Cybersecurity and environmental sustainability have more in common than what meets the eye — starting with the fact that these are the two most significant long-term challenges facing society, Fortinet's Barbara Maigret, who leads sustainability and corporate social responsibility at the vendor, penned in a blog post.
"Cybersecurity, which has become a broad sustainability issue, [is] threatening our evolving connected society and the digital economy on which individuals, organizations, and nations now rely," Maigret wrote.
And while sustainability and security pose unique challenges of their own, the approach to solving both is strikingly similar. Both issues require broad changes in behavior, investments and funding in innovation, and strict and enforceable regulations, she explained.
"At the end of the day, if enough people switch to renewable energy, enough businesses take the necessary precautions to protect their systems and data, and enough governments take efforts to level the digital playing field, I am confident we can make our world sustainable," Maigret said.
Changing Human Nature
Changing human behaviors by increasing awareness is the first step to addressing both deeper enterprise security and a more sustainable planet.
"Of course, not everyone will change, but we can tip the scales if enough people understand the issues and then adapt their behavior," Maigret said.
Climate change is largely the result of anthropogenic, or human-caused, emissions with 90 companies responsible for nearly two-thirds of all greenhouse gas emissions from 1880 to 2010, according to a research study. But being aware of, fully understanding, and caring about climate change has been arguably the biggest roadblock to actively addressing the issue.
On the security side, the human element is often the biggest challenge. A Verizon report found that 85% of data breaches are related to human error. Bringing attention to this issue and convincing individual stakeholders — like employees who may open a malicious email attachment, fail to change a server password, or misconfigure a device — that every action matters in holistic security.
"Educating individuals on the risks they should avoid through cybersecurity awareness training is the most effective way to prevent most threats," Maigret said.
Specifically, this should include providing employees with the latest information about certain threats and clearly explaining employees' role in protecting against those threats at work and at home. This is "vital for securing corporate networks and systems and keeping users safe online," she explained.
Furthermore, she recommends security risks are integrated into school curriculum to teach children growing up in an increasingly digital society about cybersecurity awareness. "Effective cybersecurity awareness motivates lasting behavior change, both professionally and personally."
Invest in Innovation
It's well accepted that technology will play a key rule in helping rebuild the systems and infrastructure required by a sustainable society, Maigret said. Substantial investments in green technology like renewable energy, carbon-free transportation, smart energy grids, and carbon-free manufacturing are crucial pieces of addressing climate change.
And as the world increases its dependence on technology to achieving a sustainable and livable future, "cybersecurity becomes mission-critical," Maigret said.
She urges cybersecurity vendors to continually push to offer services that scale and adapt to the rapidly changing digital world. For example, the industry is learning to apply artificial intelligence (AI) and machine learning to analyze data and discover breaches or unusual network activity, Maigret explained.
"[The cybersecurity industry] is also having to consolidate solutions so automation can be better leveraged to accelerate threat response time. Similarly, new security systems must be developed to protect emerging technologies, such as quantum computing, that hold so much promise," she said.
Regulation Enforces Cybersecurity, Climate Change
Self-regulation, while ideal, isn't realistic. Global regulations and international standards are needed to drive true change in behaviors, "especially if we hope to affect that change in the limited timeframe available," Maigret explained.
Emissions measurement and reporting standards are essential because they're meant to ensure transparency, integrity, and consistency in measuring organizations' emissions and energy efficiency.
While environmental reporting now is much less regulated than some argue it should be, it's an accelerating space. For example, the Securities and Exchange Commission (SEC) recently proposed a rule that would require companies to disclose their scope 3, or supply chain, emissions as part of financial disclosures.
"These and similar measures put teeth in the more generic agreements governments have adopted, like the Paris Agreement," Maigret explained.
As with climate change, enterprises successfully secure digital environments with a unified set of best practices and regulations that acts as a map and reference point. "They reduce risk by ensuring a baseline of quality and compliance for both technology and processes," she said.
Guidelines such as National Institute of Standards and Technology (NIST) and ISO 27000 certification standards are widely accepted and help enterprises implement security best practices.
"Such standards are vital for ensuring that security requirements are consistently met using best practices and compliant solutions. Current and proposed regulations are designed to have the same effect as those targeting climate change," Maigret added.
Comments