Alertis got in touch with EY Belgium through a personal contact, one of the 9 recognized service providers of the cybersecurity improvement program, and that got the ball rolling. In consultation with the client, EY agrees on where the focus of the program should be. This is different for a software company, for example, than for a physical security company like Alertis. EY always starts with a preliminary process in which it performs a baseline measurement and provides a holistic insight into a number of aspects related to security: how to deal with passwords, with compliance, GDPR, how to ensure that your integrity is preserved ... . Then EY zooms in further on managing risks, how to protect your environment, identify cyber-attacks and how resilient you are if you get hacked.
EY's role was to put its finger on the sensitive area(s) of the security system on the one hand, and to provide several building blocks with which Alertis itself could complete the security circle of the company on the other hand.
During the project EY also issued a technical vulnerability report, in which vulnerabilities within Alertis were defined and immediately addressed by the Alertis IT department. In addition, EY also pinpointed several 'blind' spots within the organization which had been tackled at some time stage – for example, a password policy for the entire company – but which were not part of a broader policy. On a technical level you can correct quite a lot, but people remain the most vulnerable link in an organization. The use of private data, Google Drive, One Drive, ... is accompanied by risks that need to be well defined in advance and recorded in a policy document where the best practices and methods are explained to employees, for example at onboarding.
Prior to the project, Alertis already had a step-by-step plan in place to make itself even more secure. This improvement project has provided some building blocks to further finish the plan. Together with EY, Alertis succeeded in integrating cybersecurity into operational management.