AI, Data and Digital

Objective: A culture of cybersecurity

Pedro Latoeiro and Filipe Domingues, co-founders of the Center for Cooperation in Cyberspace, explain how the confrontation with cybercrime has become inevitable and there is only one way to face it: to ensure that everyone in the organization is responsible for cybersecurity.

16
May 2024
4
 min of reading

In fact, the confrontation with cybercrime has become inevitable, especially for private companies. After all, they are the ones who, in Western economies, manage critical infrastructures and hold the most valuable databases and patents.  

Managers' immediate attention and action are therefore required. Doing nothing or perpetuating the illusion that you are immune to this reality can bring fatal costs: millions of euros in lost turnover; lawsuits from shareholders, customers, suppliers and authorities; and perhaps irreparable reputational damage.

The starting point for the manager's work in this area is auspicious. Recent studies agree that more than 80% of cyber-attacks are caused by human error. In other words, ensuring that everyone in the organization is responsible for cybersecurity is one of the most effective ways of protecting data.

In fact, changing behavior across the board, in the name of prevention, is by far the best remedy. That's why, from a management point of view, cybersecurity is a cultural issue rather than a technical one. It doesn't just concern the CISO or the DPO. For effective awareness and protection, the board itself must be convened at all times, together with all the functional areas.

Training managers in this area requires, first of all, an x-ray of the threats to which organizations are subject. In addition to the classic attacks of phising, ransomware, and CEO/IBAN Fraud , new malicious strategies are emerging, such as social engineering attacks using Artificial Intelligence. It is also crucial to understand that the motivation for crime is no longer limited to the financial aspect, but now includes geopolitical reasons. In the current context of war in Ukraine and fierce bipolarity between the United States and China, companies are being attacked by state actors simply because they are on one side of these rivalries.

Secondly, manager training requires knowledge of the main lines of the regulatory framework, namely the NIS 2 Directive, which must be transposed into national law by October 2024. In addition to extending the number of entities and sectors covered by NIS 1, this new legislation provides higher penalties for non-compliance as well as assigning liability to management bodies for proven negligence in cybersecurity matters.

Only after learning about the threats and legislation will we be able to adopt the best behavioral practices throughout the organization. Measures such as multiple factor authentication, hiring anti-DDoS services, regular penetration tests and offline backups should be part of everyday life. As part of this behavioral component, we also need to reflect on governance models for cybersecurity, with the acclaimed three lines of defense: implementing controls, risk supervision and control, and auditing. 

However, 100% security in the digital space is impossible. Even the best-prepared organizations can fall victim to data breaches. In this sense, managers have to prepare themselves to face a cyber-attack, they have to put themselves in the shoes of a decision-maker who suddenly finds their company paralyzed and the target of extortion by third parties. And in these chaotic hours and days, knowing what to do and how to communicate act as real beacons in the middle of the storm. 

‍

This text was written by Pedro Latoeiro and Filipe Domingues, co-founders of the Center for Cooperation in Cyberspace.

Do you know the program
Cybersecurity for Managers: from Risk to Resilience?
Published in 
16/5/2024
 in the area of 
AI, Data and Digital

Join Our Newsletter and Get the Latest
Posts to Your Inbox

No spam ever. Read our Privacy Policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
About the Author
Filipe Domingues
Co-founder of the Center for Cooperation in Cyberspace
View full profile
More articles you might find interesting
Innovation and Entrepreneurship
The Illusion of Agility and the Dilemma of Resilience in SMEs
The article examines the challenges facing SMEs in an increasingly unstable economic environment, marked by geopolitical conflicts, regulatory pressure, supply chain disruptions, and financial constraints. It argues that operational resilience is not built solely on technology or extreme efficiency, but on solid processes, alternative suppliers, close partnerships, and leadership capable of preparing the organization to continuously absorb shocks.
Institutional
Marketeer Awards 2026
Nova SBE Executive Education won the 2026 Marketeer Awards in the “Higher Education Institution” category for the sixth consecutive year, further cementing its reputation as a leader in executive education in Portugal.
Institutional
Nova SBE Executive Education Enters the Global Top 10
Nova SBE Executive Education has achieved its best ranking ever in the Financial Times Executive Education rankings: 9th in the global Top 10 for Customized Programs and among the Top 20 for Open Programs. It also retains its No. 1 position in Portugal.
See all articles