Discover our full range online
Degrees
Masters
VET

We must bear in mind the value of information and regard it as a highly valuable asset. Any activity aimed at using information to commit specific criminal acts – such as its use, control, manipulation or theft – is defined as a cyber threat, hence the importance of information security.

Information security is defined as the set of initiatives and preventive and reactive measures aimed at safeguarding and protecting information as a fundamental element enabling a country, a society or a company to carry out its communications, information-sharing or operations without assuming risks. However, information security must tackle cyber threats, analyse them, prevent them, combat them and find rapid solutions to eliminate them.

The concept of information security is based on four pillars:

  • Availability: availability ensures that authorised users can access information at any time, securely retrieving it when required, with privacy as a fundamental principle, whilst preventing unauthorised access that would hinder access to our information.
  • Confidentiality: information must be accessible only to authorised personnel. This implies that the security system protects and guarantees that all information and data collected will not be disclosed without authorisation.
  • Integrity: ensuring the security of information by presenting data in its unaltered form – accurate information free from unauthorised modifications or errors.
  • Authentication: The certainty that information originating from a particular user is indeed from the person they claim to be, by verifying and guaranteeing that the source of the data is correct.

The concept of cybersecurity complements that of cyberdefence and embodies national digital defence; thus, cyberdefence not only works to prevent attacks, as cybersecurity does, but also responds to them, countering new attacks in order to safeguard security.

It is within this global context that concepts such as cyber-terrorism and cybercrime are becoming increasingly prevalent in our societies, making the existence of cyber-defence mechanisms essential.

A new battlefield is emerging: the Internet, where cyber-threats are on the rise and where there is growing activity both on the part of states—seeking to expand their geopolitical interests through offensive cyber operations—and on the part of terrorist organisations, organised crime groups and other individual actors.

These groups exploit the situation and the anonymity offered by cyberspace to achieve their aims at minimal cost and with fewer risks, given the difficulty of attribution.

ciberseguridad_uax.jpg

For the United States Department of Defence, cyberspace is defined as “a global domain within the information environment consisting of an interdependent network of information technology infrastructures: the internet, telecommunications networks, computer systems, embedded processors and controllers” (P1-02 D. of Defence, 2009).

Within the European Union, cyberspace is defined as “the virtual space through which electronic data from the world’s computers flows”. For this supranational organisation to which we belong: “Maintaining an open, free and secure cyberspace is a global challenge that the EU must address together with relevant partners and international organisations, the private sector and civil society” (Council of the European Union 2013 (12 February) (OR. en) 6225/13 ).

The theft of data and information, ransomware and denial-of-service attacks, the hacking of mobile devices and industrial systems, and cyber-attacks against critical infrastructure are examples of cyber-threats, and this is the approach taken by the Spanish Security Strategy (ESN, 2017).

The Spanish Security Strategy (ESN, 2017), like the security strategies implemented by other countries in our region, classifies and identifies the main threats and challenges to national security in global commons as areas of particular vulnerability, such as information security.

In an international context of heightened tensions, global commons are subject to increasing competition and confrontation.

A new approach to the concept of security must be considered, because cybersecurity must be based on the certainty that no State or group of States, acting in isolation, can tackle current threats.

Faced with a transnational threat that challenges concepts such as cyber defence or cybersecurity, it is essential to ‘build’ trust not only between states but also with other non-state actors through discussion, negotiation, cooperation and compromise.

In the face of new challenges relating to risks and threats of this nature, progress must be made towards an expanded concept of security, one that evolves and renews itself, unlike in previous eras, and as a consequence of globalisation, within a space defined by three key elements: circulation, complexity and contingency.

In this new security context, greater attention must be paid to the problems posed by interdependencies and flows than to the increasingly hypothetical distinction between internal and external security, and we must reflect on the ‘global circulation’ of threats.

Tackling cyber threats at a global level

In the current international environment, characterised by low-intensity tensions, with limited areas of violent conflict, ‘global circulation’ gives rise to a wide range of problems, including information security, and cyber threats must be addressed, prevented, analysed and combated by providing rapid solutions and responses to eliminate them.

Complexity theory, as an intermediate stage between stable and chaotic states, has been extensively developed over the last 25 years.

In essence, a complex circulation system functions more like a living organism than a mechanical one, comprising several interconnected or interlinked parts whose connections contain additional information.

The greater the circulation, the more complex it becomes, the more dependent it is on contingencies of time and space; and thus, just as complexity and circulation entail contingency, contingency entails risk.

National sovereignty no longer holds the importance attributed to it in traditional approaches, giving way to a form of ‘global sovereignty’.

In 1994, the United Nations Development Programme (UNDP ) included the concept of ‘human security’ in its Annual Human Development Report.

The report in question criticises the traditional conception of security by stating that:

“Security had been interpreted too narrowly for far too long: as the security of territory against external aggression, or as the protection of national interests in foreign policy, or as global security in the face of the threat of a nuclear holocaust. Security has been associated more with the nation-state than with the people…”

We must reflect on and be prepared for the challenges of attributing a cyberattack; the potential benefits and threats of applying Big Data techniques in the detection of security risks; and how the human factor and social engineering are the most common routes for cyberattacks and their propagation.

The importance of preparing for cybersecurity

But the key point, when discussing information security, is the importance of awareness-raising, sensitisation and academic preparation for our younger generations in the fields of cybersecurity, information security, training and outreach.

Among these initiatives, and through the UAX Online University in Madrid, we prepare our students for a professional discipline in growing demand: a specialised Master’s degree in Cybersecurity and Information Security.

Given the risks and threats facing our society today, training in cybersecurity is a strategic and fundamental element, because cyber-attacks jeopardise the integrity of a country and the way of life of its citizens, and, as resilient societies, we must ‘train to overcome’ any risk or challenge that arises.

Being resilient societies – resilience being that capacity to recover from a blow and adapt positively to adverse situations – is a process in which countries face risk with fortitude, going beyond mere resistance and overcoming an adverse stimulus.

Cyber-resilience is defined as a country’s ability to manage existing risk and overcome it swiftly and decisively, with minimal impact on our societies.

It is important to have ongoing training and development to ensure the protection of our societies, because this is how we will know at all times the state of protection of our infrastructure, which will provide us with the precise tools for efficient management that guarantees our security in the event of cyber-attacks.

But we must not forget that risk does not only mean danger; it also means opportunities. Those who know how to capitalise on these opportunities are managing to bring about profound changes to their societies and adapt them to a future that is likely to be very different. 

 

Author: Luis A. Aparicio-Ordás González-García*

* Luis Ángel Aparicio-Ordás González-García. Doctor of Law. Alfonso X el Sabio University, Madrid. Faculty of Social and Legal Sciences. Member of the Scientific Committee of the Military University of Nueva Granada, Bogotá (Colombia). Professor and Doctor at ESERP (School of Business & Social Sciences), Madrid. Principal Investigator at the Scientific Observatory on Terrorist Risks and Threats. Lecturer and Tutor on the Advanced Strategic Studies Course for Ibero-American Senior Officers. Higher Centre for National Defence Studies (CESEDEN), Ministry of Defence. 2015–2016. (Spanish Higher Defence Studies College) Higher Centre for National Defence Studies (CESEDEN), Ministry of Defence, Madrid. 2013 International Security Studies Group. Member of the GESI-SEDEF International Security Studies Group.

Would you like to find out more? We’ll tell you all about it

All fields are required