Time To Speak The Language Of Risk

Cybersecurity is transitioning from being strictly a technical problem to becoming a risk-based issue. 

The transition is becoming top of mind among cybersecurity professionals, executives, board members, shareholders, analysts and other thought leaders.

According to a survey conducted by Osterman Research, cyber risks were ranked as a top priority for the majority of board members surveyed, alongside other risks such as financial, regulatory, and legal. More than half of board members say IT and security executives will lose their jobs because of failing to provide them with useful, actionable information.

Boards speak the language of risk and are holding security leaders accountable for doing the same, yet many security leaders are struggling to do so.

The Osterman report also reveals more than half (54%) of board members agree or strongly agree that the data presented is too technical.

While in writing, the concept seems straightforward, in actual execution, it can be difficult. The role of the cybersecurity professional was created based on technology-based needs. 

How many DDoS events were blocked? How many vulnerabilities do we need to patch today? Cybersecurity professionals lived and breathed technology; they worked in a silo and were known across the business as the “IT team in the corner office.”

Considering cybersecurity professionals came from this deeply rooted, technology-focused place, shifting to speaking risk is almost like learning a foreign language. So how can they make the transition as smooth and seamless a possible?

Cybersecurity professionals must first learn how to think risk, which begins with defining it. Risk is the potential of loss caused by some event - it is a consequence of the alignment of threats and vulnerabilities against an asset of value.

A threat without a vulnerability or a vulnerability without a threat does not present a risk. For example, an unlocked window is a security vulnerability; but if that window is on the 50th floor of a high rise, it is unlikely that a burglar would scale the building to break in (the threat), and therefore it does not present much of a risk.  

However, if you put the Hope Diamond in that room, the risk is elevated because the diamond’s high value may entice a thief to attempt a threat, albeit a low probability one, but a threat nonetheless.

When assessing their cyber risk, cybersecurity professionals must first focus on identifying the most valued information assets, those that could cause the most damage if compromised, and then apply the risk equation. 

They should look at the threats to their most valued assets, identify associated vulnerabilities, determine the probability of those two meeting, the impact the compromise would have, and apply their cyber-security resources accordingly. 

They should ask themselves:

  • Am I thinking about probabilities and impacts in a structured way to prioritise my activities and resources or am I treating everything equally?
  • Am I thinking about threats, vulnerabilities and impacts in isolation or am I thinking about where they intersect to present a real risk to the business?     
  • Am I reporting business risks to the board together with recommendations that will increase or decrease that risk over time, or am I only presenting recommendations without the context of how they impact the business?

If they think like a true risk professional, speaking the language of risk comes easily. 

When reporting to the board, security professionals should:

  • Paint a picture that highlights the past, present and future state of the company’s cyber-risk, including lessons learned, goals and progress against those goals.
  • Focus on asset value and impact to the business if those assets were compromised.
  • Present the top risks impacting the business, with the top being the intersection between the most likely and the most impactful cyber risks to the company.
  • Show the trend of how these risks have increased/decreased through their organization's actions or lack thereof, ultimately based on the board’s guidance.
  • Show how they expect their proposed actions or lack thereof, will impact these trends.
  • Use specific data points about threats and vulnerabilities that are important supporting information to show the actions that affect the various cyber risks, but make sure these data points are supporting not leading.
  • Use a consistent format from month to month, with metrics that can be continually compared and trended over time for progress.

Security leaders that run around with their hair on fire in constant reactive mode are being left behind. Their goal should be to understand the company’s cyber risks and manage those risks in line with the board's direction and appetites.

To be successful at that, they need to be able to monitor, measure and report those risks, both in support of their operational plans as well as in support of communicating to their board so that they can provide informed guidance and resourcing.

Infosecurity-Magazine

You Might Also Read:

Strategies For A Cyber Security Culture (£):

Your Directors Don’t Understand Cyber Threats Endangering Business (£):

Board-level Cyber Literacy Is Low, Discomfort High:

 

« North Korea More Likely To Launch A Cyber Attack Than A Military Strike
AI Might Be The Ultimate Answer To Cyber Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

BackupVault

BackupVault

BackupVault is a leading provider of completely automatic, fully encrypted online, cloud backup.

Clayden Law

Clayden Law

Clayden Law are experts in information technology, data privacy and cybersecurity law.

Cyber Together

Cyber Together

Cyber Together is dedicated to advancing the cyber security industry by giving businesses access to Israel’s leaders, innovators and great minds in the field of cyber security.

Fenror7

Fenror7

Fenror7 lowers the TTD (Time To Detection) of hackers, malwares and APTs in enterprises and organizations from 300 days on average to 24 hrs or less.

Cyber Aware

Cyber Aware

Cyber Aware aims to drive behaviour change amongst small businesses and individuals, so that they adopt simple secure online behaviours.

Quaynote Communications

Quaynote Communications

Quaynote Communications is a specialist conference and communications company focused primarily on the maritime, yachting, aviation and security industries.

SANS CyberStart

SANS CyberStart

SANS CyberStart is a unique and innovative suite of tools and games designed to introduce children and young adults to the field of cyber security.

Capula

Capula

Capula is a leading system integration specialist for control, automation and operational IT systems across all applications and industry sectors.

WiJungle

WiJungle

WiJungle is an Indian Cyber Security Company that develops and markets a unified network security gateway solution.

BioConnect

BioConnect

BioConnect provide biometric access control solutions to verify a person’s identity across physical, IOT and digital applications.

ioXt Alliance

ioXt Alliance

The ioXt Alliance is a group of manufacturers, industry alliances and government organizations dedicated to harmonizing best security practices in a highly connected world.

BeyondTrust

BeyondTrust

BeyondTrust is a leader in Privileged Access Management, offering a seamless approach to preventing data breaches related to stolen credentials, misused privileges, and compromised remote access.

Anexinet

Anexinet

From full-stack engagement strategies and solutions to modern, secure infrastructure products and services, Anexinet focuses on technology-enabled business transformation that drives value.

ImmuniWeb

ImmuniWeb

We Simplify, Accelerate and Reduce Costs of Security Testing, Protection and Compliance.

InfusionPoints

InfusionPoints

InfusionPoints is your independent trusted partner dedicated to assisting you in building your secure and compliant business solutions.

CornerStone

CornerStone

CornerStone is an award winning, independent risk, cyber and security consulting firm providing a range of Risk Management, Security Design and Implementation Management Services.

TPx Communications

TPx Communications

TPx is a leading managed services provider offering a full suite of managed IT, unified communications, network connectivity and security services.

Gravitee

Gravitee

Gravitee helps organizations manage and secure their entire API lifecycle with solutions for API design, management, security, productization, real-time observability, and more.