Hi everyone, I'm Mirjana Ciobanu, Lead Editor with The Papers, a global financial publication, and we are live at Cyberrevolution with Andrzej Kawalec, Head of Cybersecurity for Kodak On Business. Hi.
Andrzej, yeah, hi, nice to meet you. And I'm curious to learn more about your professional background.
And yeah, you once said that security is the enabling layer for innovation, maybe to connect this to ideas. So as you said, so I'm responsible for security for Vodafone business, which we look after six or seven million different businesses around the world, and they face a vast array of threats. But I think, you know, what I've learned over the years running large security organizations as CTOHP, working with NATO and other people, is that security really isn't an environment to say no in. Security lets you go faster. It lets you use technology in a better way.
I often describe it as the brakes on a car, and nobody would say, well, the brakes don't let you go faster. But actually, if you ask any racing driver, what's the most important part of the car? It's the brakes. They let you slow down. They allow you to drive faster because you know you can stop if you need to or you can navigate the road. So I would say security is like the brakes on a car. They let you go faster and then they can stop you when you need to. And I think if you think of it that way, not only does it protect you, but it enables you to use the digital world in really cool ways.
I think if we hold on to that, then security isn't the department of no, it's the department of go faster. Since you mentioned go faster, and Vodafone has lots of customers, users, and some of them, many of them are SMEs. I am curious if I were the seesaw of a small merchant or payment service provider, how can I make my car go faster and how can I make sure that I have the right brakes taking into the fact that there are many things that I should be concerned about?
So first, what should I be concerned about and then how to pull those brakes? Yeah, that's a great question. And I think we talk to a lot of our customers. We have over 1.6 million people who consume our security services every day. But what we've noticed is, you said, if I was the seesaw for a small organization, small organizations don't have seesaws. They don't have chief information security officers. They don't have a security team.
At best, they're a group of people trying to do their very best, you know, in retail or manufacturing or services, but they don't have an IT team and they don't really understand the same big challenges that are facing everybody. Governments, banks, Vodafone, we're facing a dynamic and relentless threat, an adversary that's trying to steal our secrets, our data and our money. We face technology that's moving faster than we can really keep up with. We'll talk about AI, I'm sure. But what does that mean? Small organizations don't know.
And we're also facing regulation that is complex, sometimes aggressive and often different by country, by region, by state. So if you're a small business, you look at that picture and you're not a security expert, you're really, really bewildered about, as you said, which brakes to buy, which controls to put in place. And small customers just need help. So we looked across Europe and there's, I think, 24 million small businesses across the European Union. That's nearly, that's the vast majority of all businesses in the EU, 85 million employees.
And two thirds, so two out of every three of those organizations, do not have a plan for security. And then what's the plan? How can we help them?
Well, I think it starts, it starts with, as you would at home, you know, if I said to you, what's the most important things in your house? And you talk about, well, it's, you know, sensitive objects, it's possibly my passport, maybe it's money, it's of course, my family, my loved ones, my pets. And I think you have to go through that process with your business. What is the most important assets you have? And how do you protect them? How do you use them, but lock them up when you're not using them? How do you protect your employees?
When you think about each person in your organization, their identity, their devices, their email, how would you train them and let them understand where to go in the event of a cyber fire? When you think about it through the lens of the most important things I have, the most important people I have, and then particularly, what would I do if there was an emergency? Who would I call?
Who would, you know, who would be my cyber fire brigade? If you can answer those questions, you've made a massive step forward. So now you've portrayed a bit of the strategy, the points to take back home, but now I'm thinking strictly of technology and technological solutions. What those solutions might be?
AI, digital identity, both, more? It's a great question. So I think it comes down to, again, what do we use the most?
Genuinely, so identity is super important. Understanding the digital identity, how you authenticate your passwords, your permissions, really important. The things we use, the devices, the laptops, the phones that we all carry all day every day, that we use to connect, and the, you know, the applications. So really controls around those. So endpoint detection, identity, as well as, you know, application and SaaS services. Those are really, really key.
