Skip to content

Five steps to improving cybersecurity

3 minutes read
| |
December 23, 2024

Share this post:

Five steps to better cybersecurity

Protecting your company and products from cyberattacks requires more than just virus protection and firewalls. Our cybersecurity specialist for Tekla software, Jarkko Leminen, presents five security measures to follow.

People often think that cybersecurity boils down to virus protection and other tools. They think that all you have to do is install anti-virus software and you're safe. But this is not the case. Effective cybersecurity is much more holistic. It's everyone's responsibility: employees, suppliers, partners and all the other players in the data chain.

The world of cybersecurity is full of standards, frameworks and guides to follow, including SOC, ISO 27001 and the one we'll be looking at in this article: NIST. This well-known framework from the US National Institute of Standards and Technology (NIST) details five main areas of security: Identify, Protect, Detect, Respond and Recover.

Identify

what you're trying to protect

First, you need to know what your assets are and what you're trying to protect. Is it data, software or hardware? You also need to carry out some kind of threat modeling to identify and compare the different risks associated with an asset. If a threat actor can compromise confidentiality, integrity or availability, you've found a risk and can calculate the risk score.

You can also work with cybersecurity companies who have a good understanding of the current global threat landscape. They can provide another view of your cybersecurity profile, and use penetration testing to identify potential vulnerabilities in your assets.

Protect

How you protect your assets

Once you've identified your assets and the risks associated with them, the next step is to think about how you're going to protect them. Do you need to install software? Or do you need physical security, such as locks on doors so that no-one can gain easy access to the asset? Protection can also include processes, guidelines and/or training. The question to ask is: How can you protect the entire product lifecycle, from the software supplier or open-source component to the product destined for your customer? Threats to the supply chain of open-source components are currently a hot topic in cybersecurity, as vulnerabilities in open-source software can cause problems to spread worldwide. For this reason, threat actors are putting considerable effort into open-source software.

Detect

Detect if somebody gets access to your assets

The next step is to monitor to detect whether anyone is accessing your assets, and to identify any new vulnerabilities or risks associated with them. You must have the tools or means to detect if your system is under attack. Patch Tuesday" is an unofficial term used to designate the regular publication of security patches by major software manufacturers and others. Installing these updates is a good way of securing your system. Updates help protect systems against automated exploits used by "script kiddies" and other threat actors.

Reply

In case of cybersecurity attack you need to respond

A cybersecurity attack is inevitable at some point. When it happens, you need to be able to react. That's why it's essential to have access to centralized server audit and system logs. These and forensic tools are needed to discover how the threat actor got in, to identify who he is, and to investigate what he has actually done in your environment.

Companies should also be practicing simulation exercises on what to do when a security incident is detected. It's too late to start inventing this while there's a case in progress! You need to regularly practice your response processes.

For example, if you're dealing with personal information that has been compromised in the course of a crime, you need to know who is responsible for internal and external communication. Public communication is often an area in which companies fail, as it can reveal that they are unable to understand the extent of a breach. This is the case when a company constantly publishes new information about a security problem, explaining each time that the situation was in fact worse than originally thought.

Companies shouldn't try to explain things away - it's necessary to be clear and honest about what happened. The way you communicate affects your credibility and the trust people place in you in the long term.

Recovery

You need to ensure systems work again

The final step is to recover your assets and ensure that the systems are up and running again, so that your business can continue to operate. Planning and practice are important in this recovery phase. To limit the consequences of a breach, you need not only to keep backups, but also to test them regularly to make sure they work and can be restored. If you never test your backups and they're rotten, it's as if you had no backups at all. Another important aspect of recovery is learning from your mistakes, which means implementing the right actions to be better prepared for the next cybersecurity attack.

Man in a suit interacting with a holographic interface displaying security icons.

For more details on privacy and security in Tekla products, please visit the Tekla Trust Center and discover the Tekla product security white papers.

Related articles

Article

3 ways ArcGIS Utility Network and Trimble Cityworks modernize asset management

Explore three benefits of using Esri ArcGIS Utility Networks and Trimble Cityworks to streamline and...
Read full article
Article

4 ways Trimble Vegetation Manager modernizes utility vegetation management programs

Discover four ways that your utility organization can start modernizing its utility vegetation manag...
Read full article
Article

5 applications for 3D GIS in local government and utilities

3D data will play a significant role in the digital transformation of local government, utility, and...
Read full article
Attention

We tried to combine the products in your guest cart with your saved cart, but we encountered an issue while merging them. When choosing a subscription, please select either monthly or yearly as they cannot be combined. Kindly review your cart before proceeding to checkout.

Cart updated
Some items in your cart are not available for purchase in your region, so we removed them. Please review your cart before proceeding.

Items Removed:
Attention

The software you are trying to purchase is not available in your country or region.

Cart updated
The items in your cart have been updated for two reasons. Firstly, the prices now match the currency linked to your account address. Secondly, some items have been removed because they are not available for purchase in your region. Please review your cart before proceeding.

Items Removed:
Cart updated
The items in your cart have been updated for two reasons. Firstly, you've added too many of one item to your cart. Secondly, some items have been removed because they are not available for purchase in your region. Please review your cart before proceeding.

Items Removed:
Cart updated
The items in your cart have been updated for three reasons. Firstly, the prices now match the currency linked to your account address. Secondly, you've added too many of one item to your cart. Thirdly, some items have been removed because they are not available for purchase in your region. Please review your cart before proceeding

Items Removed:
Cart updated

Your currency has been changed to match the currency associated with your account address.

Cart updated

Your cart has been updated for two reasons. First, the prices now reflect the currency associated with your account address. Second, you've added too many of one item to your cart. Please review your cart before proceeding.

Cart updated

While combining the products in your guest cart with your saved cart, at least one item in your cart has exceeded the maximum allowable quantity. Please review and correct your cart before proceeding to checkout.

Attention

We were unable to access your account information. Please contact customer support for assistance.

Attention
Unable to update shopping cart information. Please refresh the page to resolve the issue. If this issue persists, please contact Trimble support.
© 2026 Trimble Inc.

Trimble is a global technology company that connects the physical and digital worlds, transforming the ways work gets done. With relentless innovation in precise positioning, modeling and data analytics, Trimble enables essential industries including construction, geospatial and transportation. Whether it's helping customers build and maintain infrastructure, design and construct buildings, optimize global supply chains or map the world, Trimble is at the forefront, driving productivity and progress.