Connect with us

Business

Webinar on ‘Security of Information Assets: What the Board Needs to Know’

Published

on

The Sri Lanka Institute of Directors (SLID) together with EY organized a webinar, moderated by Manil Jayasinghe-Partner, EY on “Security of Information Assets: What the Board Needs to Know” recently to update the knowledge and understanding of Board members on the increasing cyber security risks and threats to information assets of an organization brought about by the rapid wave of digitalization and resulting changes in the way organizations work in response to the on-going pandemic.

The webinar also discussed strategies and best practices on how best to mitigate these risks in securing information assets while ensuring business continuity, loss minimization and quick, safe recovery in the event of a breach. The keynote address was delivered by Dileepa Lathsara-CEO, TechCert and the panel comprised of eminent tech and business leaders Madu Ratnayake-Executive Vice President, CIO/GM Virtusa and D. Soosaipillai-INED of Listed Companies.

“It is important to define what information assets are so that security can be provided to those assets. Contrary to the misconception that information assets are only the application systems or the systems where staff work on and the data that resides on those systems, information assets include supporting infrastructure such as switches, patch panels, routers, servers and all other equipment, and application systems including confidential corporate information in those systems. It is also important to identify where corporate information is stored and who has access to it” said Dileepa Lathsara-CEO, TechCert.

“Boards should get involved in handling cyber security risk by firstly setting a security tone for the organization so that everyone takes security seriously and also ensure that the required resources are made available. Boards can focus on the actual requirements of information security by adopting and adhering to security frameworks, standards, acts and directives such as NIST and ISO27000 series, PCI-DSS rather than having the IT security team re-invent the wheel” he added.

He further stated that cyber security should be incorporated into the digital transformation chain and should not be a mere afterthought to be plugged in at the end. Cyber accountability is also important in that it is the organization’s ability to demonstrate that they have good cyber hygiene to ensure, in case of an eventual attack, the ability to track back to a unique event/person or group responsible with admissible evidence which also aids in quick rectification and recovery. Dileepa also emphasized that it is important to make informed and optimal investments in cyber security mitigation which can be calculated preferably as Annualized Loss Expectancy (ALE) as against ROI since security is about loss prevention and not about earnings where ALE is calculated as the cost of a security incident x chance that the incident will occur in a year.

Panelist Madu Ratnayake said that it is essential and fundamental to have the right people in the security team led by a CISO (Chief Information Security Officer) and that cyber security is a journey and not a destination as security is evolving. The Boards should comprise of members who have expertise on security given that most companies are going digital and the risk becomes crucial.

Panelist D. Soosaipillai said that the first thing is to find a security standard to be adopted in the organization without which there will be limitless spending on security without knowing what the benefits are. The organization should have a security vertical such as a CISO or IT Security, which is where the Boards will look at to establish ownership for IT security. He also suggested that Board does regular, if not half yearly Vulnerability Assessment and Penetration Testing (VAPT) by external 3rd parties into the systems/security matrix of the organization.



Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business

AHK Sri Lanka champions first-ever Sri Lankan delegation at Drupa 2024

Published

on

The Delegation of German Industry and Commerce in Sri Lanka (AHK Sri Lanka) proudly facilitated the first-ever Sri Lankan delegation’s participation at Drupa 2024, the world’s largest trade fair for the printing industry and technology. Held after an eight-year hiatus, Drupa 2024 was a landmark event, marking significant advancements and opportunities in the global printing industry.

AHK Sri Lanka played a pivotal role in organising and supporting the delegation, which comprised 17 members from the Sri Lanka Association for Printers (SLAP), representing eight companies from the commercial, newspaper, stationery printing, and packaging industries. This pioneering effort by AHK Sri Lanka not only showcased the diverse capabilities of Sri Lanka’s printing sector but also facilitated vital bilateral discussions with key stakeholders from the German printing industry.

Continue Reading

Business

Unveiling Ayugiri: Browns Hotels & Resorts sets the stage for a new era in luxury Ayurveda Wellness

Published

on

Kotaro Katsuki, Ambassador for the Embassy of Japan

In a captivating reimagining of luxury wellness tourism, Browns Hotels & Resorts proudly unveiled the exquisite Ayugiri Ayurveda Wellness Resort Sigiriya. This momentous occasion, celebrated amidst a vibrant and serene grand opening on the 6th of June, heralds a new chapter in the Ayurveda wellness tourism landscape in Sri Lanka. Nestled amidst 54 acres of unspoiled natural splendour, Ayugiri features 22 exclusive suites and stands out as the only luxury Ayurveda wellness resort in the country offering plunge pools in every room, rendering it truly one-of-a-kind.

The grand opening of Ayugiri Ayurveda Wellness Resort was an enchanting event, where guests were captivated by the melodies of flutists and violinists resonating through Sigiriya’s lush landscapes. As traditional drummers and dancers infused the air with vibrant energy, Browns Hotels & Resorts’ CEO, Eksath Wijeratne, Kotaro Katsuki, Acting Ambassador for the Embassy of Japan and General Manager, Buwaneka Bandara, unveiled the resort’s new logo, marking a significant moment witnessed by distinguished guests from the French Embassy, Ayurveda and wellness enthusiasts along with officials from the Sigiriya area, LOLC Holdings and Browns Group.

“Our strategic expansion into wellness tourism with Ayugiri Ayurveda Wellness Resort Sigiriya symbolises a significant milestone for Browns Hotels & Resorts. Wellness tourism has consistently outperformed the overall tourism industry for over a decade, reflecting a growing global interest in travel that goes beyond leisure to offer rejuvenation and holistic well-being. By integrating the timeless wisdom of Ayurveda with modern luxury, we aim to set a new standard in luxury wellness tourism in Sri Lanka. Whether your goal is prevention, healing, or a deeper connection to inner harmony, Ayugiri offers a sanctuary for holistic well-being” stated Eksath Wijeratne.

Ayugiri encapsulates the essence of life, inspired by the lotus flower held by the graceful queens of the infamous Sigiriya frescoes. Just as the lotus emerges from the murky depths, untainted and serene,

Ayugiri invites guests on a journey of purity and rejuvenation, harmonised with a balance of mind, body and spirit, the essence of nature, echoes of culture and the wisdom of ancient Ayurvedic healing.

Continue Reading

Business

HNB General Insurance recognized as Best General Bancassurance Provider in Sri Lanka 2024

Published

on

HNB General Insurance, one of Sri Lanka’s leading general insurance providers, has been honored as the Best General Bancassurance Provider in Sri Lanka 2024 by the prestigious Global Banking and Finance Review – UK.

The esteemed accolade underscores HNB General Insurance’s unwavering commitment to excellence and its outstanding performance in the field of bancassurance. Through dedication and hard work, the HNB General Insurance team has continuously endeavored to deliver innovative insurance solutions, cultivate strong relationships with banking partners, and provide unparalleled service to customers nationwide. This recognition is a testament to the team’s dedication and relentless pursuit of excellence in the bancassurance business.

“We are honored to receive this prestigious award, which reflects our team’s tireless efforts and dedication to delivering value-added insurance solutions and exceptional service through our bancassurance partnerships,” said Sithumina Jayasundara, CEO of HNB General Insurance. “This recognition reaffirms our position as a trusted insurance provider in Sri Lanka and motivates us to continue striving for excellence in serving our customers and communities.”

Continue Reading

Trending