APAC organizations urged to evolve security strategies to ensure business resiliency in the post-pandemic world
By Enzo Luna

A year into the pandemic, organizations have been able to sustain competitiveness by pivoting quickly to digital-first strategies. While the investment leads to greater productivity, the accelerated digital transformation has also created new opportunities for cybercriminals. According to the IDC Asia/Pacific CxO Study 2021, optimization and risk management are now key C-Suite priorities and organizations need to move ahead in more strategic ways.
Fortinet Philippines, together with FortiGuard Labs, organized a discussion to help companies understand the need to do more to ensure that organizations align security and c-suite strategies to ensure business resiliency.
Organizations across Asia Pacific that adapted quickly to the pandemic by accelerating their digital transformation could have their hard-won resiliency threatened due to misalignment between business priorities and technology strategies, but a holistic, carefully-aligned security approach and the right partnerships would help them retain their resiliency gains.
A new InfoBrief by IDC, a leading provider of global IT research and advice, spotlights this imperative and reality, reinforcing the commitment by cybersecurity leader Fortinet® to helping CISOs and their security teams remain relevant in a digital-first world.
Sponsored by Fortinet, the IDC InfoBrief: Stop Reacting, Start Strategizing (August 2021 IDC Doc #AP241253IB) outlines the unique trends, risks and challenges for businesses in six economies across the region alongside a pattern of mismatched business and technology concerns.
Paradox of Misaligned Priorities
According to IDC's research, CxOs cited building resilience/mitigating risk (61%) and cost reduction/optimization (63%) as top business priorities. For technology teams, both IT security investments and a shift to hybrid cloud models have been proven to address the risk issues of continuity and security. Yet, IDC has found that implementing security technologies to reduce risk (33%) is one of the lowest ranked technology priorities.
CISOs in all markets are challenged with recruiting talent which is critical to the success of IT security teams. In contrast, improving the ability to attract and retain the workforce was seventh in terms of C-suite business priorities for 2021.
Within this paradox of misaligned priorities, CISOs and cybersecurity strategies must evolve to complement the business and achieve true resiliency.
“Keeping the business safe even as cybersecurity threats escalate and the organization’s attack surface expands remains the core concern of the CISO. But to ensure that their team makes a positive contribution to the overall business, tech leaders now need to also align their security strategies with other C-suite priorities, like optimizing costs, enabling business growth, and improving business resilience,” said Louie Castañeda, country manager, Fortinet Philippines. “Stymied by the misalignment of C-suite priorities and recruitment concerns, CISOs that work with the right partners will be best able to devise the cybersecurity strategy holistically and execute a successful cybersecurity program.”
Threat Landscape
Accordingly, to IDC, the Philippines’ top risk concerns are existing corporate network (40%) and around integration with existing operational technology (36%).
In addition, the latest FortiGuard Labs Global Threat Landscape Report from the first half of 2021 demonstrates a significant increase in the volume and sophistication of attacks targeting individuals, organizations, and increasingly critical infrastructure. The expanding attack surface of hybrid workers and learners, in and out of the traditional network, continues to be a target.
Locally, attacks are also rising. Between January to July this year, the National Computer Emergency Response Team (NCERT) has handled 601 incidents with Malware and Malicious Files (204), Unauthorized Scanning (140), and Brute Force Attack (99) as the top three cases.
Organizations face risks and a threat landscape with attacks on all fronts. However, IDC’s Asia/Pacific Digital Resilience Scorecard revealed that only 33% of organizations in the Philippines have a robust approach to cybersecurity.
“We are seeing an increase in effective and destructive cyberattacks affecting thousands of organizations in a single incident creating an important inflection point for the war on cybercrime. Now more than ever, everyone has an important role in strengthening the kill chain. Aligning forces through collaboration must be prioritized to disrupt cybercriminal supply chains. Shared data and partnership can enable more effective responses and better predict future techniques to deter adversary efforts. Continued cybersecurity awareness training as well as AI-powered prevention, detection, and response technologies integrated across endpoints, networks, and the cloud remain vital to counter cyber adversaries,” said Derek Manky, Chief, Security Insights & Global Threat Alliances, FortiGuard Labs.
Best Practices
Taking these trends and challenges into account, organizations are urged to adopt a range of business and security strategies to ensure they can continue to operate successfully and stay resilient as IT architectures and security risks evolve at pace. The recommendations include:
Ensure Alignment of Business and Technology Priorities and Processes
Effective security requires ongoing reinforcement from the executive level down. Organizations have to review their security strategy and make sure it is aligned with their business priorities. Employees now work from anywhere in the new normal and to secure a remote workforce, organizations must align business processes such as finance and HR with best practices around communication privacy and authentication. These processes should also align with cultural processes that promote effective communication in an agile, trust-based environment.
Ensure Your Cybersecurity Architecture Can Support New Business Architecture
To secure a distributed workforce, organizations have to update network architectures. Data privacy, integrity, and confidentiality need to be kept top of mind and applied across the network, not just for remote workers, as business applications and workflows need to span from the endpoint to the core network to the company’s “distributed edge” in the cloud. Securing this distributed environment requires cybersecurity solutions that are both integrated and automated.
Deploy a holistic security solution
As organizations accelerate their digital innovation, ensuring their security can keep up with today’s fast-evolving threat landscape is critical. What used to be known as the “network perimeter” is now splintered across the infrastructure due to the explosion of network edges, work from anywhere, and multi-cloud models. Organizations need a broad cybersecurity strategy, implementing a platform with end-to-end security, and a single pane of glass approach to management offering full visibility across the entire attack surface.
Adopt a zero-trust approach
To respond to increasing and evolving threats, best practices now stipulate a "trust no one, trust nothing" attitude toward network access. IT teams must move toward a zero-trust approach to cybersecurity, which means all users, all devices, and all web applications from the cloud must be trusted, authenticated, and have the right amount of access privilege.
Simon Piff, Vice President of Security Practice, IDC Asia/Pacific, said: “This IDC InfoBrief underscores the continuing relevance of CISOs and security teams in a digital-first world. We see a need for CISOs to refine and align their strategies with C-suite concerns, and to combat complexity and resource shortfalls today with trusted security partners which can provide expertise and insights that would be otherwise out of reach.”
Cybersecurity industry veteran Fortinet has a broad portfolio of complementary cybersecurity solutions that enable efficient, self-healing operations and a rapid response to known and unknown threats. Its Fortinet Security Fabric brings holistic end-to-end security to organizations of all sizes to enable broad visibility, seamless integration and automation across the entire digital attack surface and lifecycle, with converged networking and security across edges, clouds, endpoints and users.