possible security measures; a risk-based approach ensures that resources are allocated where they are most needed.
- Adaptability to keep up with changes in the threat landscape
It’s important to think about the expected lifespan of systems and how they can adapt to a changing context. The cybersecurity landscape is constantly changing and systems must be able to adapt to new and emerging threats to stay safe.
- Implement a combination of technical and policy controls
It’s important to monitor and manage the way changes are made. This can be achieved through a combination of technical and policy checks to ensure that all changes are authorized and have undergone appropriate checks to ensure they do not adversely affect the live services. These controls should be designed so that security updates and vulnerability fixes can be applied easily and quickly, minimizing exposure to known vulnerabilities.
Multifactor authentication (MFA) for a stronger management interface
In the case of administrative accounts, MFA is particularly important, as these accounts have access to sensitive and critical functions that, if hacked, could have serious consequences.
By enabling MFA for administrative accounts, organizations can significantly reduce the risk of unauthorized access to these accounts. Even if an attacker manages to get an account’s password, they would still need to provide an additional form of identification (such as a code generated by a mobile app or a biometric scan) to gain access. This makes it much more difficult for attackers to hack into these accounts and perform malicious activities.
In short…
The architecture and configuration of a system are critical to its security. A well-designed architecture can reduce the attack surface and increase the system’s resilience to attacks, while a secure configuration can mitigate risk and prevent vulnerabilities. By paying close attention to architecture and configuration, organizations can design, build, maintain, and manage systems that are secure and resistant to attack.
If you have questions or concerns about the architecture and configuration within your organization, we can certainly help you explore different approaches to tackling compliance, or put you in touch with one of our experts who can provide more specific advice.
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these ten steps, organizations can reduce the likelihood of cyberattacks and lessen the impact of potential incidents.Learn more about the OpenSight Summer Series here!
IT asset management for robust cyber security
Geplaatst op: 8 January 2024

IT Asset Management involves identifying and managing all assets in a company or organization’s IT infrastructure including hardware, software and data. Effective asset management can significantly improve cybersecurity through a more thorough and comprehensive understanding of an organization’s IT infrastructure.
What’s the most important asset for every organization?
Assets can be defined as anything within an organization that has the potential to generate value. This can include a wide range of things such as intellectual property, customer data, various types of technology such as hardware and software, physical locations, financial capital, and last but not least, the knowledge and skills of employees.
Essentially everything contributing to the growth and success of an organization is considered an asset.
In today’s digital age, cybersecurity is paramount to protect sensitive information and prevent data breaches. Companies, organizations and individuals must take steps to make their cybersecurity robust and effective. One effective way to achieve this is to implement asset management.
How implementing asset management can improve cybersecurity
- Identifying vulnerabilities
Effective asset management allows an organization to identify all devices and software used in their IT infrastructure. This identification process can reveal outdated or vulnerable devices or software that are susceptible to cyberattacks. Once identified, these vulnerabilities can be addressed through updates, patches or replacements. - Following and monitoring devices
Asset management allows an organization to track and monitor the usage of all devices in their IT infrastructure. This monitoring can detect unusual or suspicious behavior such as unauthorized access or attempts to download malware. This information can help an organization respond quickly and effectively to possible cyber security incidents. - Maintain an inventory
Effective asset management ensures that an organization has an up-to-date inventory of all devices and software in their IT infrastructure. This inventory can help an organization keep track of the location and use of devices and create an accurate list of assets to be protected. - Improving incident response
Asset management can improve an organization’s incident response capability by providing a complete picture of its IT infrastructure. With this information, an organization can quickly and accurately identify the source of a cyberattack and take the necessary steps to mitigate its effects. - Minimize conflicts and ensure optimal performance
Asset management is a critical part of most business operations and includes various aspects such as IT operations, financial accounting, software licensing, procurement and logistics. While each of these areas may have unique requirements for its management, there is often overlap and interdependence. It’s important to integrate and coordinate management across an organization to minimize conflicts and ensure optimal performance.

