“I’m sure that many local businesses are aware of the rather alarming statistic that almost 29 per cent of local enterprises have experienced a cyber-attack,” Keith Cutajar, Founder of CY4 states. “And if I’m honest, many of them should be concerned… the repercussions of not having a robust cyber and information security framework in place can be massive and can lead to reputational, legal, financial and operational damage.”
Mr Cutajar does not mince his words, saying that local businesses would do well to reflect on whether – or perhaps more accurately, to what extent – their business is exposed to cyber-attacks or security breaches. He explains that one of the best ways to ensure truly robust cyber and information security set-up is through structural independence.
“By being kept separate from traditional IT operational teams, information and cyber security activities can provide unbiased oversight, auditing and continuous threat detection to identify sophisticated attacks, while allowing broader IT operations to focus on driving technological performance,” he says.
In line with the EU’s Digital Operational Resilience Act (DORA), it is a requirement for financial entities to maintain an independent ICT risk management function. In addition, the Network Information Security (NIS2) directive also requires businesses operating across 18 different sectors to hold corporate boards and directors to take personal legal accountability for cyber governance. Complying with both DORA and NIS2 requires a deep understanding of their respective requirements and a robust ICT risk management and governance framework.
So, while the case for having a robust and independent ICT security function is certainly compelling, what does it look like in practice?
Mr Cutajar explains that true independence in ICT security exists when the security function operates without structural, financial, or operational subjection to the teams responsible for day-to-day IT delivery. He goes on to explain that that independence is defined by three non-negotiable pillars: firstly, the function must have structural and reporting autonomy. Secondly, it must have budgetary autonomy, where security funding is ring-fenced and separate from general IT infrastructure spend.
“Last but not least, the function must have the uncompromised mandate to block high-risk changes, mandate remediation, and temporarily isolate compromised assets without requiring operational permission or being overridden by delivery deadlines,” he says.
An independent cyber and information security risk management framework will deliver unfiltered visibility: executive leadership will receive raw, ‘unpolished’ risk reporting, free from operational filtering intended to mask missed patches, misconfigurations, or SLA breaches. Furthermore, this model enables independent security teams to take timely decisive containment actions should a breach occur, such as shutting down a compromised domain controller.
He explains that the need to prevent, detect and address any cybersecurity matters is also becoming increasingly urgent in a technological landscape that is increasingly impacted by Artificial Intelligence.
"As IT teams rush to adopt autonomous AI agents and copilots to drive productivity, an independent security team becomes the essential neutral line of defence needed to audit these tools for prompt injections, data leakage, and unauthorised access pathways, " he says.
“For example, IT teams are integrating AI tools and large language models into daily operations at unprecedented speed… independent oversight is required to audit these models for data leakage, unvetted integrations and prompt injection vulnerabilities,” he continues.
IT teams’ increasing reliance on AI-driven operational tools and solutions also leads to additional exposure to information security breaches.
“Having an independent information security team is one of the best ways to mitigate risk and exposures resulting from logic flaws, hallucinated misconfigurations, or unauthorised access pathways,” he points out.
Having a demonstrably independent cyber security set-up is not only a regulatory requirement for some businesses but also goes a long way in protecting brand and reputation.
“Understandably, one of the main concerns businesses have relates to the cost of establishing independent oversight,” Mr Cutajar admits. “However, with the right approach, an independent cybersecurity set-up transforms security from a defensive cost centre into a strategic asset.”
He explains that while small and medium-sized businesses rarely have the budget for a dedicated, full-time Chief Information Security Officer and a specialised security team, independence can still be achieved.
“There are a number of options available in this respect such as using one provider for IT operations and a separate provider for security operations, where the focus would be on monitoring, detecting and responding to cyber and information security threats,” he says.
He points out that businesses can consider ‘Governance-as-a-Service’, where the use of continuous compliance automation platforms is paired with third-party human auditors to independently validate controls without heavy operational overhead.
“Whatever the size of the business, whatever their industry, we at CY4 have the right experience and expertise to design and implement an effective, fully independent cyber governance framework,” Mr Cutajar concludes. “Our goal isn't to impede innovation or add unnecessary bureaucracy, but to ensure that local enterprises can scale safely, maintain compliance, and protect their hard-earned operational stability.”
Take Control of Your Enterprise Risk
CY4 provides specialised, independent information security oversight, vCISO solutions, regulatory advisory (DORA/NIS2), and automated governance services tailored for Maltese and international businesses.
To assess your organisation's security posture or discuss independent oversight options, connect with Keith Cutajar and the team at cy4.mt or reach out directly at [email protected].
Main Image: