
Arash Ghazanfari at Dell Technologies describes the three stages of moving towards a mature cyber-security posture
Cyber-attacks on businesses remain a common threat – so much so that around 7 in 10 businesses (71%) report that cyber-security is a high priority for senior management. Yet, despite this, IT leaders are still struggling to protect their data from cyber-attacks.
According to our research and measurements as part of the 2022 Data Protection Index, 67% of IT leaders worry their existing data protection measures may not be sufficient to sustain malware and ransomware threats. This shows a widespread lack of confidence in the maturity of the cyber-security solutions in place across many companies.
When it comes to ensuring robust protection over cyber-security, organisations need a strategy that addresses three key areas as a priority. Given the scale of the issue and the perception that achieving strong cyber-security is challenging enough to become overwhelming, it can be helpful to approach the problem by breaking the goal of advanced cyber-security into manageable ‘phases’ that work together to fortify the business.
Firstly, it’s imperative to think about reducing the attack surface area of the organisation. The attack surface represents potential vulnerabilities and entry points that malicious actors can exploit. To enhance security, the IT team must minimise the attack surface across all domains, including edge, core, and cloud. This involves implementing preventative measures, including a Zero Trust framework, data isolation and strict access control.
Zero Trust and strict access achieve similar goals: to regulate who or what can get into computing environments and ensure layers of additional checks based on the belief that anyone and anything can be a bad actor trying to penetrate a system.
However, where vulnerabilities are identified, swift patching of systems to plug holes is essential, as are ongoing assessments of where these vulnerabilities may occur. On top of this, segregating data into separate environments, containers, or storage units can minimise the risk associated with unauthorised access, data breaches or other forms of cyber-attacks.
Often, the most significant vulnerability is the workforce itself, so training employees to recognise and report potential security threats, phishing attempts, and social engineering tactics will help to minimise the risk of successful attacks that exploit human vulnerabilities.
The next phase involves detecting and responding to threats. Advanced threat detection technologies and methodologies can identify and respond to known and unknown threats. These technologies include implementing intrusion detection and prevention systems (IDS), identifying ‘anomalies’ and unusual patterns that deviate from established norms, and real-time traffic monitoring for overall visibility of network activity to encourage quick detection and the opportunity to rectify.
Using automation, software defined and declarative security controls, and technologies such as machine learning or deep learning, can help speed the detection of threats. Further, partnering with professional services can provide expertise in threat intelligence.
Finally, being prepared to respond to and effectively recover from an attack increases resilience and confidence in the security system overall. Effective recovery requires a well-defined incident response plan that outlines clear response protocols that are tried and tested through practice runs.
A tested and well-practised Incident Response and Recovery plan fosters good communication and coordination between internal teams, professional services, and partners and helps meet business uptime SLAs. Regular backups of critical data and systems, immutable, isolated and/or secure offsite storage solutions and data encryption can ensure a speedy recovery of your data.
Advancing cyber-security maturity in this way is essential to combat the evolving threat landscape. Reducing the attack surface allows businesses to minimise vulnerabilities and potential entry points for attackers. Proactive threat detection and response mechanisms enable swift identification and mitigation. Effective recovery strategies ensure that companies can restore operations and minimise the impact of a cyber-attack.
Additionally, by collaborating with an experienced business partner, businesses can establish a comprehensive security posture that protects against evolving threats.
As technology advances, so must our approach to cyber-security to safeguard our data, our technology powered business capabilities, and to maintain trust in the digital realm.
Arash Ghazanfari is UK CTO at Dell Technologies
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543