List of recommendations for effective asset management
Implementing asset management requires a comprehensive and structured approach. Here are some steps organizations can take to implement effective asset management:
- Inventory
A complete inventory of all IT assets should be maintained, including hardware devices, software programs and data, along with their attributes and configurations. - Categorization
Assets need to be classified based on their significance and criticality for the organization. This helps by determining appropriate security measures. - Risk assessment
A risk assessment should be conducted to identify potential threats and vulnerabilities to IT assets and their potential impact on the organization. - Access Control
Access controls should be implemented to ensure that only authorized users have access to resources and that access rights are based on the principle of least privilege. - Monitoring
Regular checks and audits should be conducted to detect suspicious activity or potential security breaches. - Incident response
An incident response plan should be in place to ensure that security incidents are detected, reported and addressed quickly. - Patching and updates
Assets should be regularly updated and patched to fix known vulnerabilities and protect against new threats. - Training and awareness
Employees should be trained in cybersecurity best practices and made aware of their role and responsibilities in protecting the organization’s IT assets.
Cleaning up assets that are no longer of use
To minimize risk and ensure optimal performance, it’s advisable to retain only the necessary systems and data. Redundant or obsolete systems or information that can’t be tied to the needs of a business should be decommissioned, with all associated data removed and relevant accounts or credentials disabled. Retaining assets that are no longer of use can increase vulnerability and expose information without any benefit. Cleaning up such assets helps reduce unnecessary risks.
In short…
Effective asset management can significantly improve cybersecurity by providing a complete picture of an organization’s IT infrastructure, identifying vulnerabilities, tracking and monitoring devices, maintaining an inventory and improving incident response.
Implementing asset management requires a comprehensive and structured approach, but the benefits are well worth the effort. By prioritizing cybersecurity and implementing effective asset management, organizations can protect sensitive information, prevent data breaches and ensure their continued success in the digital age.
While cybersecurity is an essential aspect of asset management, it shouldn’t be limited to just cybersecurity.
Need advice or help implementing asset management? Please feel free to contact us. We are happy to help!
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
Engagement and training: The critical components for effective cyber security
Geplaatst op: 8 January 2024

Together, engagement and training can help an organization build a strong defense against cyber threats. By educating employees on the latest threats and best practices, an organization can reduce the risk of cyberattacks and minimize the damage from possible incidents.
A cyber security strategy puts people first and ensures that security measures are jointly designed to meet the practical needs of the organization in question. By fostering a positive cyber security culture where employees are encouraged to actively participate and make their voices heard, they can become one of the most valuable resources in preventing and detecting security incidents.
Providing staff with the necessary skills and knowledge through awareness, engagement and training shows commitment to their well-being and emphasizes their importance to the organization. This not only protects the company, but also builds employee loyalty and increases the value of the organization.
Why are engagement and training essential parts of cybersecurity?
- Engagement:
Cyber security engagement includes creating awareness among employees and users about the importance of cyber security, the risks and threats associated with it, and the measures they can take to protect themselves and the organization. Fostering a culture of cyber security encourages employees to be more vigilant and cautious when handling sensitive data or using technological devices. - Training:
Cyber security training is essential to provide employees with the knowledge and skills needed to recognize, prevent and respond to cyber threats. It helps employees understand best practices for securing their devices, passwords and online activities, as well as how to respond to incidents such as data breaches or cyberattacks.
The most important advantages of engagement and training
- Improved awareness regarding cybersecurity.
Regular engagement and training initiatives can help make employees more aware of cyber security risks and threats, and provide them with the knowledge they need to prevent or report suspicious activity. Engagement and training can lead to a more vigilant workforce and improved organizational security. - Reduced risk of cyberattacks.
Engaged and trained employees are more likely to recognize and report security incidents or suspicious activity, which can reduce the likelihood and severity of cyberattacks. They can also implement best practices and security measures, such as strong passwords or two-factor authentication, which can further reduce the risk of a successful attack. - Improved incident response
Well-trained employees are able to respond to cyber security incidents more adequately, reducing the impact and shortening downtime. They can also work together to prevent incidents from recurring or spreading, improving overall incident response and recovery. - Early detection of security incidents.
Employees who feel safe to raise concerns and report incidents can often detect those incidents that go unnoticed by technology. This early detection can help minimize the impact of security incidents and prevent them from escalating. - Improved organizational effectiveness
Creating a safe environment where employees feel comfortable expressing their opinions and ideas can lead to better decision-making and more innovation. This can improve the organization’s overall effectiveness and competitiveness in the marketplace. - Increased trust and loyalty
When employees have the feeling that their opinion is appreciated and that they work in a safe, supportive environment, they’re more likely to be loyal to the organization and its targets. This increased loyalty can lead to increased job satisfaction, increased productivity and reduced employee turnover.

