My Vision for IT Security: From Reaction to Prevention

“What do I want to achieve with my work in IT security?” I was recently asked. When you drive a car, ride a bike, or walk on the street, you make a risk assessment and decide how to behave to arrive safely and avoid causing damage. I wish an implicit risk assessment in the development, purchase, and maintenance of IT systems and infrastructures to protect companies’ value creation and jobs.

My impression is that IT security is still a relatively new factor, much like testing internally and externally developed software was in 2003 when I started my studies. Today, investing in testing is a given in every IT project. IT professionals must understand the different types of tests and their respective advantages and disadvantages, and be able to implement them in practice.

Furthermore, I wish more published statistics about the extent and probability of errors, failures, and attacks against IT systems, so security measures can be evaluated based on these values within a company. There are already clear metrics to evaluate investments in testing. Based on the frequency and type of errors in production environments, one can identify which type of testing is missing in the development process. For security products and solutions, we’re not yet at the point where we can make informed decisions about their effectiveness.

What do you want to achieve with your work in IT security? What does this world look like?

Image by This_is_Engineering from Pixabay

essential