Generating Competitive Advantage Through Compliance

All too often security compliance is regarded as a series of hurdles the business needs to jump through in order to achieve accreditation. It can tend to be regarded as red tape and a barrier to getting things done.

But changing the mindset of the executive body so that regulations are regarded as helping rather than hindering ambitions can pave the way for the business to become more efficient and more competitive in the marketplace.

From a security perspective, cyber risk is the predominant factor in the decision-making process and this seems to contradict the primary objectives of the board, which are to save money, save it faster, make money, make it faster and manage risks that threaten those objectives.

Yet the two need not be conflicting if controls are applied in such a way that they allow the business to achieve those goals, rather than acting as an impediment. 

A good analogy here is Formula 1 racing. Racing driver, Mario Andretti, famously said: “It’s amazing how many drivers, even at the Formula 1 level, think that the brakes are for slowing the car down”. In actual fact, those brakes are there to provide the driver with the control to enter and exit a corner and in so doing, optimise the performance of the car and the time taken to complete the circuit. Similarly, compliance can enable processes and procedures to be better understood. 

Streamlined By Compliance

For example, there may well be changes or improvements that the business wants to make to software or systems to boost its competitiveness and it’s at this point risk and compliance can become an obstacle. However, if the business puts compliance first and implements the necessary processes, expectations can be met quicker. By putting processes X, Y and Z through the risk management lens, it becomes possible to see what elements are or are not applicable and what could confer competitive advantage versus what could constitute a block.

Let’s use the hypothetical example of a US company selling software to a non-aligned market such as Russia or China. That team would face export controls on its software. By identifying where those barriers to export are at the earliest stages in the process, the business can get the product into production more quickly without the need to retroactively engineer further down the line which would cause delays. The process is effectively streamlined in accordance with compliance requirements.

To get to this position, the board needs to actively engage with its responsibilities from a regulatory compliance perspective. Of course, compliance with cyber security regulations and standards is not optional – it is a legal requirement that protects the company from fines and reputational damage – but complying with regulations versus utilising them are two very different things.

To establish where the business is in terms of its compliance maturity, it’s necessary to ask some searching questions.

Questions To Consider

First and foremost, what role does the board play in overseeing the company’s cyber risk management and compliance strategy? Is it purely passive or does it seek to lead? Does the board seek to stay informed about the latest cyber threats and trends or is it simply reactive? How does the board evaluate the effectiveness of the company’s cyber risk and compliance management, and applied security measures? What measures are in place to ensure that the company complies with relevant cyber security regulations and standards? And how would the board describe the company’s approach to ensuring that there is an appropriate incident response capability?

The answer to these questions should ideally see the board taking an active role in the security management of the company.

Effective leadership in this regard will help the business stay abreast of relevant regulations and standards and ensure that compliance efforts are thorough and proactive. This is vital because the regulatory landscape for cyber security is complex and ever-changing, so the board needs to be aware of its legal and regulatory requirements on an ongoing basis.

Compliance with Digital Operational Resilience Act (DORA) provides a good example as its relatively recent. Being able to demonstrate compliance with the standard is one thing but being able to articulate that in terms of the controls and risk management processes that are in place can be a strong business enabler. From a marketing point of view, compliance with DORA marks the business out, signifying it has met stringent demands. This then allows the business to win new customers or renegotiate contracts from a stronger position, thereby bolstering its competitiveness. 

Personal Accountability

The general direction of travel with respect to regulations is that the board is increasingly being held accountable. Revisions to disclosure requirements such as the Securities and Exchange Commission Form 8K, NIS2 on the continent and possibly the Cyber Security and Resilience Bill here in the UK, all require senior management to be able to demonstrate oversight of risk management. A failure to do so could result in those individuals being held personally responsible, making it even more pressing this issue is addressed.

The reality is that the board must now get to grips with compliance and should regard it as another critical aspect under its remit.

But this needn’t equate to an increase in workload. Senior executives at board level seldom hold cybersecurity experience so it makes sense to put in place a risk management and compliance board to keep them informed. The committee should include members with diverse expertise in finance, operations, legal, compliance, and strategic planning and should seek to evaluate, mitigate, and monitor various risks, reporting back to and informing the board. In addition to providing compliance oversight, such a committee can also identify risk, review policy, evaluate internal controls and ensure reporting mechanisms are effective.

Aided by these personnel, the board can then begin to use compliance as an enabler that that informs the decision-making process and strategically allows the business to position itself to capitalise upon market opportunities.

James Eason is GRC CRA Practice Lead at Integrity360

Image: Ideogram

You Might Also Read: 

Six Steps On The Road To NIS2 Compliance:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Safeguarding Your Business: 10 Best Practices For Mobile Device Safety
Social Media Algorithms & Their Effects »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Mobile Guroo

Mobile Guroo

Mobile Guroo is a strategy and systems integrator for Enterprise Mobility Management projects.

Subgraph

Subgraph

Subgraph is an open source security company, committed to making secure and usable open source computing available to everyone.

ThreatMark

ThreatMark

ThreatMark provides fraud detection solutions for digital banking and payments.

KLC Consulting

KLC Consulting

KLC Consulting offers information assurance / Security, IT Audit, and Information Technology products and services to government and Fortune 1000 companies.

H-ON Consulting

H-ON Consulting

H-ON Consulting develops and applies robust cyber security procedures enabling control systems to be secure.

Westminster Insight - Cyber Security Conference

Westminster Insight - Cyber Security Conference

Join colleagues this December for Westminster Insight’s Cyber Security Conference, as you’ll assess how new technologies such as AI can secure your organisation against future threats.

Leidos

Leidos

Leidos is a recognized leader in cybersecurity across the federal government, bringing more than a decade of experience defending cyber interests globally.

Razorpoint Cybersecurity

Razorpoint Cybersecurity

Razorpoint’s world-class security experts have provided advanced, effective cybersecurity expertise to corporate and public-sector organizations around the world.

Norma Inc.

Norma Inc.

Norma provides the secured wireless environment (WiFi and Bluetooth) with the unauthorized AP detection, and secures your IoT assets from various threats.

Schillings

Schillings

Shillings defends your rights to privacy, reuptation and security. We fight passionately against breaches of your privacy, attacks on your reputation and threats to your security.

Distology

Distology

Distology are an award-winning cloud security distributor bringing a wealth of experience and strong relationships with a huge breadth of partners covering the UK, Ireland and Benelux.

Velum Labs

Velum Labs

Velum Labs is a cyber intelligence company that provides simple and non-intrusive, cloud and cyber intelligence solutions; built from a market-leading understanding of cyber-attack methodology.

SequelNet

SequelNet

SequelNet is an emerging MSP, providing 360° business IT solutions and consulting services.

Allure Security

Allure Security

Allure Security AI-driven brand protection scans more of the online world for faster, more accurate detection & removal of spoof websites, social media & mobile apps -- before customers fall victim.

CyRiSo

CyRiSo

CyRiSo is a cyber security consulting company with a focus on 'as-a-service' services for the most pressing challenges of cyber security.

Harness

Harness

Harness delivers an end-to-end software delivery platform that helps engineering teams achieve the highest levels of engineering excellence.