In general, fostering a safe and open environment where employees feel comfortable reporting incidents and contributing new ideas can lead to early detection of security incidents, improved organizational effectiveness and increased trust and loyalty to the organization. This will help achieve the goal of engagement and training.
Strategies for engagement and implementation of training
To successfully implement engagement and training initiatives, it is important to consider the following strategies:
- Fine tune engagement and training to different learning styles.
Everyone has a different way of learning and being involved in something. It’s important to use different methods of training and engagement to accommodate different learning styles, such as hands-on activities, visual aids and interactive discussions. - Make engagement and training interactive
Stimulate participation and engagement by making training and learning sessions interactive. This can be done by means of group activities or scenario based exercises and quizzes. - Provide continuous learning opportunities
Cybersecurity threats are constantly evolving so it’s important to also provide ongoing learning opportunities to ensure employees stay abreast of the latest threats and best practices. - Use real-life scenarios
Real-life scenarios help make the training more relatable and practical. It can help employees understand how cyberattacks affect their job and the organization as a whole, which motivates them to take cyber security seriously. - Stimulate accountability
Hold employees accountable for their actions by setting clear expectations and monitoring their progress. This can be accomplished by regularly assessing the effectiveness of training and engagement initiatives and providing employee feedback. - Role of executives
To create a strong cyber security culture within an organization, it is critical to emphasize the importance of senior leaders setting the tone through their behavior. When senior leaders prioritize following security policies and processes and do not seek “special treatment,” they send the clear message that cyber security is a top priority for the organization. Moreover, senior leaders can serve as role models for the rest of the organization by consistently adhering to security policies and practices. This helps create a culture of accountability and responsibility when it comes to cyber security. - Allow sufficient time to make the impact of awareness campaigns visible
It can take some time to see the effectiveness of awareness campaigns, so it is important to allow sufficient time to elapse before analyzing their impact. - Align messages with your staff and organization
It is essential that the messages in awareness campaigns are relevant, achievable and do not negatively impact the way staff work. Irrelevant or unfeasible messages can have negative consequences and show a lack of appreciation for staff needs.
In short…
Understand that awareness is only the first step. While awareness is an essential first step, it does not guarantee that staff will follow the recommended behavior. It may be necessary to identify technical or cultural barriers and develop alternative solutions to ensure staff compliance with the recommendations and effective cyber security awareness campaigns. This requires tailored messages, sufficient time to assess impact, positive messaging and an understanding that awareness is only the first step. By applying these best practices, organizations can create a culture of cyber security and promote staff involvement in security initiatives
Getting help from trained professionals is something to consider. We at OpenSight can give advice and cyber awareness training to support your cyber security. Contact us today and we will gladly help you and your team move toward a better and more secure cyber environment
OpenSight Summer Series
During the OpenSight Summer Series, we publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents. Learn more about the OpenSight Summer Series here!
OpenSight Summer Series: A comprehensive guide to 10 essential cyber security measures
Geplaatst op: 2 January 2024

Cyber security is an essential part of the activities within any modern organization. It’s fundamental to have an extensive cybersecurity plan at your disposal in order to protect your organisation against financial and reputational damage caused by cyberattacks or data leaks. In this blog you’ll learn more about the ten essential steps for cybersecurity for organizations.
During the OpenSight Summer Series, we will publish weekly blogs that elaborate on the following topics:
- Risk management
- Engagement and training
- Asset management
- Architecture and configuration
- Vulnerability management
- Identity and access management
- Information security
- Logging and monitoring
- Incident management
- Supply chain security
By implementing the security measures outlined in these 10 steps, organizations can reduce the likelihood of cyberattacks and reduce the impact of potential incidents.

