_64_mit_ganzheitlicher_sicherheitsstrategie_dein_unternehmen_besser_sch_tzen-10.jpg
Episode 642/21/2024

#64 Protect your company better with a holistic security strategy

This episode was recorded in German.

In our latest podcast episode, we dive deep into the world of information security, a topic that is critical for every company. Our guest is a true expert in the field: Iskro Mollov, Chief Information Security Officer at GEA Group, a global leader in systems for the food, beverage, and pharmaceutical industries.

Why information security matters

Statistics show that 90% of companies have already fallen victim to attacks. Respected risk barometers rank this as the single biggest business risk, which makes being prepared for such attacks essential. Cybercrime attacks are increasing, especially against the backdrop of tense geopolitical interests. On top of that, new EU regulations even establish personal liability for managing directors and board members, underscoring why this topic deserves serious attention at the highest level.

Looking at security holistically

An interesting comparison between the challenges faced by the financial industry and those faced by manufacturers shows that the former already have to ensure security through a large body of legal requirements, while the latter are less regulated but at the same time have to consider far more areas of the business from a security perspective, such as production and the supply chain, to name just a few.

Mollov explains the holistic security approach, which goes beyond IT security topics and requires a broader view. To tackle information security successfully, he points to the need for a comprehensive strategy like the one GEA has implemented. The topics are managed centrally and put into practice across eight different workstreams.

Preparing for attacks as well as possible

Mollov points out that risk remains despite every precaution, and that companies absolutely have to be prepared to respond appropriately to attacks in order to keep their business running over the long term.

The main challenges lie less in recruiting specialists, since those are available globally. What matters far more, and should never be underestimated, are these aspects: stakeholder management, leadership accountability, communication, training and engagement of existing staff, and secure in-house software development.

A positive outlook

Beyond raising awareness of risks, a decisive factor is showing the opportunities that good security work creates, because it can absolutely become an important competitive advantage.

A first important step in a holistic security strategy is finding the right CISO and positioning that role correctly within the organization, so this complex topic is seen as a whole and driven forward.

SHOW NOTES

StrategyFrame® ACADEMYIskro Mollov GEA Group Christian Underwood Prof. Jürgen Weigand StrategyFrame Podcast "Hope Is Not a Strategy"Book "Hope Is Not a Strategy" Allianz Risk Barometer