{"id":1362,"date":"2021-10-25T15:01:52","date_gmt":"2021-10-25T15:01:52","guid":{"rendered":"https:\/\/ribesalat.com\/differences-between-active-security-and-passive-security-in-it\/"},"modified":"2025-11-17T08:49:06","modified_gmt":"2025-11-17T08:49:06","slug":"differences-between-active-security-and-passive-security-in-it","status":"publish","type":"post","link":"https:\/\/ribesalat.com\/en\/differences-between-active-security-and-passive-security-in-it\/","title":{"rendered":"Differences between active security and passive security in IT"},"content":{"rendered":"<p><b>IT security is a complex topic<\/b><span style=\"font-weight: 400;\">,<\/span> <span style=\"font-weight: 400;\">especially in recent times, as the <\/span><b>rise of remote work<\/b><span style=\"font-weight: 400;\"> and the <\/span><b>accelerated digital transformation of businesses<\/b><span style=\"font-weight: 400;\"> has led to a <\/span><b>significant increase in vulnerabilities and weaknesses<\/b><span style=\"font-weight: 400;\">. <\/span><b>Hackers and cyber-criminals exploit potential weak points to introduce malware<\/b><span style=\"font-weight: 400;\"> in order to steal important data from companies and even slow down or disable their systems or networks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To ensure optimal levels of protection in IT systems and networks, organisations need to implement <\/span><b>two types of IT security systems: active security and passive security<\/b><span style=\"font-weight: 400;\">. What do they consist of? What are the differences between them? At <\/span><a href=\"https:\/\/ribesalat.com\/en\/risk-consultancy\/\"><b>Rib\u00e9Salat<\/b><\/a><span style=\"font-weight: 400;\">, we explain it in detail.<\/span><\/p>\n<div id=\"attachment_3344\" style=\"width: 2570px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3344\" class=\"wp-image-3344 size-full\" src=\"https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-scaled.jpg\" alt=\"IT security\" width=\"2560\" height=\"1752\" srcset=\"https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-scaled.jpg 2560w, https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-300x205.jpg 300w, https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-1024x701.jpg 1024w, https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-768x525.jpg 768w, https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-1536x1051.jpg 1536w, https:\/\/ribesalat.com\/wp-content\/uploads\/2021\/09\/seguridad-informatica-2048x1401.jpg 2048w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><p id=\"caption-attachment-3344\" class=\"wp-caption-text\"><em>IT security<\/em><\/p><\/div>\n<h2><b>What are active security and passive security?<\/b><\/h2>\n<p><b>Computer security, IT security or cybersecurity<\/b><span style=\"font-weight: 400;\"> can be defined as a <\/span><b>set of Information and Communications Technology (ICT) mechanisms and procedures designed to provide protection<\/b><span style=\"font-weight: 400;\">, and involve a wide range of systems and devices: hardware, software, networks and all types of computer equipment, including mobile devices (smartphones and tablets) and computers.<\/span><\/p>\n<h2><b>The importance of implementing active and passive security systems<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Ensuring the <\/span><b>security of digital data and information<\/b><span style=\"font-weight: 400;\">, as well as your <\/span><b>IT systems<\/b><span style=\"font-weight: 400;\">, is a <\/span><b>difficult objective to achieve but one that is absolutely necessary<\/b><span style=\"font-weight: 400;\">, a challenge faced by all companies, regardless of their size, and also by self-employed professionals.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Otherwise, <\/span><b>they risk exposing the data and information they process to hackers and cyber-criminals<\/b><span style=\"font-weight: 400;\">, whose objective is to use them for fraudulent purposes: the sale of personal data, making purchases or carrying out banking transactions without your consent, identity theft, etc. The consequences can be the loss of customers and the credibility of the company or professional, financial damage, and heavy fines and penalties. <\/span><b>Another possible risk is digital sabotage<\/b><span style=\"font-weight: 400;\">, which can seriously affect the operations, profitability and effectiveness of the organisation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In view of the serious consequences that a cyberattack may have for a company, it is essential to <\/span><b>use the tools available and implement all the measures necessary to avoid this<\/b><span style=\"font-weight: 400;\">, both those that are <\/span><b>preventive (active)<\/b><span style=\"font-weight: 400;\"> and those that focus on dealing with the situation when there has already been a <\/span><b>security incident (passive)<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><b>Difference between active and passive security<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The difference between active and passive computer security is that<\/span><b> the former attempts to prevent the attack or incident before it occurs, <\/b><span style=\"font-weight: 400;\">meaning it is<\/span><b> proactive<\/b><span style=\"font-weight: 400;\">. In contrast, <\/span><b>passive security refers to <\/b><span style=\"font-weight: 400;\">measures the company takes to<\/span><b> respond to computer security issues when they have already occurred and try to find a solution<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Below we list the<\/span><b> main measures for each type of IT security<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h3><b>Active security measures\u00a0<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The installation of <\/span><b>effective, up-to-date antivirus software<\/b><span style=\"font-weight: 400;\"> on company equipment, networks and systems, in order to combat the main types of malware (computer viruses).<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The<\/span> <span style=\"font-weight: 400;\">design and implementation<\/span><b> of effective policies for managing <\/b><span style=\"font-weight: 400;\">user <\/span><b>passwords, credentials and authorisation.