Time To Speak The Language Of Risk

Cybersecurity is transitioning from being strictly a technical problem to becoming a risk-based issue. 

The transition is becoming top of mind among cybersecurity professionals, executives, board members, shareholders, analysts and other thought leaders.

According to a survey conducted by Osterman Research, cyber risks were ranked as a top priority for the majority of board members surveyed, alongside other risks such as financial, regulatory, and legal. More than half of board members say IT and security executives will lose their jobs because of failing to provide them with useful, actionable information.

Boards speak the language of risk and are holding security leaders accountable for doing the same, yet many security leaders are struggling to do so.

The Osterman report also reveals more than half (54%) of board members agree or strongly agree that the data presented is too technical.

While in writing, the concept seems straightforward, in actual execution, it can be difficult. The role of the cybersecurity professional was created based on technology-based needs. 

How many DDoS events were blocked? How many vulnerabilities do we need to patch today? Cybersecurity professionals lived and breathed technology; they worked in a silo and were known across the business as the “IT team in the corner office.”

Considering cybersecurity professionals came from this deeply rooted, technology-focused place, shifting to speaking risk is almost like learning a foreign language. So how can they make the transition as smooth and seamless a possible?

Cybersecurity professionals must first learn how to think risk, which begins with defining it. Risk is the potential of loss caused by some event - it is a consequence of the alignment of threats and vulnerabilities against an asset of value.

A threat without a vulnerability or a vulnerability without a threat does not present a risk. For example, an unlocked window is a security vulnerability; but if that window is on the 50th floor of a high rise, it is unlikely that a burglar would scale the building to break in (the threat), and therefore it does not present much of a risk.  

However, if you put the Hope Diamond in that room, the risk is elevated because the diamond’s high value may entice a thief to attempt a threat, albeit a low probability one, but a threat nonetheless.

When assessing their cyber risk, cybersecurity professionals must first focus on identifying the most valued information assets, those that could cause the most damage if compromised, and then apply the risk equation. 

They should look at the threats to their most valued assets, identify associated vulnerabilities, determine the probability of those two meeting, the impact the compromise would have, and apply their cyber-security resources accordingly. 

They should ask themselves:

  • Am I thinking about probabilities and impacts in a structured way to prioritise my activities and resources or am I treating everything equally?
  • Am I thinking about threats, vulnerabilities and impacts in isolation or am I thinking about where they intersect to present a real risk to the business?     
  • Am I reporting business risks to the board together with recommendations that will increase or decrease that risk over time, or am I only presenting recommendations without the context of how they impact the business?

If they think like a true risk professional, speaking the language of risk comes easily. 

When reporting to the board, security professionals should:

  • Paint a picture that highlights the past, present and future state of the company’s cyber-risk, including lessons learned, goals and progress against those goals.
  • Focus on asset value and impact to the business if those assets were compromised.
  • Present the top risks impacting the business, with the top being the intersection between the most likely and the most impactful cyber risks to the company.
  • Show the trend of how these risks have increased/decreased through their organization's actions or lack thereof, ultimately based on the board’s guidance.
  • Show how they expect their proposed actions or lack thereof, will impact these trends.
  • Use specific data points about threats and vulnerabilities that are important supporting information to show the actions that affect the various cyber risks, but make sure these data points are supporting not leading.
  • Use a consistent format from month to month, with metrics that can be continually compared and trended over time for progress.

Security leaders that run around with their hair on fire in constant reactive mode are being left behind. Their goal should be to understand the company’s cyber risks and manage those risks in line with the board's direction and appetites.

To be successful at that, they need to be able to monitor, measure and report those risks, both in support of their operational plans as well as in support of communicating to their board so that they can provide informed guidance and resourcing.

Infosecurity-Magazine

You Might Also Read:

Strategies For A Cyber Security Culture (£):

Your Directors Don’t Understand Cyber Threats Endangering Business (£):

Board-level Cyber Literacy Is Low, Discomfort High:

 

« North Korea More Likely To Launch A Cyber Attack Than A Military Strike
AI Might Be The Ultimate Answer To Cyber Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Nordic IT Security

Nordic IT Security

Nordic IT Security is a cyber security business forum in Scandinavia bringing together the converging worlds of IT, Cyber and Information Security.

Mocana

Mocana

Mocana provides a software platform that allows you to develop, test and distribute more secure IoT devices and services.

Chubb

Chubb

Chubb is the world’s largest publicly traded property and casualty insurer. Commercial services include Cyber Risk insurance.

KnowBe4

KnowBe4

KnowBe4 is an integrated platform for security awareness training combined with simulated phishing attacks.

IMS Networks

IMS Networks

IMS Networks specializes in the design and management of high criticality networks and telecoms services including network security and Managed Security Services.

CyberGhost

CyberGhost

CyberGhost is a Virtual Private Network services provider offering secure encrypted access to the internet.

Apozy

Apozy

Apozy replaces a secure web gateway to nullify phishing, malware and impersonation attacks.

Charities Security Forum (CSF)

Charities Security Forum (CSF)

The Charities Security Forum is the premier membership group for information security people working for charities and not-for-profits in the UK.

Adyta

Adyta

Adyta specializes in cybersecurity solutions adapted to the needs of sovereign institutions, business groups and other organizations that handle information and sensitive or classified data.

Cognyte

Cognyte

Cognyte are a market leader in security analytics software that empowers governments and enterprises with Actionable Intelligence for a safer world.

eCentre@LindenPointe

eCentre@LindenPointe

The eCenter@LindenPointe provides assistance to the development, management and promotion of STEM (Science, Technology, Engineering, Mathematics) related business ventures.

RankedRight

RankedRight

RankedRight empowers security teams to take immediate action on their most critical risks.

CSIOS Corp.

CSIOS Corp.

At CSIOS we help our customers achieve and sustain information and cyberspace superiority through a full range of defensive and offensive cyberspace operations and cybersecurity consulting services.

AirDroid Business

AirDroid Business

AirDroid Business is an efficient mobile device management solution for Android devices, helping businesses to remotely control and access devices in large quantities using a centralized approach.

RAND Corporation

RAND Corporation

The RAND Corporation is a non-profit institution that helps improve policy and decision making through research and analysis.

DeviQA

DeviQA

DeviQA provide best-in-class quality assurance services to companies of all sizes.