Cybersecurity Is A Competition Issue For Business

20141125152439-competitors-should-collaborate-more-cyber-security.jpeg

The current environment around cybercrime is quickly becoming a forcing function that’s causing businesses to begin evaluating how they’re doing cybersecurity across the board. 

Most importantly of all, it’s forcing companies to start thinking about how to measure and prepare for the real, business impacts of cyber threats lest they be held legally accountable by, say, the fine folks at the FTC. Or any number of voracious civil suit-seeking lawyers closely monitoring their failings and foibles.
But words and phrases like “begin evaluating” and “start thinking about” don’t equate to decision-making or “doing” anything real about it at all. 

In fact, despite a cyber and business “pop culture” zeitgeist brimming with signs and indicators that people really are starting to notice cyber insecurity an alarming number of companies put some very considerable roadblocks in front of themselves for not getting started on the same sorts of “competitive intelligence” programs for cyber that have become widely used and benefited from across industry.  
 
Some of my favorite excuses that I’ve heard from companies who want to avoid engaging in cyber intelligence functions?
• We’re not ready; we’re just not mature enough to make use of it.
• What would I do with this information anyway?
• How can I justify the expense and time if I can’t measure the benefits?
• I don’t have the right people and processes to handle it.
Absurd as this sounds, could you imagine a company being told one of their products presents a choking hazard saying, “Meh, we’re not mature enough to make use of this information.” Shockingly, this is pretty much exactly what’s happening when it comes to equally risky cyber threat information.
But it seems most just don’t see that cyber intelligence needs to become a prioritized, resourced part of what they’re already doing.
Now, in fairness, most of these excuses are actually quite real and tangible for the companies making use of them. In other words, most companies are, in what has become a stark reality, very immature when it comes to cyber defense.
Companies really don’t have the cyber expertise on hand in the right numbers. They don’t have well-developed processes in place internally (and externally to partners and customers) to deal well with even known threats, nor or the right tools on hand or a budget commensurate with the problem. Most companies don’t even know how big their cyber problem is, much less what to do with information about any one threat or the other.
But let’s apply this same set of excuses to, say, product development.
Would a company that wants to be successful in their marketplace not try to establish - and very quickly - all the necessary means to gather and use intelligence on what the customer wants, what their competitors are up to, how their products compare, what they’re doing better or worse, etc.?
Not a chance.
And that’s what is so confusing - and telling - about the reaction businesses have to even getting started gathering this sort of information about their cybercrime competition:
What these excuses say about most organizations is that most simply don’t have a real corporate strategy for cyber defense complete with focused objectives for how they want to defend themselves across the board from exploit.
And most are in fact lethargic, lazy and reluctant when it comes to doing anything about it.
In other words, unlike with products or sales, companies are not devoting time, energy, focus and a long-term commitment to what they want to be and achieve with their cybersecurity. There’s no plan, no blueprint developed for and bought into (and nurtured) by corporate leadership from the lowest rungs of cybersecurity management and all the way up to the board of directors.
In short, there’s just no cyber business plan - and few who care enough to develop it.
Cyber Security Strategy is Becoming Corporate Strategy
When a company develops its products or services for market, it develops an overall plan - a shared strategy that everyone in the organization can see and support by virtue of their part to play in it.
Whether you’re in product development, R&D, finance, marketing or sales, you depend on a cohesive, clear and cared-for map of where you’re going.
In all cases, these plans are highly dependent on data. Research is performed and insights are shared in a collaborative way as key players work together from all parts of an organization to develop ideas into marketable things.
Over time, the process by which companies stay competitive by evolving, pivoting and fixing is rooted in this continual and disciplined data collection and analysis. It forms the basis for refining raw ideas into initial offerings, then supports the perfection of those ideas through a product or service lifecycle.
Most importantly, a clear plan not only provides a unique vision of where you’re going, it governs day-to-day operations. Without it, resiliency and continuity of operations isn’t possible.
As well, it helps companies and their individual organizations avoid:
• Getting complacent across the board
• Becoming disorganized, inefficient and stovepiped 
• Being surprised by disruptions in the market 
• Wasting precious talent and expertise 
• Failing to deliver on continuous improvement, evolution
• Failing to satisfy customers
• Losing money to waste, fraud, abuse and litigation
• Conducting risk management and mitigation 
All of these things lead to a quickly tarnished brand. Like a shark, a business must keep moving and eating or die. And data and analysis is the energy that propels this motion.

