CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Data Security

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

DB Schenker

Michal Niezurawski, Head of Global IT Security Competence Center

The Future for IT Security will be Challenging

As technology evolves, new threats emerge. Even though such changes are quite fast and frequent the basic principles for IT Security function hold. In my opinion, the fundamental one, at least for commercial enterprises, stays solid - IT Security needs to be the business enabler that allows for avoiding threats and pursuing new opportunities in risk acceptable way.

Just to refer to the most recent example Covid-19 was a unique situation for the whole IT. The logistics industry was no different here. Thousands of people were forced to start working remotely. Technology allowed for this transition in a relatively secure manner. IT Security’s focus was to ensure IT services availability and data protection. In most cases, it went so smoothly that users didn’t question why this was even possible. Success was secured by a combination of multiple factors just to name – reliance on cloud services, centralized identity management, transparent cloud VPN. The other aspect that proved value was the IT Security Awareness Program that helped users to find themselves in a new situation or find an acceptable response to new threats.

Focusing on the last one. End-user awareness, at all levels of an organization, is still and will be the biggest challenge to IT Security. Basically, users demand more and more functionalities, easy ways to use technology. Unfortunately, they do not know how to do it properly or just make simple mistakes. Technology that allows protecting data became so transparent that for some is hard to recognize what is acceptable. Just to add, due to the current situation, users working from remote locations are missing direct IT support contact or without the supervision of more experienced colleagues have the challenge to recognize threats.

Challenging is also a constant increase of devices like mobile computers, mobile telephones, smart watches, basically the “Internet of Things” (like IoT) that allow us to access information. Obviously, from a risk management perspective, we can block access to functionalities. Unfortunately, these functionalities are just “what our business wants”.

This makes the whole IT environment extremely complex, its configuration volatile and hard to control. This makes users even more vulnerable – we do not need zero-day hacks as long as we can use social engineering to persuade users to give us what we want. That is why we see an increasing number of such incidents like phishing or surprisingly USB device-related attacks. Both of them are quite cheap to execute in comparison to potential gain for the adversary in case the enterprise is successfully compromised.

The Talent shortage we struggle with in IT Securitydoes not help here. I believe the whole IT industry is plagued by this. This also impacted the application development process. Historically, we were able to overcome this by the ability to reuse or re-deploy code. The boom of use of open-source libraries is the best example here. I believe thatsuch an approach will be changed after recent events likelog4J or just one with NPM libraries. From an IT Security perspective, we need fully vested and trustful code at least for critical systems. That is why in the short term we should see some changes in a way how code will be re-tested and validated before the newer version is accepted.

Technology that allows protecting data became so transparent that for some is hard to recognize what is acceptable

IT Security industry is looking now at Big Data processing and Artificial Intelligence to resolve complexity and resource challenges. This concept is sold as the “ultimate solution” for the industry. Currently, Artificial Intelligencetechnology gained adequate maturity that allows findingsome practical applications. This happened due to a processing power increase. However, in my opinion, we are not there yet. Full process automatization is not possible and we are struggling to find a correct spot between seeing too much or too little due to lack of system calibration. Constant human supervision and action are still necessary. However, I have to admit the use of AI is ona good path here and willbe present more and more as the preferred solution.

Finally, the IT Security industry is and will be in a disadvantageous position. Our role is to make sure we are able to protect everything. For our opponents the objective is much easier – find the weakest element. There is no easy solution available. To protect the commercial enterprise IT environment we should make it simple enough to achieve reasonable benefits of scale –similar devices are by far easier to protect than trying to have an individual approach. At the same moment, we need to avoid the situation that the whole IT environment is compromised using one vulnerability present everywhere – that is limit services to a minimum, keep a fast pace of patching. In a commercial environment, taking into account technological progress, there is no way to keep valid business offering using such limitations. More and more devices are being connected to the Internet (we should exceed 18 billion this year) enterprises also tend to clutter their internal network with them. Our users demand “smart” projectors, TVs, printers, thermometers, light controls,etc. This comes at cost of increased interconnectivity and environment complexity.The IT Security can always help here by supporting the implementation of such programs like Vulnerability Management, Zero-Trust, or just basically challengingthe status quo by “red-team” exercises. However, this usually is not adequate in comparison to depict clearly needs to decision-makers. To summarize – the future for IT Security will be challenging here and as an industry, we will be still struggling here as long as the pace of progress of the IT Industry and the possibilities of IT applications is increasing. To be honest, this is part of our job.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://data-security.cioapplicationseurope.com/leadership-perspective/the-future-for-it-security-will-be-challenging-nid-2953.html