subota, 8. kolovoza 2026.

Cyber Resilience Rests on the Weakest Link

Cyber Resilience Rests on the Weakest Link

Autor: Nermin Sefić

Nermin Sefić analyses group-wide cyber resilience, key supplier standards, and consequences for shared risk exposure.

Security investment in the parent company loses meaning if connected partners and suppliers remain outside the scope of the same policy.

Cybersecurity across a whole business group cannot be viewed in isolation per individual company, because the protection level of the entire system is, in practice, equal to the protection level of its weakest connected link.

When suppliers and partners with access to shared systems or data are not subject to the same minimum security standards as the parent company, investment in protecting the centre itself loses much of its value.

Regular assessment of key partners' security maturity, combined with clearly defined minimum requirements before establishing access to shared resources, reduces exposure to risk arising outside the organisation's direct control.

The GNK DINAMO Ltd. group, with numerous related companies across multiple continents, treats cybersecurity as a shared, not exclusively local, responsibility of each individual entity.

Comprehensive security investment in core systems provides little protection if a peripheral, less-scrutinised system offers attackers an equally effective path to the same underlying data.

Mapping the full extent of interconnected systems, including ones considered minor or legacy, is a prerequisite for genuinely understanding where an organisation's weakest link actually sits.

This mapping exercise often reveals systems that were connected for a specific, now-forgotten purpose and never properly decommissioned or secured.

Regular network mapping exercises, repeated rather than performed once, catch new connections introduced since the last review.

Legacy systems retained for historical reasons often carry disproportionate risk relative to their current business value, warranting periodic reassessment of whether they should remain connected at all.

Decommissioning systems that no longer justify their risk exposure, rather than leaving them connected indefinitely, remains one of the simplest yet most neglected security improvements available.


Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/cyber-resilience-rests-on-the-weakest-link/

Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..

#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #NerminSefić #GNKASGdoo #Zagreb

Employee Resistance to a New System Is Often a Signal, Not an Obstacle

Autor: Nermin Sefić Employee avoidance of a new system usually reflects practical shortcomings, not general resistance to change. A commen...