31. March 2016

Just an e-mail, right?

"IT Security Management in Companies" was the topic of the 4th IMS Breakfast at Zittau/Görlitz University of Applied Sciences.

A single careless mouse click activated encryption software that, within an hour, encrypted over 10,000 files on the user’s own computer and on computers connected via network drives, as well as the entire booking and accounting system. Annette Scheibe, managing director of Trixi-Park GmbH, and Andreas Gerlach, a freelance system administrator for Trixi-Park and other regional companies, described in no uncertain terms how this hacker attack on their company occurred, what its effects were, and how aware employees can prevent such situations. Thanks to the quick response of the employees and the system administrator at Trixi-Park, the downtime was limited to 8 hours, until the IT system’s functionality was restored and lost data was recovered from backup copies. According to statistical studies, such a cyberattack does not always end so mildly but results in financial losses averaging 80,000 euros per attack for small and medium-sized enterprises.

“IT Security Management in Companies” was the topic of the 4th IMS Breakfast, hosted by the Chair of integrated management systems in collaboration with the TÜV Rheinland Academy at the Zittau/Görlitz University of Applied Sciences. More than 20 company representatives and students from the master’s programs in “integrated management systems,” “integrated management,” and “computer science” joined the discussion on March 18, 2016. The technical content of the IMS breakfast was provided by Prof. Marietta Spangenberg from the Faculty of Electrical Engineering and Computer Science and her students. Constant availability through new media and social networks, online presence, trends such as Industry 4.0 or Smart Home—in her presentation, Prof. Spangenberg explained where potential vulnerabilities in IT security may exist within companies and how companies can protect themselves against these threats through systematic IT security management. Standards for this are available at both the international and national levels through the ISO 27000 series, the BSI’s IT Basic Protection, and ISIS 12. The discussion revealed that regional companies are aware of the challenges in IT security management, but there is still much work to be done. None of the companies present are currently certified in IT security management. This will change by 2018 at the latest, as by then companies of certain sizes operating in so-called critical infrastructure sectors—such as energy, information technology and telecommunications, transportation and traffic, health care, water, food, and the finance and insurance sectors—will be required by the IT Security Act passed in 2015 to demonstrate compliance with certain minimum standards in IT security management through a certified IT security management system. Once this is done, it will only be a matter of time before these companies pass on the pressure to obtain certification along their value chain. At least, that is what has been observed in the area of quality and environmental management systems.

Awareness among employees is crucial for effective IT security management. Students in the “Computer Science” Master's degree programme used Pecha Kucha—a presentation technique originating in Japan—to present their proposal for an awareness-raising training program for employees, which they developed as part of Prof. Spangenberg’s class / course. Pecha Kucha means: 20 slides for 20 seconds each, with no text—only images on the slides. It’s a concise and entertaining presentation format that’s highly recommended for others to try!

The next IMS breakfast will take place in June on the topic of “Including Mental Health Risks in Hazard Assessments.”

Ihre Ansprechpartnerin
Prof. Dr. rer. pol.
Jana Brauweiler
Faculty of Natural and Environmental Sciences
02763 Zittau
Külzufer 2
Building Z VI, Room 07
First floor
+49 3583 612-4752