<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cybersecurity <\/span><b>awareness and training campaigns<\/b><span style=\"font-weight: 400;\"> for all employees.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internal and external<\/span><b> audits to detect vulnerabilities in systems and equipment, and resolve them<\/b><span style=\"font-weight: 400;\">.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Regular frequent backups <\/b><span style=\"font-weight: 400;\">of the company&#8217;s software, applications, information and data.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Passive security measures<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Elimination of malware from infected equipment <\/b><span style=\"font-weight: 400;\">using appropriate software.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Recovery of lost or damaged information<\/b><span style=\"font-weight: 400;\"> from previously made backups.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><\/p>\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If a cyberattack has been detected, <\/span><b>make hard disk partitions or use independent repositories<\/b><span style=\"font-weight: 400;\"> to prevent the spread of malware.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Generally speaking, <\/span><b>active security is considered the ideal option<\/b><span style=\"font-weight: 400;\">, as it involves taking measures to prevent any computer incident. The most advanced prevention systems, recommended for companies with particularly sensitive information (banking, healthcare, traffic control and other basic services) <\/span><b>rely on the services of analysts specialised in preventing and neutralising future cyberattacks<\/b><span style=\"font-weight: 400;\"> through complex defence systems, which <\/span><b>combine the knowledge and experience of past situations with real-time information<\/b><span style=\"font-weight: 400;\"> relating to multiple parameters.<\/span><\/p>\n<h2><b>Impact of cyberattacks on companies<\/b><\/h2>\n<p><b>IT security<\/b><span style=\"font-weight: 400;\">\u00a0protects revenue, data, and continuity. When it fails, the impact translates into direct losses and knock-on effects on sales, operations, and compliance:<\/span><\/p>\n<h3><b>Loss of critical and financial data<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Exfiltration, encryption, or deletion<\/b><span style=\"font-weight: 400;\"> of accounting information, intellectual property, and customer databases.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Increased costs<\/b><span style=\"font-weight: 400;\"> due to restorations, audits, IT overtime, and urgent acquisition of tools.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Risk of incorrect decisions<\/b><span style=\"font-weight: 400;\"> due to working with incomplete or manipulated data.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Reputational damage<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Decline in trust and increased customer churn<\/b><span style=\"font-weight: 400;\">, especially if the organisation handles personal data or payment information.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Difficulty closing deals and higher acquisition costs due to <\/b><span style=\"font-weight: 400;\">increased commercial friction.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Internal impact: <\/b><span style=\"font-weight: 400;\">demotivation and turnover if crisis communication is poorly managed.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Legal and regulatory costs (GDPR, LOPDGDD)<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Obligations to notify<\/b><span style=\"font-weight: 400;\"> authorities and affected parties within strict deadlines.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Potential sanctions and civil claims <\/b><span style=\"font-weight: 400;\">arising from cybersecurity breaches.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Costs <\/b><span style=\"font-weight: 400;\">of legal advice, due diligence documentation, and updating policies and contracts.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Business disruption<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Downtime of key applications and services; <\/b><span style=\"font-weight: 400;\">performance degradation due to reactive responses.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Technical teams diverted<\/b><span style=\"font-weight: 400;\"> to containment and remediation tasks, causing a domino effect on projects.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Loss of productivity and sales<\/b><span style=\"font-weight: 400;\"> due to unavailability, bottlenecks, and long recovery times.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h2><b>The role of cyber insurance<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Cyber insurance transfers part of the financial risk of incidents that affect <\/span><b>IT security<\/b><span style=\"font-weight: 400;\">. It does not prevent the attack,<\/span><b> but it reduces the financial cost and accelerates the return to normal<\/b><span style=\"font-weight: 400;\"> through specialised assistance.<\/span><\/p>\n<h3><b>What is cyber insurance?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">It is a <\/span><a href=\"https:\/\/ribesalat.com\/en\/sectors\/tech\/\"><b>policy<\/b><\/a><span style=\"font-weight: 400;\"> that protects against <\/span><b>economic losses<\/b><span style=\"font-weight: 400;\"> resulting from incidents that affect your <\/span><b>IT security<\/b><span style=\"font-weight: 400;\">. To take out a policy, <\/span><b>minimum maturity requirements<\/b><span style=\"font-weight: 400;\"> are usually demanded (MFA, verified backups, patches, response plan), and the limits, sub-limits, and excesses are adjusted according to the risk profile. Let&#8217;s see exactly what it covers:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Data and systems recovery costs: <\/b><span style=\"font-weight: 400;\">restoration from backups, environment reconstruction, forensic analysis and containment. It usually includes technical hours, tools and certified suppliers.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Liability to customers or third parties: <\/b><span style=\"font-weight: 400;\">compensation for data breach, unavailability of services, or protection failures. It includes legal defence and negotiation with claimants.