I think, so focus on an employee, a focus on secure connection. So can you really work securely from anywhere? As we learned through the pandemic, being able to work for extended periods of time and collaborate with people around the world in different homes, in different cities, in different countries, can you work securely from anywhere and connect to anything that you need to? And then I think the third sort of discrete solution is being able to monitor and detect and respond.
So there's MDR, there's managed security services, where something like, you know, Vodafone or any partner can really help you and tell you when you're being attacked and what you should do. We're all trained, I think, from an early age, you know, in the event of a fire, right, an alarm will sound, and you should exit the building and you'll be met by somebody, you should use the stairs, not the lift, you should, you know, take one important thing, not wait. Most cyber emergencies don't have those rules. People don't understand where to go, what to do.
So for example, if you're being, you know, the subject of a cyber attack, should you use your email or not? Should you turn your computer on or not? At that point, you need advice, you need somebody that you can speak to, who can advise you and say, that's great. We've got it from here, go and have a cup of tea, you'll be OK. And I think everybody needs that peace of mind. So really focus on the employee, the individual, the controls around identity and device and application, connect securely from anywhere to anything.
And we, you know, there's lots of ways of doing that and then really have somebody there who's got your back. So when that emergency does happen, you've got somebody you can speak to, somebody you can help and advise you. And if I were to work with somebody that would help me through all of this process, would it be challenging for me to implement all these systems? So what should I do? Should I change my employees' mindset to integrate all this within my business? I think that's such a really brilliant question or discussion because you picked on two things.
One is, is this hard to integrate? Yeah.
Yes, it's hard for trained IT and security professionals. Big organisations have on average 90 different security controls that they try to integrate. So I've seen at this event, put all the boxes and numbers, yeah. But small organisations have an average 17. You ask most small organisations, could you name the 17 security controls you have? You've already bought. And they wouldn't know.
So, yes, they need to be integrated. I mean, we take a very simple approach that says these things need to work together and need to give you a single traffic light view of your organisation's risk, right?
Are you A, B or C? Are you good or bad? How does that work? But the second point you raise is, I think, is as important and that's the people. The people, yeah. Changing behaviours. Changing behaviours or actually helping people become more literate around security, help them understand what the things are.
We often, in security, we describe people as the weakest link. We say things like there's no patch for people.
Well, actually, we should turn that on its head. People are your first line of defence. And helping them understand the risks and recognise threats. We asked about 3,000 people in the UK very recently if they felt prepared to respond to an AI phishing attack. Ninety five percent of them said no. Ninety five. So we need to help people, almost everybody.
I mean, would you feel comfortable responding to an AI phishing attack? The rest were the CISOs from big corporations. So we really have to keep investing in our people, helping them understand the risks and know what to do when they get that email or that phishing attack that looks real, but they're not sure. We're the first people to really question things, but know what to do when that happens. So training and awareness and that human risk is as important as the technology and the security risk. And since we mentioned technology, security, we're here at the cyber revolution.
What are some trends or ideas that you take back home from the event? I think there's a couple of observations.
One is, as you said, security is so complicated, so many different aspects of it. And as an industry, we need to really simplify security for businesses of all sizes. I think it's something we can do better at. So my first observation is we make things deliberately complicated.
Secondly, when we start to think about the promise of, let's take AI, there's huge advantages from a defensive perspective, but there's also huge advantages for the attackers. And I think that's what makes security so dynamic. Every time we create a new piece of defensive technology or control or process, we need to keep improving our brakes. As our cars get faster, we need to improve our brakes so that they never stand still. And there is room and there are room for experts in this. But we need to really make sure we understand how to deliver these things at scale.
Yeah, great. Thank you, Andrzej.
And yeah, we look forward for our next interview, next edition. Hopefully we'll film it within a car. That would be amazing. Thank you. Thank you.