The data must flow (Part 1)

(with apologies to Frank Herbert…)

It may be hard to imagine now, but it wasn’t that long ago that discerning business leaders were able to have thoughtful discussions on the synthesis of technology and business strategy while scarcely ever uttering words about cybersecurity. 

How times have changed. 

Today, cybersecurity concerns touch most every aspect of business operations as companies and governments have deployed substantial digital assets and vulnerabilities abound. In fact, the threat economy now rivals the GDP of advanced countries. By one estimate alone, the World Economic Forum calculates the cost of cybercrime at $10.5 trillion USD in 2023. And it’s rising.

Business leaders are adapting strategies to meet the changing times. For example, the influential Director’s Handbook on Cyber-Risk Oversight, recently released by the National Association of Corporate Directors (NACD), sets its first principle as “Directors need to understand and approach cybersecurity as a strategic, enterprise risk, not just an IT risk.” 

Investments in cyber are also changing: 65% of organizations plan to increase cybersecurity spending in 2023. Gartner projects that spending on information security and risk management products and services will grow 11.3% to reach more than $188.3 billion this year alone.

An Occult View of the Cyber-Enabled Economy

But there’s a deeper level to uncover: the lifeblood of our deeply connected global system is data. At this concealed level, global business is deeply challenged by the complexities of cross-border information flows, cybercrime, data privacy, new frameworks, and increasing or changing cybersecurity regulations

Business leadership today needs to pay particular attention to data and flows. Consider that a recent McKinsey report notes the fastest-growing global flows are now data, services, intellectual property, and international students. Estimates vary on how much data is flowing at any given second (an “intangible”) but there’s no denying its centrality.

It is also clear that ensuring the free flow of data across borders is a paramount concern to business and government. After all, industry derives exceptional value from its use, allowing for rapid innovation such as what we are now seeing with advancements in AI. It also affords the tantalizing possibility of solving some of the world’s most pressing crises. 

But how is data best protected?

Along with technological changes and risks to business operations, it’s critical to understand that it’s the regulatory environment that allows data to flow and businesses to operate at global scale. Regulations also provide an opportunity for businesses and governments to help protect data, whether intellectual property or PII, from cyber-enabled threats. 

Indeed, compliance with data regulations can actually help businesses grow and fight the scourge of cybercrime.

Your organization needs to think deeply about the role of data, privacy, protection, and flows. Consider the following acts and regulations and their implications for your organization:

Lastly, governments have developed free resources for you to identify and manage privacy and data risks. For example, NIST offers a voluntary Privacy Framework tool. And the EU offers a GDPR checklist tool for data controllers.

In our second blog entry on the centrality of data and the challenges of keeping it secure and flowing, my colleague Dr. Rois Ni Thuama and I have the pleasure of talking with one of the world’s foremost experts on the topic, Linda Priebe of Culhane Meadows, PLLC.


Sean Costigan

9 May. 2023



Recent Posts


Preventing certificate related violations in cybersecurity frameworks:  A guide to certificate monitoring…

Rebecca Warren

TLS is one of the most widely adopted security protocols in the world allowing for unprecedented levels of commerce across the internet.  At the core of the TLS protocol is TLS certificates. Organizations must deploy TLS certificates and corresponding private keys to their systems to provide them with unique identities that can be reliably…

Read more

Red Sift ASM & Red Sift Certificates: the missing link in your…

Billy McDiarmid

According to Gartner, Attack Surface Management (ASM) refers to the “processes, technology and managed services deployed to discover internet-facing enterprise assets and systems and associated exposures which include misconfigured public cloud services and servers.” This broad category of tooling is used within Continuous Threat Exposure Management (CTEM) programs, with many vendors within it having…

Read more

The best tools to protect yourself from SubdoMailing

Francesca Rünger-Field

In late February 2024, ‘SubdoMailing’ became a trending search term overnight. Research by Guardio Labs uncovered a massive-scale phishing campaign that had been going on since at least 2022. At the time of reporting, the campaign had sent 5 million emails a day from more than 8,000 compromised domains and 13,000 subdomains with several…

Read more
Product Release

Red Sift’s Spring 2024 Quarterly Product Release

Francesca Rünger-Field

This early into 2024, the cybersecurity space is already buzzing with activity. Emerging standards, such as Google and Yahoo’s bulk sender requirements, mark a new era of compliance for businesses reliant on email communication. At the same time, the prevalence of sophisticated cyber threats, such as the SubdoMailing campaign, emphasizes the continual hurdles posed…

Read more