That’s right, today we’ll give you some insight into the cybersecurity awareness that Intwo promotes, and where we want to get to as a cyber-safe business for us and our customers.
As a business, we want to do quality work, and in the modern era, digital security is a huge part of it. It’s baked into everything we do, but that doesn’t mean we don’t actively try to improve it and make sure it’s reviewed and brought to the front of every team member’s mind. Today, we’re going to dive into how we have built cybersecurity awareness into our business, and how you could do it in yours.
Companies cannot afford to take the threat of cyberattacks lightly. There are plenty of examples in the news where large organizations are effectively brought to their knees by small but sophisticated groups of cybercriminals. For example, Maastricht University had unauthorized people inside their system for two whole months and was forced to pay €200,000 to get rid of them. Frankly, Maastricht University got lucky because 29% of organizations who pay ransoms still can’t recover their data once they’re rid of unwanted guests.
As part of our SOC 1 T2 audit, we have to have sufficient security policies in place that are designed to protect information and critical resources from a wide range of threats. These policies ensure business continuity, minimize business risk, and maximize ROI. The very purpose of our information security policy is to ensure the confidentiality, integrity, and availability of data and services for us and our customers.
Part of our approach is also built upon our Zero Trust Principles, which consist of the following:
Awareness is the cornerstone of adopting a security mindset that carries through daily business activities. The digitization of everyday life has been accelerated by COVID-19 and now hybrid work is becoming the standard. But, none of that changes the fact that cybercrime doesn’t sleep, and so neither should your defenses whether you’re in the office or at home. With 95% of all successful cyberattacks caused by human error, every single person in our business has a role to play in the security of our data and privacy as well as that of our customers.
Organizations and VCs are increasingly looking at cybersecurity risks during business deals, including mergers, acquisitions, and vendor agreements. As a result, there are an increasing number of requests for more data about a partner’s cybersecurity program. We’ve seen it with our own clients, they are a genuine focus on security and safety in the digital ecosystem. The trends we’ve witnessed stack up more broadly as well, with Gartner research showing that 88% of boards now regard cybersecurity as a business risk rather than solely an IT problem.
Security, privacy, and governance should be baked into everything we do, not just bolted on. And that’s why, for 2023 and 2024, we aim to further improve the overall state of security and compliance at Intwo through a number of initiatives, including going for our SOC 2 and ISO27001 certifications. We want our global security posture and state of governance to keep pace with the ever-developing threats of cyber attacks, and allow us to always be in control. It requires focus, a dedicated team, and the right mindset, but we have all those pieces already in place, so we’re confident we’ll make it happen.
Want to make cybersecurity a focus for your business? Intwo can help with that, contact us now.
As the primary responsibilities, I develop and productize new services, redesign existing ones, and implement them on various cloud platforms. I also conduct market research, develop strategies, and lead the roadmap for service offerings. Additionally, as the CISO, I ensure the organization’s security by establishing and maintaining processes, policies, and practices to mitigate risks and respond to incidents across various domains.
Companies cannot afford to take the threat of cyberattacks lightly. Plenty of examples in the news show how large organizations are effectively brought to their knees by small but sophisticated groups of cybercriminals. Awareness is the cornerstone of adopting a security mindset that carries through daily business activities. The digitization of everyday life has been accelerated by COVID-19, and hybrid work is now standard, but cybercrime does not sleep, and neither should defences whether teams are in the office or at home. Every person in the business has a role to play.
Maastricht University had unauthorized people inside their system for two whole months and was forced to pay 200,000 euros to get rid of them. The incident is a striking example of how a long, undetected breach combined with ransomware can compromise a major institution and force a substantial payment to attackers. Frankly, Maastricht University got lucky because 29 percent of organizations who pay ransoms still cannot recover their data once the attackers leave. The case illustrates why proactive detection and response matter as much as preventive controls.
29 percent of organizations who pay ransoms still cannot recover their data once the attackers leave. The statistic challenges the assumption that paying the ransom is a reliable path back to normal operations. Roughly one in three payers ends up out of pocket and still locked out of their information, since attackers do not necessarily honour their promises after receiving payment. This is why cybersecurity experts consistently recommend against paying ransoms, instead pointing organisations toward robust backup, incident response, and prevention strategies that do not depend on attackers behaving honestly.
As part of the SOC 1 Type 2 audit, Intwo has to maintain sufficient security policies designed to protect information and critical resources from a wide range of threats. The policies ensure business continuity, minimize business risk, and maximize ROI. The very purpose of the information security policy is to ensure the confidentiality, integrity, and availability of data and services for Intwo and our customers. SOC 1 Type 2 is a recognised compliance standard that audits the effectiveness of controls over a defined period, providing meaningful assurance to customers in regulated industries.
Intwo’s approach is built on three Zero Trust Principles. Verify Explicitly means always authenticating and authorising based on all available data points including user identity, location, device health, data classification, and anomalies. Least Privilege means minimizing user access with just in time and just enough administration risk-based adaptive policies, plus data protection. Assume Breach means minimizing the scope of breach damage and preventing lateral movement by segmenting access, verifying all sessions are encrypted end to end, and using analytics for visibility and threat detection.
Verify Explicitly is the first Zero Trust principle Intwo applies. It means always authenticating and authorising every access request based on all available data points. This includes user identity, location, device health, data classification, and any anomalies that suggest the request might not be legitimate. Rather than trusting users or devices based on network location, Verify Explicitly treats every access attempt as a fresh decision requiring justification. The principle counters the older castle-and-moat model where insiders were trusted by default once they were past the perimeter.
Assume Breach is the third Zero Trust principle Intwo applies. It means treating a security breach as inevitable rather than just possible. The practical implications are to minimize the scope of damage when a breach happens and to prevent lateral movement by segmenting access across networks, users, devices, and applications. All sessions are verified as end-to-end encrypted. Analytics provide visibility and drive threat detection so anomalous behaviour gets caught quickly. The mindset shift produces architectures that contain damage even when initial defences fail.
95 percent of all successful cyberattacks are caused by human error. The figure shows that the most sophisticated technical defences can be undone by a single staff member clicking a malicious link, sharing a password, or falling for a social engineering attempt. This is why awareness is the cornerstone of an effective security mindset. Every person in the business has a role to play in protecting data and privacy, both for the business itself and for its customers. Technology controls matter, but training and culture matter equally.
Organizations and VCs are increasingly looking at cybersecurity risks during business deals, including mergers, acquisitions, and vendor agreements. There are an increasing number of requests for more data about a partner’s cybersecurity program. Gartner research shows that 88 percent of boards now regard cybersecurity as a business risk rather than solely an IT problem. The shift reflects how a cyber incident can affect financials, reputation, regulatory compliance, and competitive position simultaneously. Boards now demand visibility into cybersecurity in the same way they demand visibility into other major business risks.
Intwo helps businesses foster a strong cybersecurity culture by combining advanced security technologies with employee awareness, governance, and best practices. Rather than treating cybersecurity as a one-time project, Intwo helps organizations make security an ongoing part of everyday business operations. Through security assessments, Zero Trust strategies, threat monitoring, compliance support, and expert guidance, Intwo helps businesses identify risks, strengthen defenses, and improve security readiness across their organization. With extensive experience supporting companies across multiple industries, Intwo enables teams to better understand cyber threats, adopt secure working practices, and build a more resilient digital environment that protects critical business data and systems.
Rest assured. We've got you.
Let's get in touch and tackle your business challenges together.