- Risk management
The first step in developing a robust cybersecurity plan is to identify and assess potential risks to your organization. This includes conducting a comprehensive risk assessment that identifies the different types of risks facing the organization, including external and internal threats. The risk assessment should prioritize risks based on their potential impact on the organization, the likelihood of their occurrence, and controls already in place to reduce these risks. - Engagement and training
Cyber security is a collective responsibility, and every employee must be aware of the importance of cybersecurity and their role in protecting the organization. Therefore, regular engagement and training sessions should be held to educate employees on the latest cybersecurity threats, best practices for safe online behaviour and how to recognize and report potential security incidents. - Asset management
A crucial part of cyber security is asset management. This is all about identifying all the assets of an organization and analysing their value. This includes hardware software and data. Once assets are identified, the organization can take measures to protect them, such as access control, monitoring, and encryption. - Architecture and configuration
A robust cyber security plan requires architecture designed with safety in mind. This includes implementing a secure network architecture and secure configuration management that restricts access to sensitive information and checks user rights. This also includes the implementation of firewalls, intrusion detection and prevention systems and other security measures to protect the network. - Vulnerability management
Vulnerability management is the identification and addressing of vulnerabilities within systems, applications, and networks of the organization. This includes regularly scanning for vulnerabilities, assessing the risk of each vulnerability, and taking action to mitigate the risks. - Identity and access management (IAM)
In the world of cybersecurity, Identity and Access Management (IAM), is a critical component. IAM includes managing user identities and controlling access to systems and data. It provides solutions for user authentication, authorization, and access control mechanisms to ensure that only authorized users have access to sensitive information. - Information security
Information security is the protection of sensitive information against unauthorized access, theft and destruction. for example, implementing data encryption, access controls and control measures to prevent data breaches and cyber attacks. - Logging and monitoring
Logging and monitoring are essential for detecting potential security incidents and cyber attacks. This includes collecting and analysing system and network logs, monitoring user activity and setting up automatic alerts to notify security personnel of potential threats. - Incident management
Incident management means having a plan in place to respond to security incidents and cyber attacks. Such as assembling a response team, defining roles and responsibilities, and establishing communication protocols to ensure an effective response to security incidents. - Supply chain security
Supply chain security is essential for organizations that rely on external sellers and suppliers. It implies that security measures should be taken to ensure that all suppliers and sellers follow the same security standards and have adequate security measures in place to protect sensitive information.
In short, an extensive cyber security plan is critical for any organization seeking to protect its data, reputation, and finances. The ten topics discussed in this blog provide a comprehensive framework for developing an extensive cyber security plan that can effectively protect an organization from cyber attacks. In the coming weeks, we will explore each of these topics in more detail.
Want to learn more in advance? Contact one of our experts!
Everything you need to know about ISO 27001:2022
Geplaatst op: 2 January 2024

The transition to ISO 27001:2022. What is changing and what does it mean for your organization?
Why an ISO 27001 certificate?
Within the ISO standards world, it is customary to assess every five years whether a standard should be revised. The ISO 27001 standard, considered the standard for information security, was last updated in terms of content in 2013. The time for an update has finally come, and we will tell you all about the new ISO 27001.
De ISO 27001:2013, as we know ’em
ISO 27001 is one of the most highly regarded and globally used standards for information security. It is an international standard that describes the requirements for an Information Security Management System (ISMS). An ISMS is a structured framework of policies, procedures, processes and systems used to manage and protect information security.
The now outdated version, ISO/IEC 27001:2013, has special requirements that an ISMS must meet. These include identifying information security risks, establishing security measures and monitoring performances. By complying with the ISO/IEC 27001:2013 standard, organizations can improve their
information security processes, ensure data security and increase customer confidence. The standard applies to all types of organizations, regardless of size, location or industry.
The new ISO 27001 standard
As developments in the field of security continue at a rapid pace, it is customary to update security standards every few years. It’s therefore
striking that the current version of the ISO 27001 standard dates from 2013 and has not been updated for ten years. But, now exactly ten years later, a new update has been announced. Meet the ISO 27001:2022.

The new ISO 27001 standard
As developments in the field of security continue at a rapid pace, it is customary to update security standards every few years. It’s therefore
striking that the current version of the ISO 27001 standard dates from 2013 and has not been updated for ten years. But, now exactly ten years later, a new update has been announced. Meet the ISO 27001:2022.
The main changes in ISO 27001
The new version of ISO/IEC 27001:2022 addresses the new challenges facing organizations. The changes are mainly found in Annex A, in anticipation of the publication of ISO/IEC 27002. In this Annex A, security controls have been added, removed or merged. The changes now include cybersecurity and privacy issues, while control terms have been refreshed and additional guidance has been added. This will help organizations manage risk and ensure nothing is overlooked, ensuring proper follow-up. Considering the last version dates back to 2013, there have been quite a few changes to the security controls. 11 new, 58 updated and 24 merged controls to be exact. A few examples of changing scenarios being addressed:
- The adoption of digital technologies, such as cloud and automation.
- A recent and increased adoption of these technologies.
- The recognition of cybersecurity and privacy risks.
- Reflecting the changing threat landscape, for example, with new types of malware and ransomware.
