APAC CIOOutlook

Advertise

with us

  • Technologies
      • Artificial Intelligence
      • Big Data
      • Blockchain
      • Cloud
      • Digital Transformation
      • Internet of Things
      • Low Code No Code
      • MarTech
      • Mobile Application
      • Security
      • Software Testing
      • Wireless
  • Industries
      • E-Commerce
      • Education
      • Logistics
      • Retail
      • Supply Chain
      • Travel and Hospitality
  • Platforms
      • Microsoft
      • Salesforce
      • SAP
  • Solutions
      • Business Intelligence
      • Cognitive
      • Contact Center
      • CRM
      • Cyber Security
      • Data Center
      • Gamification
      • Procurement
      • Smart City
      • Workflow
  • Home
  • CXO Insights
  • CIO Views
  • Vendors
  • News
  • Conferences
  • Whitepapers
  • Newsletter
  • Awards
Apac
  • Artificial Intelligence

    Big Data

    Blockchain

    Cloud

    Digital Transformation

    Internet of Things

    Low Code No Code

    MarTech

    Mobile Application

    Security

    Software Testing

    Wireless

  • E-Commerce

    Education

    Logistics

    Retail

    Supply Chain

    Travel and Hospitality

  • Microsoft

    Salesforce

    SAP

  • Business Intelligence

    Cognitive

    Contact Center

    CRM

    Cyber Security

    Data Center

    Gamification

    Procurement

    Smart City

    Workflow

Menu
    • Enterprise Contract Management
    • Cyber Security
    • Hotel Management
    • Workflow
    • E-Commerce
    • Business Intelligence
    • MORE
    #

    Apac CIOOutlook Weekly Brief

    ×

    Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

    Subscribe

    loading

    THANK YOU FOR SUBSCRIBING

    • Home
    Editor's Pick (1 - 4 )
    left
    Enterprise Performance Management: The Way Forward

    Peter Law, Senior General Manager & Head, People Development & Performance, Mah Sing Group Berhad

    It's a Journey: The State of IT Transformation in APJ

    Frederic Dussart, Senior Vice President and General Manager of Consulting Services, APJC and EMEA, Dell EMC

    HR Transformation, What Really Is It?

    Gaurav Hirey, Group Director HR & Talent Development, Teledirect Telecommerce

    How Do Performance Management Systems Enable Organisations in Creating an Awesome Employee Experience?

    Merle Chen, Chief Talent Officer, The Lo & Behold Group

    Enterprise Performance Management: 4 Considerations for Successful Implementation

    Gary Lee, Global Head of Leadership and Organisational Development, Sivantos Group

    New Challenges Have Reshaped the Role of the CIO

    Kevin Kern, CEO & President, Innotas

    Utilize Value-Add Project Management

    Tom Mochal, President, TenStep

    right

    Four Reasons Why You Need a Third-Party Security Assessment

    Jeff Cann, CIO, Encore Electric

    Tweet
    content-image

    Jeff Cann, CIO, Encore Electric

    Recently, social media giant Facebook announced that a security breach exposed the accounts of 50 million of its users. There will be significant impacts caused by this breach and it is another example of why information security is scaring not only CIOs but all of their executive colleagues – at every business.

    Encore Electric follows IT best practices such as: consistent employee training on social engineering and phishing, regular security patching, and we do not allow windows admin access for employees. However, we decided earlier this year to conduct our first-ever third party security audit.

    We interviewed three firms, each with excellent credentials. We settled on one that spent a week visiting four locations where employees work – two offices and two construction sites. The external company turned up issues across 13 assessment categories.

    It was a fruitful experience. Our environment is more secure and our IT team is more security-minded. I would offer four reasons why I recommend a third-party security assessment:

    1. Best practices–IT professionals use best practices because they are effective. Our teams often do not have the time or resources to examine all aspects of our IT environments and believe that best practices will ensure that our specific environments are not vulnerable.

