
Information security requires more than just technology: A personal perspective from Thomas Seiler, CISO at CANCOM Austria
Information security in business: Why security is more than just technology
As is well known, the umbrella term ‘information security’ encompasses a wide range of individual aspects – from IT security to the protection of critical infrastructure. Most companies, public authorities, institutions and organisers are now aware of the importance of information security . This was not always the case. However, the need for appropriate measures is now taken seriously , driven not least by the numerous national and European regulations that set the broad framework and define guidelines for action. “At CANCOM, the issue of information security is consistently practised and promoted, ” says Thomas Seiler. “We are a trusted partner to our customers, for example when it comes to implementing regulations relating to information security, ” explains Seiler. Information security is always a balancing act between usability and security. You cannot have one without the other, and vice versa. It is a matter of finding and establishing the optimal approach, the best resources and the most future-proof solutions. Which solution is used where and how depends on many factors. Information security is, of course, particularly important in critical sectors: energy supply, healthcare and so on. These essential services and facilities, with their complex processes and legal requirements, must always function and be available at all times; there must be no downtime or data loss here.
From regulation to implementation!
It is often a long road from the text of the law to the implementation of the requirements defined therein. This is where I see my role: how should I interpret this regulation in a way that is tailored to our clients’ specific requirements? How do I arrive at the optimal solutions on this basis? How, in practical terms, do we achieve a sustainable strategic and technical integration of what is set out in abstract terms in the legal text or standards? How do I assess the whole picture? What is the company’s security maturity level? What risks are involved? How critical are the systems? I will need to protect a run-of-the-mill server containing no critical data differently from a server that holds my company’s data – my crown jewels – and controls my entire infrastructure or production. We also demand the highest standards of compliance with laws and standards, as well as reliability, from ourselves – and our customers rightly expect this of us. We are a critical supplier and service provider. Anyone who chooses us can rely on our knowledge, our expertise and a productive working relationship. After all, information security is a two-way process, involving a collaborative ‘integration’ of strategy, interests and solutions that is geared towards synergies, integration, future-proofing and transparency. For us, implementing ISO 27001 and NIS2 into user-oriented solutions is not rocket science. We are not starting from scratch; rather, we have always been service providers in the very best sense of the word, and our customers expect us to be able to take these matters into account and put them into practice. Anticipation is one of our strengths: we do not wait until a regulation is laid out before us in black and white; we think ahead and are ready for implementation. In this regard, I see standards and the centralisation of our expertise as a powerful lever for implementation. This is also at the heart of our Security Policy Framework, which guides our strategy and enables us to pass on the relevant concepts and implementations to our clients.
Working together and collaborating!
Let me conclude with a brief summary. When it comes to information security – perhaps even more so than in other areas – it is essential to work together openly, transparently, constructively and productively. It’s about trust – not just in the systems, but above all in the suppliers and the supply chain as a whole. This is the critical point on which we should focus our particular attention. Information security is always about risk management. Information security can be time-consuming and demanding, and it does come at a cost. But it’s worth it. Nobody can afford uncertainties and risks. Here at CANCOM, we have the experience, expertise and teams of specialists to help you – and us – make progress in the field of information security. As CISO, I am always available to exchange ideas and discuss matters with you. We can tackle this – preferably together.
Thomas Seiler, born in 1990, CANCOM CISO, has been with the company since June 2014, initially at Kapsch BusinessCom as a first-level support engineer, and has since progressed to become CISO. His forward-thinking approach is already evident in his Master’s thesis on quantum cryptography. Thomas is a CRISAM expert and holds CISM and CISA certifications; he also has a Professional MSc in Management, specialising in Information Security Management.