Companies engaged in custom software development primarily focus on delivering the functionalities required by the client (the software is to perform the functions that are ordered) within a specified budget and timeframe. Unfortunately, in many cases, the security of applications (or the security of resources within the organization) is treated as an unnecessary hindrance, which causes this aspect to be pushed to the background.

An exception occurs when security is of great importance to the client – in such cases, it is often expected that the software creator will manage data security within their organization and that security tests of the product (so-called penetration tests) will be conducted. In such instances, all identified vulnerabilities and weaknesses are to be addressed at the supplier's expense.
At first glance, it might seem impossible for cybersecurity to be a secondary concern – after all, it is primarily IT professionals who work there. However, IT is a very broad field of knowledge and specialization. Every office worker has a specialization, and the same applies in IT. Today, one can no longer think of an IT professional as someone who knows everything related to information technology. A network administrator may not necessarily know how to program, a programmer may not necessarily understand how a computer network functions, and both may not be familiar with Windows while working in a different operating system. Narrow specialization and still relatively low awareness of security mean that in companies that do not employ qualified personnel dedicated to cybersecurity, data protection issues are relegated to a lower priority. The same applies to clients ordering dedicated solutions – the lack of pressure from their side leads to a focus on what the client cares about, rather than on what is good and appropriate.
Investors allocate significant sums for dedicated solutions that require substantial labor input, which is why many new software companies, focusing solely on a specific business, notice security issues in their infrastructure far too late. Unfortunately, it is often only after the created code or processed client data has been exposed or subjected to another unfortunate event due to a breach or user error.
Pillars of Data Security
Security in organizations of this type can be divided into three different areas: technical, physical, and organizational. While security in other industries can be similarly categorized, software companies particularly stand out in terms of organizational security. The specificity of these companies means that this is a very important area, requiring education and building staff awareness in the context of creating secure software based on recognized standards. Furthermore, a very important aspect is also the secure management of code changes, appropriate versioning, or access management to the project. An unreliable approach to security during the implementation of a new product can lead to a data leak of customer information, which ultimately results in a significant likelihood of not only reputational losses but also financial ones – such as penalties imposed by supervisory authorities, e.g., the Polish DPA, due to the failure to adhere to the principle of privacy by design, which mandates the consideration of personal data protection at the design stage of a system or service.
Of course, the discussed organizational safeguards are not only training and raising staff awareness but also tailored documentation, as well as appropriate content in contracts with suppliers of the tools and solutions used. In many cases, employees are not fond of procedures, but this often happens due to a lack of understanding of their functioning. It turns out that in many cases, they can actually make life easier for employees, and for employers – facilitate business operations. The functioning of organizational safeguards in the form of adopted and applied documentation will not only standardize, accelerate, and maintain the quality of the data processing activities but also keep security at a relatively stable level. Moreover, organizational procedures will help not only new employees understand the functioning of the business but also guide older employees, especially in unusual situations, such as procedures in the event of a break-in or suspicion of a break-in.
Summary
Organizational procedures are an important aspect of the life of every software company, not only in terms of ensuring the security of processed data. The functioning of these procedures within the organization often determines the conclusion of a contract with a new client. A similar influence may arise from the presence of a person or a specialized company acting as a Data Protection Officer or Information Security Officer. Furthermore, corporate clients and other clients of software companies, for whom security is a priority, require not only adequate – specified in contractual provisions – organizational security measures but also the performance of a risk analysis and/or the implementation of specific technical safeguards. Such requirements often align with the elements described by the ISO 27001 standard – Information Security Management Systems, the implementation of which in such companies is certainly worth considering.
Each of the aforementioned areas of security is very extensive, and anaudit is essential for assessing their functioning. The outcome should include a description of the current state of security configuration of the utilized servers, network devices, systems, applications, computers, smartphones, printers, and removable media, as well as the method of securing the organization's boundaries (especially in situations where more than one company operates within the same building or buildings). Any deviation identified in the audit report from the accepted audit criteria should have a corresponding recommendation, including a description of a sample method for restoring the organization to a state compliant with those criteria.


