Skip links

We Are Building Our ISMS, and Phishing Is the First Conversation

Introduction

This edition opens CIMA 360's annual information security awareness program. Every month we will share a core topic, a cybersecurity trend and a practical piece of advice. We start with the basics: what an information security management system is, why we decided to build one and how it changes the way we work. We close with this month's trend, phishing.

Topic of the month: what the ISMS is and why we are building it

At CIMA 360 we use the term ISMS, or Information Security Management System, for the set of policies, processes and practices we use to protect our own information and the information our clients entrust to us. It is not a tool or the job of one department: it is a way of organizing daily work.

We are building it in line with ISO/IEC 27001:2022, an international standard that defines how a system of this kind should work and that can be verified by external, independent auditors. We chose that path because it requires us to demonstrate what we do with evidence, not simply to state it.

The system rests on three objectives:

Confidentiality

Information reaches only those authorized to know it.

Integrity

Information stays accurate and complete, free of unauthorized changes.

Availability

Information is accessible when the people who need it require it.

For us this means clearer processes, documented decisions and a periodic review that pushes us to improve. For our clients and partners it means working with an organization that can explain how it identifies and manages its risks. No system removes the possibility of an incident entirely, and that is exactly why the value lies in discipline: preventing, detecting early and responding in an orderly way.

Trend of the month: phishing

Phishing is a deception aimed at people rather than systems. Someone poses as a company, a colleague or a known supplier so that the victim hands over confidential information, such as a password, or takes an action they would not take under normal circumstances.

It shows up in several forms: mass emails imitating well known brands, highly targeted messages built around personal details, deception through SMS or messaging apps, calls that pretend to be technical support and corporate email impersonation used to redirect payments.

We work in a sector where messages are the product, so the topic concerns us twice over: like any organization we can be the target, and as a communications platform we take responsibility for keeping our channels from becoming the vehicle of the deception.

Tip of the month: verify through a different channel

When a request arrives by email and conveys urgency, especially if it asks to change billing details, raise sending limits or modify a campaign setup, we confirm through the usual channel agreed with that person or client before acting. A short call to the known contact settles in a minute what a fraudulent message can cost in weeks.

A second habit helps a great deal: two step verification, known as MFA, which asks for an additional confirmation from another device on top of the password. If someone manages to steal the password, that second step is often what stops the access.

Information security works like a chain. Employees, partners and clients are all part of it, and every verification we make protects the rest as well.

This website uses cookies to improve your web experience.