There is no longer any question as to whether corporate data needs to be secured. The time has come to take action to protect what has become a critical asset—one whose compromise could damage the value and reputation of the entire company. Didier LAVOINE explains.
Isn’t data security already a long-standing concern within companies?
Didier Lavoine: Surprisingly, no. The issue is actually a fairly recent one. Previously, security concerns focused on the information system as a whole: infrastructure, architecture and applications. The primary objective was to prevent operational downtime as much as possible, while securing access to and the perimeter of the information system.
However, what we had already begun to see with the shift from the concept of “corporate IT” to that of an “information system” has now become a reality: we live in a data-driven world. Whether raw, processed or temporary, data has value. Hackers have understood this too. While their “exploits” once consisted primarily of bringing down information systems, stealing, altering or corrupting data is now among their main objectives.
Does this issue therefore extend far beyond the boundaries of the IT department?
DL: Absolutely! It is a company-wide issue, particularly because insufficient protection of certain types of information, such as personal data under the GDPR, can result in criminal penalties.
Corporate data and its security have therefore become a key area of governance. At DEEP, we believe that the IT department should now be represented within the company’s governing bodies, on the same footing as its other departments, such as finance, sales and operations, regardless of what these bodies are called: management committee, board, executive committee, steering committee, etc.
What approach should companies adopt when it comes to data security?
DL: First and foremost, we recommend an approach that is both pragmatic and structured, as part of a forward-looking strategy. Designing a data security plan is only the first step. To remain effective over time, it must be actively managed and continuously adapted.
The first stage involves identifying the assets, namely the databases, which are by far the most common targets when it comes to data. This identification must cover both technological aspects—vendor, version, administration procedures, etc.—and usage, through an analysis of their business impacts using a Business Impact Analysis (BIA). This makes it possible to rank databases according to their criticality for the business.
The next step is to analyse vulnerabilities for each individual asset and identify the security measures already in place, before developing risk scenarios. Organisational aspects must also be taken into account.
Which areas are examined in practical terms?
DL: Drawing on our experience in database management, particularly with Oracle databases regardless of the version, we have developed a security assessment framework covering seven key areas:
-
Access management
-
Data security, including availability
-
The environment: infrastructure and architecture
-
Maintaining operational conditions
-
Licences and supplier contracts
-
Teams, including HR-related aspects
-
Physical security
This framework leads to a remediation phase which, for Oracle databases, is supported by a range of Oracle solutions, including:
-
Data masking with Data Masking & Subsetting
-
Data encryption with Network Encryption and Transparent Data Encryption
-
Database lifecycle management with Database Lifecycle Management
-
Data redaction or pseudonymisation with Data Redaction
-
Advanced access control management with Database Firewall and Database Vault
-
Unified database control with Database Security Assessment (DBSAT) and Data Safe
For each identified risk, the security plan must therefore define the corresponding actions, the maturity level of those actions and how they will progress over time. Once again, the data security plan must be managed over the long term if it is to remain effective.
To support this approach, we have chosen to equip the framework with a risk management tool for managing cyber risks and compliance.
What about standards-related risks?
DL: For around two years, this has clearly become a major concern for companies: ITIL is no longer enough, and many organisations have begun working towards ISO 27001 certification. In this context, end-to-end data traceability and a continuous improvement approach must be implemented. We can now help our clients easily incorporate data security into their ISO 27001 initiatives.
In conclusion, what advice would you give companies looking to begin securing their data?
DL: While we believe there are a number of best practices, there is no single way of doing things. It all depends on the company’s environment and organisation, as well as the types and volumes of data it manages.
What is certain, however, is that companies should not attempt a “big bang” transformation, but should instead start with a small number of databases—particularly the most critical ones, on which business continuity clearly depends.
In every case, companies must ensure that long-term operational monitoring is in place. A data security plan that is relevant and effective at a given point in time will generally not remain so for very long.
Contact us
Do you have any questions about an article? Do you need help solving your IT issues?
Contact an expertOther articles in the category Cybersecurity
DDoS Attacks in Luxembourg – 2025 Statistics
Explore monthly statistics on volumetric DDoS attacks detected in Luxembourg in 2025 by DEEP. Insights into attack types, durations, and trends to enhance your cybersecurity posture
Published on
31 March 2025
DDoS attacks in Luxembourg in 2024
Discover the statistics of DDoS attacks detected in Luxembourg in 2024 by POST Cyberforce.
Published on
31 March 2024
DDoS attacks in Luxembourg in 2023
Discover the statistics of DDoS attacks detected in Luxembourg in 2023 by POST Cyberforce.
Published on
15 February 2023








Our experts answer your questions
Do you have any questions about an article? Do you need help solving your IT issues?
Got a project? Questions?
Send us a message and our experts will get back to you quickly.
DEEP? Your digital ally!
With DEEP, turn your IT projects into measurable and sustainable growth drivers.