- Aligning with other best practices, such as NIST, COBIT, etc.
- Updating control language and adding additional guidance.
The key areas affected by these changes are:
- Leadership
- Business security
- IT function
- Delivery
Transition period ISO/IEC 27001:2022
In short, with the new changes going into effect with the advent of ISO/IEC 27001:2022, organizations must re-evaluate their risk assessments and reset security measures. What does that mean for your organization?
On Oct. 25, 2022, the new version of ISO/IEC 27001 was released. During the 3-year transition period, existing certificates must be transitioned to the new version by Nov. 1, 2025. After October 2023, you cannot recertify for the 2013 version. From then on, the transition audit must take place during the next scheduled audit, but can also be performed earlier as a special transition audit.
Does your organization need to re-evaluate risk assessments and re-establish security controls? If so, you have a transition period of 3 years. The transition to ISO 27001:2022 can be done either at recertification or at the annual follow-up or control audit. At OpenSight, we are happy to help you certify for the new standards.
5 steps you can take to transition to ISO/IEC 27001:2022
- Become familiar with the content and requirements of the new version:
It is critical that you familiarize yourself with the new version of ISO/IEC 27001 and understand what the changes are and mean in content from the previous version. Does your organization already have the 2013 ISO 27001 version? Then you should focus mainly on the changes that the revision brings. These are mainly in ISO 27002, or ISO 27001 Annex A. - Train your staff:
We can’t say it often enough. Make sure all employees in your organization are trained and understand the key changes and requirements. This will ensure that the entire team is up to speed on the new guidelines and practices. - Peform a GAP analysis:
To meet the new requirements, it is important to use a GAP analysis to identify where your organization is already meeting them and where adjustments or additions are needed. - Establish an implementation plan:
Based on the findings from Step 3, you can create a plan to meet the new requirements. Do set concrete actions and make clear deadlines for implementing these actions. Talk the talk, walk the walk. - Update your management system:
After implementing the actions laid out in the new action plan, update your management system to meet the new requirements. This may mean modifying existing processes or implementing new ones. Make sure you properly document and communicate these changes within your organization.
To make the transition to the new ISO as smooth as possible, it is very important to start preparing on time. By following these steps you ensure that you meet the new requirements and that your certification is renewed on time. In doing so, the experts at OpenSight are always ready to help you with questions or for advice.
OpenSight
Calling in a specialist is the wisest choice and saves a lot of time. The knowledge and experience of a specialist ensure a worry-free process. Moreover, an
independent auditor should be appointed. By taking OpenSight as a partner, you can be sure that the knowledge and experience is there to ensure the best possible process. Because of the specialized knowledge and experience in cybersecurity, you are guaranteed to obtain the ISO 27001 certificate.
Knowledge
OpenSight has been dealing with cybersecurity for companies for years. Originated out of an interest, developed into a passion and eventually formed into a company with helping services.
Experience
Numerous companies have previously partnered with OpenSight and as a result have achieved great successes regarding cybersecurity. From improved business processes to certifications and from consulting to implementations.
Documentation
Clear and accurate documentation is the foundation of cybersecurity. From the plan of action to checkpoints to recording calamities that have occurred and been resolved. In fact, most documentation is necessary for achieving and maintaining certifications. It also increases visibility into the progress and status of the management system.
Time Saving
With compliance software and help from OpenSight, you can minimize the pressure on the organization which saves an enormous amount of time. Consider, for example, the scheduling
of regular tasks that happen automatically according to the set frequency and other automations.
Integrations
Integrations with Microsoft Teams or Slack are frequently requested options. This allows tasks arising from management to be distributed within the organization. From our experience, many organizations benefit from using such integrations and maintaining, for example, their ISO 27001 management system. OpenSight can provide this.
Download the ISO 27001:2022 transition brochure
In short, with OpenSight’s service you can easily complete your certification or transition to ISO 27001:2022. You get access to experienced experts, independent advice and practical support in implementing security measures and management systems. Fill in your details below to download the brochure and find out how our ISO service can help your organization.
Risk-driven information security
Geplaatst op: 27 December 2023

Adopt a risk-based approach to information security.
Taking risks is a natural part of doing business. Risk management forms the basis for decisions and creates a healthy balance between threats and opportunities. Both are necessary to achieve the organizational objectives as well as possible. Risk management in the cybersecurity domain ensures that an organization’s technology, systems and information are protected in the most appropriate way and aligned with the things that are important to your organization. A good approach to risk management is embedded throughout the organization and complements the way you manage other business risks.
