The Do’s and Don’ts Of Security Risk Management

Managing risk effectively is a balancing act. Leveraging data while safeguarding it requires careful consideration and the application of appropriate controls.

It’s not just a matter of choosing risk methodologies based on contractual or regulatory requirements, although these will play a part, but of selecting these based on the needs of the organisation itself, which means identifying acceptable and unacceptable risks that are aligned to the risk appetite of the business.

There are a number of ways in which risk management can be misapplied. Firstly, it should fit the organisation and this means going beyond identifying risks to having a clear understanding of the goals and priorities of the business. Why? Because this sees risk management enabling the business to meet its goals without breaking either compliance commitments or risk appetite.

Risk As A Business Tool

We also need to understand what matters to the organisation in terms of the information it needs to collect, process, store and share to help it meet these business goals and priorities. This approach then allows risk management to become integral to business decision making to the point where it becomes instinctive. Once specific risk criteria are implemented some business decisions can then rely on these repeatable “canned” mitigations allowing delegated risk decisions which increase agility in the marketplace.

Another key sticking point is how risk is communicated and acted upon. It’s vital to support those at the coalface, so those charged with the responsibility for managing information risk within the organisation must have the right skills and support to be effective. As part and parcel of this, they also need access to sufficient information from every corner of the business, with input from the right people at the right time. This includes SME’s (technical/data protection specialists/vendors etc) to ensure that an accurate picture of information risk can be formed and clearly articulated.

How that risk intelligence is shared is absolutely critical to mitigating that risk. If those responsible for the provision of resources don’t understand the level of risk involved, they can’t make timely, informed and objective risk management decisions, so the risk must be translated.

Avoid ‘risk speak’

For example, risk is often analysed using matrixes and metrics leading to a Red Amber Green (RAG) assessment or perceived risk number ie 42. Although effective when visualising or triaging risk, senior management need this information to be translated into business terms. This can be achieved by stating what the impact of a risk occurring would mean against an agreed set of parameters, such as loss of business, reputational damage, financial impact or punitive measures such as penalties.

Likelihood can be a bit of a moving feast. The impact, whether it is deemed highly unlikely or very likely, will still be realised if the event happens so the risk decisions must be cognisant of this.

Ownership of risk decisions should also be documented and reviewed at planned intervals and also where specific triggers are met. These might include a change in the direction of the business, a heightened risk environment or a re-evaluation following a security incident or other external influences.

Refining Risk

Risk management isn’t a onetime process and will require revaluation and fine-tuning. It must evolve to ensure that any systems used to collect, process or store information have appropriate risk mitigation controls applied throughout their lifespan. We have all heard of the horror stories around IT being disposed of without data sanitisation! Often this can be down to a lack of funding regarding secure disposal or reuse of old IT systems.

Finally, risk management needs to be adaptive to the climate in which it is used and to the evolution of risks or emergence of new ones. We’ve seen countless examples of this over the past few years, from businesses adapting to meet the risks posed by the Internet of Things to those posed by working remotely during the pandemic.

Risk is therefore not static but neither does it need to be restrictive. Done correctly, it can bring about continuous improvement and ultimately leads to gains or growth within the business.

David Adams is a Security Consultant at Prism Infosec

You Might Also Read: 

Four Questions To Ask After An Attack:

 

« How Long Does It Take Before An Attack Is Detected?
Is It Time To Consolidate Systems? »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Senetas

Senetas

Senetas is a leading developer and manufacturer of certified high-assurance encryption solutions, dedicated to protecting network transmitted data without compromising performance.

Splunk

Splunk

Splunk provide real-time Security Information & Event Management solutions for Enterprise Networks, Cloud and small-scale IT environments

CloudHesive

CloudHesive

CloudHesive provides cloud solutions through consulting and managed services with a focus on security, reliability, availability and scalability.

Miller Group

Miller Group

Miller Group is an IT managed service provider. We proactively monitor and manage your entire business computer network. Services include backup & recovery and cyber security.

herdProtect

herdProtect

herdProtect is a second line of defense malware scanning platform powered by 68 anti-malware engines in the cloud.

Think Cyber Security (ThinkCyber)

Think Cyber Security (ThinkCyber)

ThinkCyber is a Tel Aviv-based Israeli company with a team of cybersecurity professionals who are experts in both information and operations technology.

ConvergeOne

ConvergeOne

ConvergeOne is a leading global IT services provider of collaboration and technology solutions including cybersecurity.

Hawk AI

Hawk AI

Hawk AI’s mission is to help financial institutions detect financial crime more effectively and efficiently using AI to enhance rules and find anomalies.

Emerge Digital

Emerge Digital

Emerge Digital is a technology and digital innovation business and Managed Services Provider providing solutions to SMEs.

Anchor Technologies Inc (ATI)

Anchor Technologies Inc (ATI)

Anchor provides a full spectrum of cybersecurity services assisting our clients with all aspects of cybersecurity risk planning, identification, management, and monitoring.

Foresiet

Foresiet

Foresiet is the first platform to cover all of your digital risks, allowing enterprise to focus on the core business.

MIS Solutions

MIS Solutions

MIS Solutions is a managed cloud and IT security partner making technology work for you.

Incode

Incode

Incode is the leading provider of world-class identity solutions that is reinventing the way humans authenticate and verify their identities online.

CyberNINES

CyberNINES

CyberNINES is a business specializing in helping US Department of Defense contractors become compliant and attest to federal cybersecurity regulation requirements.

Vulnify

Vulnify

At Vulnify, we’re revolutionizing the way businesses identify and manage security vulnerabilities.

Steryon

Steryon

Steryon is an innovative Cyber Resilience & Risk Management Platform for Cyber-Physical Systems (CPS), tailored for industrial infrastructures.