On 19 September 2024, Digital Transformation host Kevin Crane was joined by Jean Carlos, VP Cyber Security, BOXT; Sasha Henry, Senior Managing Consultant, Cyxcel; and Karim Eldefrawy, CTO and Cofounder, Confidencial.
Australia has taken a groundbreaking step in cybersecurity legislation with the introduction of a new Cyber Security Bill, mandating that businesses must report ransomware payments to the government. The bill, presented to the Australian Federal Parliament on Thursday, aims to improve the country’s response to cyber threats following a series of high-profile attacks. Mandated reporting of cyber security incidents is already in force in the US and other governments around the world are expected to follow suit – there is also NIS2 and DORA in the EU. Regulating only specific types of cyber attacks poses the risk of cyber criminals coming up with new threat vectors. Hower, given that cyber security teams are already stretched by compliance exercises, pushing out new legislation may be counterproductive. It’s also a question at what point of the forensic investigation the reporting should take place and what details it should include about the attack. Reporting in cyber security is made more challenging by the speed at which incidents happen in this space.
What ZeroTrust advocates is resilience and protection when trust erodes. The framework has already been around in defence for a long time and now it’s being adopted by the commercial world. A considerable barrier to adaptation is the difficulties that data classification and governance present, as well as the micro-segmentation of unstructured data. Such a huge shift requires a complete restructuring of the network architecture, the reconfiguration of access controls in segregated OT and IT environments. Because of the size of such a project, a switch to ZeroTrust often happens incrementally. The transformation also requires a large population of engineers and training for employees to teach them how to use the technology.
Cryptography has a major role to play too. Transport Layer Security (TLS), a security protocol that encrypts network traffic to protect data and privacy, for example, has been a huge success. Applying ZeroTrust to the data can be less intrusive or disruptive than ripping off the whole infrastructure. The point of the TCP/IP stack, a set of communication protocols that govern how data is transmitted between computers on the internet, is to make you independent of the infrastructure at the highest layer. Also, if you secure the data inside files and containers, you will have security regardless of where data ends up. A business must identify where their crown jewels lie and apply different levels of security according to that, as well as how often and by how many users a particular type of data is used. Despite the complexities of ZeroTrust, if you start classifying your data today and lock it up correctly, you will see immediate results in your security posture. With the user frustration that MFA causes, there is a chance that new discussions will start about risk-based authentication. Access of users to the same data may vary too – for some, it can be read-only, while others, like finance, can also be enabled to manipulate the same data.
Businesses operating in different jurisdictions have to comply with a variety of data protection regulations, which will have an impact on what an employer can do when vetting candidates and monitoring employees. Using AI to automate data classification raises the issue of data governance creating a loop. Prior to an AI deployment, however, you need to understand the business’s data. THE LM has all the regulatory data and governmental information about rules fed into it, but when users of the model add more data, the wording may start to get skewed from what the baseline is. Therefore, it’s important for businesses to curate who can add information to the model. As a first step, businesses can start classifying data under a couple of labels (i.e., public, internal, etc) rather than doing nothing, which will alert employees to the fact that there are different types of data with different levels of security controls. Without taking any further steps, you can also just monitor the organisation in the background and use the information gained to guide your implementation of controls.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543