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Legal costs and penalties: <\/b><span style=\"font-weight: 400;\">attorney fees, compliance with deadlines and formal communications. Some policies limit or exclude administrative sanctions: review conditions.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Incident support services: <\/b><span style=\"font-weight: 400;\">24\/7 support, response coordination, crisis management, and public communication. In ransomware attacks, support in assessing and managing extortion, always within the applicable legal framework.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Aspects to review before purchasing<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Limits<\/b><span style=\"font-weight: 400;\"> per event and annual <\/span><b>aggregates<\/b><span style=\"font-weight: 400;\">, <\/span><b>sub-limits<\/b><span style=\"font-weight: 400;\"> by item (forensic, PR, notifications).<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Excesses and waiting periods.<\/b><b>\n<p><\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Exclusions<\/b><span style=\"font-weight: 400;\"> (internal fraud, known existing faults, serious breaches).<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>IT security maturity prerequisites<\/b><span style=\"font-weight: 400;\"> (MFA, EDR, patches, verified backups, response plan).<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<\/ul>\n<h3><b>Prevention vs. coverage<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">It is important to note that insurance <\/span><b>does not replace<\/b> <b>IT security<\/b><span style=\"font-weight: 400;\">: it covers the residual impact. An effective strategy combines controls and insurance, incorporating all the elements of <\/span><b>active cybersecurity<\/b><span style=\"font-weight: 400;\"> mentioned earlier.<\/span><\/p>\n<h2><b>The day half the world was encrypted: the WannaCry case<\/b><\/h2>\n<p><a href=\"https:\/\/www.deloitte.com\/es\/es\/services\/risk-advisory\/perspectives\/los-cinco-mayores-ciberataques-de-la-historia.html\" target=\"_blank\" rel=\"noopener\"><strong>WannaCry <\/strong><\/a><span style=\"font-weight: 400;\">was a<\/span> <span style=\"font-weight: 400;\">ransomware attack that spread on 12 May 2017 by exploiting the SMBv1 vulnerability (MS17-010), which Microsoft had already patched in March, <\/span><b>automatically encrypting devices across entire networks<\/b><span style=\"font-weight: 400;\">. <\/span><span style=\"font-weight: 400;\">Within a few hours, it affected over <\/span><b>200,000 devices<\/b><span style=\"font-weight: 400;\"> in at least <\/span><b>150 countries<\/b><span style=\"font-weight: 400;\">, according to Europol and subsequent technical reports. Notable victims included NHS hospitals in the UK, causing ambulance diversions and appointment cancellations, and companies such as Telef\u00f3nica and Renault-Nissan, which halted operations to contain the outbreak. The global economic impact was estimated in the billions of dollars.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A common pattern among the hardest-hit organisations was<\/span><b> a lack of basic<\/b> <b>cybersecurity controls<\/b><span style=\"font-weight: 400;\">: unpatched systems, no network segmentation, and unverified backups, allowing the ransomware to move laterally and disrupt business continuity. In the NHS, official reports highlighted that insufficient preparedness and outdated IT practices amplified disruption and recovery costs, underlining the need for regular updates, audits, and resilience testing. <\/span><b>The key lesson: <\/b><span style=\"font-weight: 400;\">organisations that maintained up-to-date patches, segmentation, and recoverable backups drastically reduced the impact.<\/span><\/p>\n<h2><b>Prevention and coverage combined<\/b><\/h2>\n<p><b>Cybersecurity <\/b><span style=\"font-weight: 400;\">requires an intelligent combination of preventive (active) controls and containment and recovery measures (passive). This reduces the likelihood of intrusions and limits their impact on data, operations, reputation, and regulatory compliance. However, <\/span><b>no system is infallible: <\/b><span style=\"font-weight: 400;\">a well-designed <\/span><b>cyber insurance policy<\/b><span style=\"font-weight: 400;\"> enables a rapid response, funds recovery, and protects the organisation against claims and legal costs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">At <\/span><b>Rib\u00e9Salat<\/b><span style=\"font-weight: 400;\">, we help assess risks, define the <\/span><b>IT security <\/b><span style=\"font-weight: 400;\">requirements demanded by insurers, and obtain the cyber insurance that fits your actual exposure. If you want to strengthen your protection and be prepared for incidents, <\/span><a href=\"https:\/\/ribesalat.com\/en\/contact\/\"><b>contact us<\/b><\/a><span style=\"font-weight: 400;\"> for personalised advice.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT security is a complex topic, especially in recent times, as the rise of remote work and the accelerated digital transformation of businesses has led to a significant increase in vulnerabilities and weaknesses. Hackers and cyber-criminals exploit potential weak points to introduce malware in order to steal important data from companies and even slow down [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":892,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[37],"tags":[],"class_list":["post-1362","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-innovation-and-technology"],"_links":{"self":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/1362","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/comments?post=1362"}],"version-history":[{"count":2,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/1362\/revisions"}],"predecessor-version":[{"id":3357,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/posts\/1362\/revisions\/3357"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/media\/892"}],"wp:attachment":[{"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/media?parent=1362"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/categories?post=1362"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ribesalat.com\/en\/wp-json\/wp\/v2\/tags?post=1362"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}