Right now, too many businesses across the globe are operating without a proper cyber intelligence function that makes it possible to develop this data-driven plan in the first place.

Without it, they have nothing that tells them, quite simply, what their specific cyber risks are based on who they are as a company, including their:
• Customers and suppliers 
• Technologies used
• Internal business organizations
• Products manufactured and sold
• Data stored
• Overall brand and reputation
Under these circumstances, a clear plan and shared strategy is impossible.
Sadly, even with more coverage of breaches, more executives losing their jobs, more companies taking major brand hits… many companies are still putting cybersecurity squarely as a problem for the geeks. The engineers. The people (like me) who are awkward to be alone with in an elevator. As such, cyber is their problem. A technical problem that’s far too “in the weeds” for management to care about.

They get their hour in the quarterly staff meeting, you get some slides and spreadsheets and request for more money.
Until cybersecurity is seen and treated just like any other critical business problem with the same needs for intelligence gathering, tools and analysis to support decision-making, companies will continue to lose. Lose in bottom line revenue, lose customers and lose lots of cash to legal expenses in tough litigation that could also cost them brand and reputation. 
“Cyber intelligence” is “competitive intelligence” by any other name. Kinda the same way “cyber attack” or “data breach” has become just another alias for “legal fees.” 
Security Week:http://http://bit.ly/1VZRf4V

 

« Tor Gets Help to Anonymise Users of 'dark web'
A New Design for Cryptography’s Black Box »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Virtual Security

Virtual Security

Virtual Security provides solutions in the field of managed security services, network security, secure remote work, responsible internet, application security, encryption, BYOD and compliance.

RSA Insurance Group

RSA Insurance Group

RSA is one of the world’s leading multinational quoted insurance groups. Commercial services include cyber risk insurance.

Government Communications Headquarters (GCHQ)

Government Communications Headquarters (GCHQ)

GCHQ defends Government systems from cyber threat, provide support to the Armed Forces and strive to keep the public safe, in real life and online.

File Centre

File Centre

File Centre is a leading specialist when it comes to data backup, we offer our clients a premium backup retrieval and delivery solution.

Terranova Security

Terranova Security

Terranova is dedicated to providing information security awareness programs customized to your internal policies and procedures.

Quorum Cyber

Quorum Cyber

Quorum Cyber offer end-to-end cyber security solutions, specialising in Managed Security Services, Consulting and Resourcing.

ERMProtect

ERMProtect

ERMProtect is a leading Information Security & Training Company that helps businesses improve their cybersecurity posture and comply with regulations.

CertiPath

CertiPath

CertiPath create products and services that ensure the highest levels of validation for digital identities that attempt to access customers’ networks.

Tromzo

Tromzo

Tromzo's mission is to eliminate the friction between developers and security so you can scale your application security program.

ProCheckUp

ProCheckUp

ProCheckUp is a London-based independent provider of cyber security services, including IT Security, Assurance, Compliance and Incident Response.

Legit Security

Legit Security

Legit Security's mission is to secure every organization's software factory by protecting the pipelines, infrastructure, code and people for faster and more secure software releases.

Cisilion

Cisilion

Cisilion's mission is simple – to transform and connect business with next-generation IT infrastructure. Our expertise includes enterprise networking, security, data centre & cloud, managed services.

Cyber Explorers

Cyber Explorers

Cyber Explorers is a fun, free and interactive learning platform for future digital superstars. An exciting addition to UK curriculum delivery or after school activities.

ZEST Security

ZEST Security

The ZEST platform natively integrates into your technology stack to make efficient risk remediation possible.

Dial A Geek

Dial A Geek

Dial A Geek are a Bristol-based B Corp that provides Managed IT Services to companies of 20+ users. We help businesses with a smart use of tech, including compliance and cybersecurity solutions.

RANE Network

RANE Network

RANE is a global risk intelligence company that provides critical insights and analysis to more efficiently anticipate, monitor, and respond to emerging threats.