Making Information Security a Strategic Priority in Companies
CIOREVIEW >> Security >> NEWS

Ype

Paulo Yukio Watanabe, Head Security Information and Data Privacy

Making Information Security a Strategic Priority in Companies

Paulo Yukio Watanabe, Head Security Information and Data Privacy
Paulo Yukio Watanabe, Head Security Information and Data Privacy, Ype

Having extensive experience in the domain, how would you describe the development of enterprise security in the industries to this day?

The development of information security in Brazil is following a significant increase in the speed implementation of processes and systems due to the multiple safety incidents that have been occurring in recent times. I believe that there is still much to do the same speed for companies providing industrial solutions are not at the same speed. I believe that the criticality of the subject has not been taken into account by suppliers, and this prevents the evolution of the information security ecosystem in the industry. It is always necessary to be thinking of alternatives for armoring industry by other paths other than by the supplier himself. There are many great challenges to maintain industrial operation somewhat protected.

What are some of the new trends that organizations are leveraging to ensure topmost security in their space?  

We are currently adopting best practices such as segregation of environment (network microsegy), double factor authentication, update systems, antivirus based in artificial intelligence, frameworks such as ISO, NIST, CIS and others, awareness for employees and suppliers, participation and discussion forums among others. We cannot stop looking at what the market offers and what companies are practicing better. We are no longer from the decade where we cannot share best practices, today to survive the business "to think outside the box."

What are some of the challenges that companies are facing while ensuring security compliance in different departments? 

I believe the greatest difficulty is the awareness of employees regarding information security practices. Many still insist on saying that information security can bring a slowness in the collaborative process of the company. However, I see small changes happen when the high leadership sponsors information security actions in order to ensure the continuity of operations. I see many colleagues by saying that the process of awareness is very ineffective when there is no sponsorship of high leadership.

  ​Many still insist on saying that information security can bring a slowness in the collaborative process of the company. However, I see small changes happen when the high leadership sponsors information security actions in order to ensure the continuity of operations. 

Can you give us a brief background about your roles in the organizations you've worked for? How does the experience augment your role and responsibility at your current organization?

In the last 10 years, I have been bringing to all companies where I worked the view that information security is a strategic issue. In my last and current experiences, information security is treated as a strategic subject, is possible check "goals" from security information are also being shared with other areas, gaining strength in the application of information security culture. Treating the subject to the strategic level, the information security person responsible also begins to account for high leadership under the risk management aspect, and this makes the subject to be treated with more priority and speed, depending on the subject matter. More responsibility for information security will have before the company.

As an ending note, what is your advice for other senior leaders and CXOs working in the enterprise security industry?

With resilience, being calm, and patience as main points, including a number of others to be treated throughout the journey. Build solid and high knowledge teams on information security, a high performance team can help faster and ensure that strategic issues are being worked as best as possible. Encourage training and updating information security concepts at all levels, from intern to senior manager. Everyone needs to be seeing what the external environment is suffering; unfortunately the suffering of others can be their salvation in the future. Get ready for the worst, make sure that unfortunately you will go through an incident that you will need to be calm to deal with your followers and their leaders. Talk, research, read, and share best practices, that are not the holders of all experience and knowledge of the cause.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.