What’s the difference between cyber security and cyber resilience?

Business magazine Forbes puts it so well: the difference between cybersecurity and cyber resilience (and why you need both).

With cyber threats such as ransomware, phishing, hacking and DDoS attacks a regular occurrence in the business world these days, cyber security has become a vital component of every business’s risk avoidance strategy because it helps to avoid:

  1. Disruption of vital business services,
  2. Reputational damage,
  3. Stiff fines from regulators as a result of personal data loss and breach.

Think of British Airways, fined 1.5% of its global turnover (more than £183 million) after customer data was breached in a 2019 cyber attack. This was the first fine delivered by the UK’s Information Commissioner’s Office (ICO) under the EU’s General Data Protection Regulation (GDPR).

Since then cyber attacks have been hitting the news with increasing frequency and, while some multinational companies can absorb a massive fine, for most small to medium-sized companies a cyber attack can be devastating. Says Forbes: “This is why all companies need to invest in cybersecurity and cyber resilience.”

What’s the difference between the two? 

Cyber security refers to a company’s ability to protect itself against, and avoid the increasing threat of, cyber crime. Cyber resilience refers to a company‘s ability to alleviate damage to its systems, processes and reputation and, crucially, to be able to carry on past the disruption.

While cyber security focuses mainly on external threats, cyber resilience covers inside threats such as human error, and minimises the effects of a cyber attack.

Because cyber threats are advancing all the time, it is fair to say that no cyber security solution can protect against every form of cyber threat, but with cyber resilience in place, it is entirely possible to lessen the impact of an attack.

What steps can I take to cover both?

Cyber security involves taking practical steps such as:

  • Installing malware protection that includes antivirus.
  • Educating your team on cyber security threats and how their careful actions help to protect the company.
  • Keeping software on all devices up to date with the latest patches.
  • Turning firewalls on to secure your internet connection.

Cyber resilience involves compiling a “cyber incident response plan” also known as a disaster recovery (DR) plan, to clarify:

  • Who is responsible for executing the DR plan
  • What needs to be done when there is a breach or disruption
  • How to get operations back to normal as soon as possible
  • How to recover lost data
  • How to communicate the incident to stakeholders
  • How to report the incident to regulators

Cyber resilience will vary from company to company but an effective way to start is to assess where a cyber attack would have the most damaging effect on your business. In which areas do you rely on technology, for example, and where do you keep your most valuable data?

Answering these questions will establish your vulnerable areas ahead of installing appropriate measures to minimise the damage of a cyber attack. A dedicated business continuity solution, for instance, enables you to maintain essential functions during and after a disruption has occurred. This is invaluable for maintaining a healthy customer service record.

As Forbes says, “Cyber security and resilience both require an investment in time, resources, and education, but that investment will be repaid many times over once you’ve withstood your first cyber attack.”

If you are unsure about your cyber resilience (or cyber security), feel free to chat with us. Every company is different and we can help you with yours.

Cyber Security Trial

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

Does your business send bulk emails?

Learn all you need to know about Google & Yahoo’s new requirements for bulk email senders.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

This field is for validation purposes and should be left unchanged.

"*" indicates required fields

Hidden

Training

We also offer certified training packages The training will cover POPIA in general. We have two options available. Once off costs. Employee Awareness Training - R490 per candidate Senior Employees Awareness Training - R650 per candidate All prices exclude VAT

Company Structure

Are you part of a group structure?*
IronTree is committed to protecting and respecting your privacy, and we'll only use your personal information to administer your account and to provide the products and services you requested. From time to time, we'd like to contact you about our products and services, as well as any other content that may be of interest to you. If you consent us contacting you for this purpose please tick the checkbox below*

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

"*" indicates required fields

Hidden
Keep me up to date

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

Give us a call:

+27 87 943 2278

Send us a WhatsApp:

+27 66 372 4061

Drop us an email:

After hours support:

+27 72 595 1066

After hours hosting support:

+27 76 102 9813

Log a support request

The reseller zone is currently out getting a facelift as we look to integrate it with our backup platform, as it stands you can overview your clients on our new backup console. If you don't know what console that is, please reach out to us.

"*" indicates required fields

Hidden

I have read and understand IronTree Internet Services (Pty) Ltd's privacy notice.

This field is for validation purposes and should be left unchanged.
One of our team members will be happy to help answer any questions you have!
Just click the chat icon in the right-hand corner.