A conversation with Bob: How Cube ensures security and data integrity.
We sit down with Bob, a steady and valuable force within Cube's team. With a cup of coffee in his hand, he talks about his years of experience within the organisation. What started as an internship in front-end development and design grew into a multi-faceted career in which he increasingly focused on security and compliance. When the AVG legislation took effect, Bob became closely involved in implementing privacy policies within Cube. His eye for detail and perfectionism made him the right person to delve further into security and data integrity. He now plays a key role in setting up testing processes and developing policies to build software in the safest way possible.
The road to certification.
With the emergence of ISO 27001, he explored what this certification entailed and what impact it would have on Cube. Together with colleagues, he set up an Information Security Management System (ISMS) and associated team. "We wanted not only to comply with regulations, but also to create a culture where security is a given. Everyone within Cube needs to understand why certain rules are there and how they contribute to a safer working environment." To strengthen his expertise, Bob attended various courses and obtained international certifications that allow Cube to prove it has a competent specialist in-house.
Methods and protocols.
Cube maintains strict protocols to ensure the security of systems and data. This starts with mapping all data and linking restrictions and safeguards. "We always worked with clear guidelines and working agreements, but with a growing client base and more complex projects, we have further tightened and standardised our processes," Bob explains.
An important part of this is the Cube Code, a document that all employees receive and sign. This contains guidelines for safe working practices, data storage and privacy protection. In addition, all policy documents are maintained in a live management system, making updates and changes immediately visible and applicable.
The entire system around security must be continuously monitored. This includes not only software, but also people, processes, software and policies. Policies translate into processes, and their effectiveness is checked through logging and monitoring. "We make sure that everything we do is demonstrable and traceable. That means we don't just say what we do, but can prove that we actually comply with it."
A concrete example is an incident where a monitoring tool noticed an inconsistency in database queries. "Our lead developer immediately noticed that this could be a potential risk. We analysed the problem and implemented a policy to ensure that this error does not recur. This shows how our approach is not only reactive, but also proactive."
Customer data security.
At Cube, the internal approach to security is also applied to clients. This means that client data is always protected according to strict guidelines. "We work according to the principle of 'least privilege', a developer only has access to the projects and required data he or she is working on directly. This minimises risks and ensures that sensitive information is not unnecessarily exposed," says Bob.
In addition, internal policies have been greatly expanded. Where previously guidelines were mainly for developers, the policy now covers the entire organisation. "A project manager may not have direct access to code, but he should know how customer data is processed. Everyone within Cube has a role in ensuring security." Employees are actively involved in complying with the guidelines and can report situations like security incidents when in doubt. "We have a culture where everyone feels responsible for security. We keep each other on our toes, organise training sessions and presentations, and work together to not only follow the policy, but also live it. That's a big difference from how we used to work," Bob stresses.
Continuous learning and improvement.
An essential part of ensuring security is keeping knowledge up-to-date. Cube actively follows relevant news sources, holds and attends additional security training courses and ensures employees are familiar with the latest developments in the field. "We don't settle for 'good enough'. We always want to go one step further and improve ourselves. That's in our DNA."
ISO certification also requires knowledge to be updated periodically, providing a constant incentive to keep learning. "What really sets us apart is that we don't see security as an obligation, but as an opportunity to excel. We don't just build secure software, we make sure our clients can rely on it." To underpin that trust, our clients regularly commission pen tests and audits on the software we build. Security is not only a matter of trust, but also of control.
Part of company culture.
According to Bob, the commitment to continuous improvement is noticed both internally and externally: "Clients, partners and employees appreciate the diligence with which we implement testing processes and security measures." Thanks to the policy processes and implementation of a structured security framework, Cube has created an environment where security is not only a technical requirement, but also an integral part of the corporate culture. The result: an organisation that not only complies with regulations, but also continuously strives for improvement and optimisation in the security of data and systems.
Ready for the next step? We are too.
More info on data security? Bob is happy to talk to you.
Worth reading next...
How does CAPTCHA know you are not a robot?
Successful internal digital transformation with a Knowledge Base.