Risk management in security
Every organization has to do with risks. Most people are aware of the fact that you simply cannot erase or avoid every risk. It’s all about getting the balance. Risk management is the ideal process that helps make decisions with the right balance between threats and opportunities to best achieve organizational objectives. Risk management in the security domain helps with protecting data (and all concerned systems and technology) in an organization and deploying limited resources where it will have the greatest impact. You can make better decisions through risk management, but for this to happen, it must be embedded in the organisation.
Adopt a risk-based approach to information security.
Taking risks is a natural part of doing business. Risk management forms the basis for decisions and creates a healthy balance between threats and opportunities. Both are necessary to achieve the organizational objectives as well as possible. Risk management in the cybersecurity domain ensures that an organization’s technology, systems and information are protected in the most appropriate way and aligned with the things that are important to your organization. A good approach to risk management is embedded throughout the organization and complements the way you manage other business risks.
Risk management in security
Every organization has to do with risks. Most people are aware of the fact that you simply cannot erase or avoid every risk. It’s all about getting the balance. Risk management is the ideal process that helps make decisions with the right balance between threats and opportunities to best achieve organizational objectives. Risk management in the security domain helps with protecting data (and all concerned systems and technology) in an organization and deploying limited resources where it will have the greatest impact. You can make better decisions through risk management, but for this to happen, it must be embedded in the organisation.
What are the advantages of risk management?
Good risk management is about:
- the right information to improve decision making;
- helping delegate decision-making across the organization while maintaining appropriate board-level oversight;
- Providing a foundation to adapt and respond effectively to new threats and opportunities as they arise;
- Whether you are new to cyber risk management or are trying to assess the effectiveness of existing approaches, providing an accurate understanding through guidance. In doing so, you get a better picture of what a good approach to risk management looks like in the context of your organization.

What should you do?
Consider the broader context in which you want to manage cyber risk
Think about what your organization does and cares about: what are the business priorities and goals? This may seem like an odd starting point for cybersecurity, but it forms the basis of cyber risk management. Cyber risk management is not separate from what an organization wants to achieve but must support the organizational objectives. Think about the risks you are willing to take to achieve the organizational goals. Based on these risks, you can make decisions about the steps you need to take to manage the cybersecurity risk.
Consider what governance structures are in place to manage business risks
How does managing and communicating about cyber risks fit within those structures? Effective governance is important for good cybersecurity risk management. The reason for this? The actions that an organization takes to limit cybersecurity risks are monitored and controlled. Addressing and managing cybersecurity-related risks should be managed in a way that works for your organization.
Ensure that the organization has an adequate policy
An adequate policy approved and owned by the board of directors – outlining the risk management strategy for the organization as a whole – is a must. Make sure that the board collectively has sufficient knowledge regarding cyber security. This ensures that the board understands how cybersecurity supports overall organizational goals. Provide the board with sufficient information, in a format that is manageable when making decisions.
Understand where cyber risk management should be applied
Think about the range of technology, systems, services and information your organization uses. It is important that different sources of information are used to help identify the scope. For example, you can use asset registers and system diagrams for existing systems. For systems in development, you can start with high-level design. Talking to those who use, manage, or are affected by the systems or services will give you a better understanding of what needs to be protected and why. Don’t forget to include elements that may be beyond your direct control but are still part of the broader risk concerns like the supply chain, use of third-party services and cloud services.
Think about how employees interact with technology, systems and services
How employees deal with the various systems, networks and services within the organization is also something to think about. How are employees supported to do this in a safe and usable way? If you include this in risk management, the cybersecurity risks of the organization are further mitigated. Systems include people, processes and technology: the way cyber risk management is deployed must take into account these different elements and how they interact with each other.
Choose a cybersecurity risk management approach that fits the organization
Consider which approach to cybersecurity risk management, or a mix of approaches, is right for your organization. There are countless tools, methods, frameworks and standards to choose from. This depends on the standards or regulations that are followed within the organization, costs and/or level of knowledge. The most important part? Go for an approach that is right for your organization and that reveals good risk information about the systems and services. It is not always necessary to carry out a detailed risk assessment. Using a baseline such as Cyber Essentials to provide information about the basic controls needed is often enough to protect against most cyber risks.
Do you want to know more about the correct implementation of risk management? One of our experts will be happy to help you on your way!
