Adversaries as 'interested parties'
- Jul 16
- 3 min read
ISO/IEC 27000:2016 clause 4.4 "Why an ISMS is important" explained the purpose of information security and an ISMS in about a page of 7 paragraphs. In ISO/IEC 27000:2026, that clause became 4.1.7 "Importance of an ISMS" and was condensed to half a page with 3 paragraphs. It's more than just a tightening-up of the wording, though, including this new text:
"Interested parties can include not only the organization’s customers, suppliers, business partners, employees, shareholders, but also government officials and, potentially, regulators. Competitors and criminals are also interested parties."
Explicitly considering adversaries such as competitors and criminals as 'interested parties' in an organisation's information risk and security arrangements substantially raises the stakes for the Information Security Management System. Obviously, their interests are diametrically opposed to the organisation's conventional stakeholders. The emphasis shifts from largely passive protection of information assets against relatively mild and generic threats to proactively defending the business against determined, competent and creative adversaries.
It's a game-changer, particularly for senior managers with their heads buried in the sand, vainly hoping that serious incidents only affect other organisations.
Here are three significant business consequences to the subtle change of wording tucked away in clause 4.1.7 ...
1. Threat-based risk assessment
2018 version: risk assessment typically focused on the organisation's most valuable information assets (particularly its key IT systems), addressing the associated vulnerabilities and potential business impacts under normal operational conditions. Asset-based assessments tend to address the organisation's systems one-by-one, a disjointed approach prone to point solutions.
2026 version: risk assessment also considers threat actors and vectors or techniques through adversarial threat modeling (e.g. STRIDE or MITRE ATT&CK frameworks), exploring their motivations, capabilities and tactics to determine how they might go about achieving their goals. This substantially widens the perspective since any device, technology, protocol, supplier or worker (not just within the organisation, not just the crown jewels) may be vulnerable to exploitation by hackers using advanced AI-enabled techniques to gain a foothold, infiltrate, escalate and compromise 'at machine speed'.
2. Risk evaluation extends throughout supply networks
2018 version: likelihood of incidents was often estimated from historical internal data or generic statistics, while impacts were measured in downtime and direct financial losses to the affected organisation, such as penalties. Longer-term consequential costs (such as reputational harm, brand devaluation and loss of business) were hard even to estimate and so were largely ignored.
2026 version: risk criteria include consideration of adversaries' willingness and capabilities to invest in mounting well-resourced and determined attacks:
Likelihood relates to the attractiveness of the organisation to, say, criminals (looking to generate cash), competitors (stealing trade secrets, intellectual property and personal information for business reasons, disrupting business activities) or spooks (long-term discreet infiltration, espionage and cybertage). What are the glittery bits most likely to catch their eyes? Just how glittery are they? How is offensive and defensive use of Artificial Intelligence changing things?
Impact criteria expand to include strategic disadvantage. For instance, a competitor accessing pre-patent secrets or pre-launch product blueprints could devastate commercial strategies. Tightly-integrated supply chains imply a widening mesh of interdependencies with common failure points or modes. Any one organisation is not just an individual, isolated target but a weakpoint that may compromise the extended commercial network. There are assurance, trust and other implications here at industry, national and societal levels - externalities that transcend cybersecurity concerns within any one organisation.
3. Security engineering for use and misuse cases
2018 version: treating information risk generally meant applying generic security controls (often point solutions) to meet baseline security requirements derived from use cases (e.g. "Personal data in the HR system must be encrypted to satisfy GDPR").
2026 version: risk treatments are explicitly engineered to disrupt determined adversaries' objectives, selecting and designing appropriate controls to counter misuse cases including potentially devastating multi-stage long-term attacks, collaboration or coercion of mutiple parties, and partial or complete failure of trusted controls. This involves due consideration of more advanced and costly approaches such as honeytokens/canaries, zero-trust network architecture and immutable backups. Broadening the perspective on threats increases the value of broad-based controls such as resilience, assurance, discreet surveillance and oversight, with behavioral analytics for anomaly detection and more automated incident responses for speed.
Bottom line: information security must be re-engineered to tackle capable adversaries determined to profit from and harm supply chains. The ISMS gives senior management the governance levers necessary to control their ISMS puppet.

Another thing that puts Hot Games at the top of the gaming industry is the social experience. Players from all around the globe are brought together by global leaderboards, online matchmaking, cooperative activities, and seasonal events. Hot games become real-life experiences that go beyond the screen when players work together to conquer challenging obstacles, share strategies, and celebrate successes.