Security in IT is very important. Unauthorised access to confidential information can cause major disruption to companies, and to individuals lives. Some disruption can have life changing impacts to finance and reputation. Even 'lesser' security issues, such as viruses, can cause massive damage to company systems. Breaches to Operational Technology (OT) systems (such as SCADA) in utilities could cause countrywide failures, and put lives at risk. IT security is therefore quite rightly taken very seriously by governments, organisations and individuals.
However IT security is just one amongst the many risks we all face on a daily basis. Even a major breach of a utility OT system would not have the impact of an atomic bomb, and yet the world managed to increase overall wealth, and made great strides to reduce poverty, throughout the Cold War, under the threat of mutually assured destruction. IT security is therefore just another risk that we all have to manage.
Unfortunately in too many organisations IT security is used as a reason not to implement technological improvements. For example, video conferencing between computers, and even mobile devices, is something many of us use regularly, however video conferencing between organisations is very rare, generally because of 'IT security' concerns. Sharing of information is frequently blocked, and yet shared information often increases knowledge and opportunity for all of the participating organisations. For example, Transport for London (TfL) made most of the information for its transport systems (e.g. timetables) publically available: there are now a plethora of 'apps' to help travellers plan their journeys, all of which have been produced at no expense to TfL, and increase customer satisfaction.
I believe it is a duty of those of us in the IT world to ensure that IT security is managed appropriately, and not used as an excuse to block the business and personal benefits that our innovative technology can bring. Like any other risk it should be managed appropriately and balanced against the benefits. We cannot let the few who would wish to take advantage of us through IT security breaches constrain our future.