
Information security is not an IT issue – it is a corporate responsibility
A call after the worst-case scenario # A company calls. Ransomware. Production has come to a standstill. The first question: “How could this happen?” A better question would have been: “Why didn’t we do anything about it before?”
Many companies still treat information security as a chore – something you do because you have to. It is regrettable that regulatory pressure is often needed to make this happen, but given human weaknesses in dealing with statistics and risk, it is hardly surprising.
