The recent security breach involving Denmark’s national personal identification register (CPR) has highlighted the serious consequences that can arise when unauthorized parties gain access to sensitive personal data.
At the same time, the incident serves as a reminder that cybersecurity is about more than keeping hackers out. It also involves access management, monitoring, processes, and employee behaviour.
This also applies to property management.
At CEJ, IT and data security are an integrated part of how we conduct business and fulfil our responsibilities towards clients, residents, and business partners.
Trust is built on security
For Michael Brinch, Head of IT at CEJ, security is therefore closely linked to trust.
“We handle large amounts of data every single day. That is why security is not merely an IT discipline. It is a prerequisite for the trust our clients place in us,” says Michael Brinch, continuing:
“The recent security incident involving CPR numbers demonstrates how quickly the consequences can become tangible when unauthorised individuals gain access to sensitive information. At the same time, we are facing a threat landscape that becomes more complex year after year.”
Security is a prerequisite
To ensure a systematic and measurable approach, we have chosen to base our security efforts on CIS Controls 18, an internationally recognised framework consisting of 18 prioritised security controls. These controls are used by organisations worldwide as a practical guide for cybersecurity management.
Secure access to systems and data
Continuous monitoring and rapid response
We use advanced security solutions to monitor activity across devices and networks, enabling us to identify and respond quickly to suspicious behaviour. In addition, we utilise AI-powered tools and solutions such as Darktrace to support continuous monitoring and strengthen our ability to detect abnormalities.
Cloud environments, networks, and devices are continuously monitored and maintained. Critical systems are segregated, and software is updated systematically to reduce the risk posed by known vulnerabilities.
Security as part of the culture
The ongoing development of cybercrime and digital security incidents demonstrates that robust cybersecurity is a fundamental prerequisite for responsible business operations.
According to Michael Brinch, some of the most significant risks today include advanced phishing attacks, AI-enabled threats, supply chain risks, cloud infrastructure vulnerabilities, and ransomware.
As a result, we continuously strengthen our technology, processes, competencies, and preparedness.