[An Opinion Piece for CIOs of Large Enterprises]
By Noam Rosenfeld, CEO of WaveBL (Cyber Security Specialist)
For decades, we have operated according to an almost self-evident model: the organization defines a business process, IT builds an information system to support it and then we begin protecting it.
Firewalls, identity and access management, DLP, EDR, SIEM, encryption, monitoring, fraud prevention, and many other layers are designed to protect the system, its data, and its users. Each has a valid purpose. But collectively, they have created a reality that every CIO should examine: an increasing share of IT investment and complexity is no longer dedicated to the business process itself, but to protecting the architecture we chose to implement it.
The traditional response to growing cyber threats has been logical: a new threat emerges – another defense mechanism is added. Over time, however, this has created a paradox: we add systems to protect systems, and then we need to manage, integrate, and protect the systems we added.
So, alongside the question “Which additional security tool are we missing?”, CIOs should consider a more architectural question:
Can we design information systems so that some of their trust, verification, and data integrity capabilities are inherent in the infrastructure itself?
This is not about replacing cybersecurity systems or eliminating them. Users, identities, endpoints, networks, APIs, and enterprise integrations still need to be protected. The question is whether the right architecture can reduce some of the need for external layers whose purpose is to establish trust, verification, and proof after the fact.
WaveBL: When Trust Is Built Into the Infrastructure
A good example can be found in one of the world’s most complex business processes – global trade.
When we at WaveBL set out to digitize the transfer of trade documents, we faced a multi-party process involving shipping carriers, exporters, importers, banks, freight forwarders, and other participants operating across different countries, regulatory environments, and information systems.
We could have built a conventional digital document-transfer system and then surrounded it with layers of security, verification, control, and reconciliation.
We chose a different path.
We asked whether some of the fundamental requirements for trust and security could be built directly into the infrastructure itself.
The Bill of Lading illustrates the challenge well. Turning a paper document into a digital file is relatively simple. Turning it into a trusted digital asset – while maintaining authenticity, integrity, uniqueness, and a verifiable chain of transfer – is an architectural challenge.
At WaveBL, we therefore designed the trust model and the information system together. We built a distributed infrastructure in which blockchain, cryptography, digital signatures, identity mechanisms, and privacy are part of the infrastructure through which the business process takes place – rather than simply additional layers added after the system has been built.
This does not mean cybersecurity is no longer necessary.
It means that some of the trust that would otherwise need to be created and verified through additional systems is already supported by the underlying architecture.
The lesson from WaveBL is not that every enterprise system needs blockchain. Nor is blockchain the right technology for every process.
The more important question is: In which business processes are we investing significant resources to create trust between parties, and could some of that trust become an inherent property of the infrastructure itself?
Choose one significant business process involving high-value information, multiple organizations or parties, and a substantial need for trust, verification, or proof of origin. Map the systems currently required to provide trust, verification, integrity, reconciliation, and auditability.
Then ask: If some of these capabilities were built into the infrastructure itself, what would the system look like?
The existing architecture may still prove to be the right choice. But if a different architecture can reduce complexity, decrease reconciliation, improve auditability, and lower security overhead, it is worth exploring.
The next phase of digital transformation is not simply about making processes digital. It is about asking whether the trust required to operate them can be built into the digital infrastructure itself.