World Computer Security Day (30 November) was launched in 1988 by the ACM’s security community in Washington DC. The aim was to position computer security as an integral part of corporate culture.
Why is it Critical?
Today, security is a balance of data privacy + business continuity + legal compliance + reputation. The 2025 IBM report shows that the use of artificial intelligence without governance increases the risk and cost of breaches; security controls and model governance must now be addressed together.
Computer Security from its Inception to Today
- 1988 – “Computer Security Day” begins: It emerged in Washington DC as an awareness day around the ACM’s security community; it is now commemorated on 30 November.
- 2001/2004 – Budapest Convention: Opened for signature on 23 November 2001. Entered into force on 1 July 2004, providing a binding international framework for combating cybercrime.
- 2014 – NIST Cybersecurity Framework 1.0: NIST published the first version of its guidelines for managing cyber risks.
- 2022 – ISO/IEC 27001:2022: The current version of the information security management system standard was published in 2022; “Amendment 1” (provisions related to climate action) was added in 2024.
- 2024 – NIST Cybersecurity Framework 2.0: The scope was updated, with emphasis on areas such as governance and supply chain.
Three Simple Principles for Thinking Differently
Security is the combination of the right focus, the right process and the right habits. The following three principles offer a practical system for reducing complexity and quickly making impact visible.
- Put people at the centre: Who is accessing what data, and why? Human errors (phishing emails, approval fatigue) are the starting point for most breaches. Short, targeted training + multi-factor authentication (MFA) deliver the fastest gains.
- Make it sustainable with process and governance: Establish risk-based management. The framework of ISO 27001 and the roadmap of NIST CSF transform security from a “project” into a business culture.
- Visibility and basic technology hygiene: Asset inventory, up-to-date patches, secure backups, endpoint monitoring, and identity security… The fundamentals must be flawless before complex solutions.
Clarifying risks is important. However, we see the fastest and most measurable impact in visibility, access, and backup. The short list below outlines concrete steps that can be taken today without getting into technical detail. Implementing even three or four items will significantly reduce your attack surface.
10 Point Quick Checklist
- Multi-factor authentication: Make it mandatory for cloud panels, email, finance, and code repositories. Start today with administrator and finance accounts.
- Separate device/session for administrator accounts: Isolate privileged access from daily usage environments.
- Target timeframe for patches and secure settings: e.g., “critical patches within 7 days”.
- Endpoint security and centralised monitoring: Behaviour-based detection and 24/7 alert tracking.
- 3-2-1 backup and regular recovery testing: Verify the last successful restore today.
- Least privilege and access review: Remove unnecessary permissions; start with the most critical groups.
- Secure configuration checks in cloud and containers: Run automated checks, obtain reports; start with at least one account/cluster.
- Phishing tests and short training sessions: Plan monthly simulations; provide micro-training to high-risk teams.
- Supplier security: Add MFA, encryption, incident reporting timeframes, and audit rights to contracts.
- Artificial intelligence and data management rules: Approved tools, prohibited sharing, storage, and human oversight should be clearly documented.
As CFECERT, we offer course, internal audits, GAP analysis and certification, as well as a wide range of training programmes. Below are just a few of the topics covered. Contact us for the right programme: info@cfecert.co.uk
- ISO 27001 Information Security Management System The basis for identifying, controlling, and continuously improving information security risks within an organisation.
- ISO 27002 Information Security Controls Implementation Implementation of access management, cryptography, supplier management, physical and technical controls.
- ISO 27005 Information Security Risk Management Defining assets, threats, and vulnerabilities. Assessing risks and managing risk registers.
- ISO 27017 Information Security in Cloud Services Clarification of responsibilities in cloud services. Record keeping and data location rules.
- ISO 27018 Protection of Personal Data in the Cloud Clear rules for processing personal data in the cloud. Deletion, audit trail and transparency requirements.
- ISO 27701 Personal Data Management System Adding privacy management to the information security structure. Strengthening compliance with the Personal Data Protection Law and similar legislation.
- ISO 27031 Information Technology Service Continuity Preparing for interruption scenarios. Planning backup and recovery steps. Conducting drills.
- Secure Software Development Prevention of common security flaws in applications. Threat analysis, code review, and pre-release checks.
- NIS2 Governance, risk management and incident reporting periods for critical and important services. Supply chain security requirements.
- DORA: Information technology risk management in financial institutions. Testing processes, service provider management, and incident reporting.