    When I was a software engineer, we lived by an adage: all software has bugs

    This sentiment leads to a false sense of security because when it comes to finding security vulnerabilities, it is necessary to examine everything in the environment that is connected to your company’s network. There’s no shortcut and the third party will find vulnerabilities your team could not foresee.

    2. IT systems are complex–When I was a software engineer, we lived by an adage: all software has bugs. Despite the best efforts of most commercial software manufacturers, it is not possible to eliminate all security vulnerabilities. It is likely that the third party team will find vulnerabilities in the commercial software you use that is not yet fixed (or reported) to the software manufacturer. Most appreciate the feedback when you report vulnerability.

    3. IT people don’t think like hackers–The IT people on your staff are as smart as the hackers but do not spend their time thinking of devious ways to infiltrate your infrastructure. A good third-party security firm employs people that have the skills to infiltrate your infrastructure. They will surprise you with their ingenuity to break into your systems so that your IT team will begin to view the infrastructure as a hacker, instead of an IT administrator.

    4. Everyone’s a target–At a recent industry IT event, a “white hat” security expert / hacker delivered a sobering case study on his methods for a social engineering attack. He reminded the audience that “bad guys are port scanning the internet, looking for any open doors. They don’t care what door is open.”

    Many IT leaders believe that their company is not a target because of the industry or the size of the company. The fact is hackers don’t care who they target. You have to take the initiative to prevent a security breach.

    So do not delay. Speak with your company leadership and budget for an effective IT security assessment. The assessment help security your company’s information. It will heighten your team’s awareness of security. It will provide some comfort to your company’s employees and leadership that the IT team is managing risk. Finally, you as the IT leader will sleep better.

    tag

    Information Security

    Weekly Brief

    loading
    ON THE DECK

    I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

    Read Also

    Artificial Intelligence - Myths And Truths

    Artificial Intelligence - Myths And Truths

    Geraldo Pereira Junior, Chief Information Officer, Ypê
    Sustainable Future through Innovative Technology Solutions

    Sustainable Future through Innovative Technology Solutions

    Faisal Parvez, Director, BT Business CIO
    The Future Relies on Augmented AI

    The Future Relies on Augmented AI

    Laurent Fresnel, CIO, The Star Entertainment Group
    Digitalization with the use of digital technologies/Improving business through digital technologies

    Digitalization with the use of digital technologies/Improving business through digital technologies

    Wilbertus Darmadi, CIO, Toyota Astra Motor
    How Marco's Pizza Leaned On Technology To Succeed Amid The Pandemic By Quickly Pivoting To Contact-Free Delivery And Curbside Carryout

    How Marco's Pizza Leaned On Technology To Succeed Amid The Pandemic By Quickly Pivoting To Contact-Free Delivery And Curbside Carryout

    Rick Stanbridge, VP & Chief Information Officer, Marco’s Pizza
    Bunnings  Diy Digital Transformation

    Bunnings Diy Digital Transformation

    Leah Balter, Chief Information Officer, Bunnings
    For a Smarter City: Trust the Data, Ignore the Hype

    For a Smarter City: Trust the Data, Ignore the Hype

    Brad Dunkle, Deputy CIO, City of Charlotte
    Smart Community Innovation for the Post Pandemic

    Smart Community Innovation for the Post Pandemic

    Harry Meier, Deputy Cio for Innovation, Department of Innovation and Technology, City of Mesa
    Loading...
    Copyright © 2025 APAC CIOOutlook. All rights reserved. Registration on or use of this site constitutes acceptance of our Terms of Use and Privacy and Anti Spam Policy 

    Home |  CXO Insights |   Whitepapers |   Subscribe |   Conferences |   Sitemaps |   About us |   Advertise with us |   Editorial Policy |   Feedback Policy |  

    follow on linkedinfollow on twitter follow on rss
    This content is copyright protected

    However, if you would like to share the information in this article, you may use the link below:

    https://enterprise-contract-management.apacciooutlook.com/ciospeaks/four-reasons-why-you-need-a-thirdparty-security-assessment-nwid-5742.html