Cybersecurity Is A Competition Issue For Business

20141125152439-competitors-should-collaborate-more-cyber-security.jpeg

The current environment around cybercrime is quickly becoming a forcing function that’s causing businesses to begin evaluating how they’re doing cybersecurity across the board. 

Most importantly of all, it’s forcing companies to start thinking about how to measure and prepare for the real, business impacts of cyber threats lest they be held legally accountable by, say, the fine folks at the FTC. Or any number of voracious civil suit-seeking lawyers closely monitoring their failings and foibles.
But words and phrases like “begin evaluating” and “start thinking about” don’t equate to decision-making or “doing” anything real about it at all. 

In fact, despite a cyber and business “pop culture” zeitgeist brimming with signs and indicators that people really are starting to notice cyber insecurity an alarming number of companies put some very considerable roadblocks in front of themselves for not getting started on the same sorts of “competitive intelligence” programs for cyber that have become widely used and benefited from across industry.  
 
Some of my favorite excuses that I’ve heard from companies who want to avoid engaging in cyber intelligence functions?
• We’re not ready; we’re just not mature enough to make use of it.
• What would I do with this information anyway?
• How can I justify the expense and time if I can’t measure the benefits?
• I don’t have the right people and processes to handle it.
Absurd as this sounds, could you imagine a company being told one of their products presents a choking hazard saying, “Meh, we’re not mature enough to make use of this information.” Shockingly, this is pretty much exactly what’s happening when it comes to equally risky cyber threat information.
But it seems most just don’t see that cyber intelligence needs to become a prioritized, resourced part of what they’re already doing.
Now, in fairness, most of these excuses are actually quite real and tangible for the companies making use of them. In other words, most companies are, in what has become a stark reality, very immature when it comes to cyber defense.
Companies really don’t have the cyber expertise on hand in the right numbers. They don’t have well-developed processes in place internally (and externally to partners and customers) to deal well with even known threats, nor or the right tools on hand or a budget commensurate with the problem. Most companies don’t even know how big their cyber problem is, much less what to do with information about any one threat or the other.
But let’s apply this same set of excuses to, say, product development.
Would a company that wants to be successful in their marketplace not try to establish - and very quickly - all the necessary means to gather and use intelligence on what the customer wants, what their competitors are up to, how their products compare, what they’re doing better or worse, etc.?
Not a chance.
And that’s what is so confusing - and telling - about the reaction businesses have to even getting started gathering this sort of information about their cybercrime competition:
What these excuses say about most organizations is that most simply don’t have a real corporate strategy for cyber defense complete with focused objectives for how they want to defend themselves across the board from exploit.
And most are in fact lethargic, lazy and reluctant when it comes to doing anything about it.
In other words, unlike with products or sales, companies are not devoting time, energy, focus and a long-term commitment to what they want to be and achieve with their cybersecurity. There’s no plan, no blueprint developed for and bought into (and nurtured) by corporate leadership from the lowest rungs of cybersecurity management and all the way up to the board of directors.
In short, there’s just no cyber business plan - and few who care enough to develop it.
Cyber Security Strategy is Becoming Corporate Strategy
When a company develops its products or services for market, it develops an overall plan - a shared strategy that everyone in the organization can see and support by virtue of their part to play in it.
Whether you’re in product development, R&D, finance, marketing or sales, you depend on a cohesive, clear and cared-for map of where you’re going.
In all cases, these plans are highly dependent on data. Research is performed and insights are shared in a collaborative way as key players work together from all parts of an organization to develop ideas into marketable things.
Over time, the process by which companies stay competitive by evolving, pivoting and fixing is rooted in this continual and disciplined data collection and analysis. It forms the basis for refining raw ideas into initial offerings, then supports the perfection of those ideas through a product or service lifecycle.
Most importantly, a clear plan not only provides a unique vision of where you’re going, it governs day-to-day operations. Without it, resiliency and continuity of operations isn’t possible.
As well, it helps companies and their individual organizations avoid:
• Getting complacent across the board
• Becoming disorganized, inefficient and stovepiped 
• Being surprised by disruptions in the market 
• Wasting precious talent and expertise 
• Failing to deliver on continuous improvement, evolution
• Failing to satisfy customers
• Losing money to waste, fraud, abuse and litigation
• Conducting risk management and mitigation 
All of these things lead to a quickly tarnished brand. Like a shark, a business must keep moving and eating or die. And data and analysis is the energy that propels this motion.

Right now, too many businesses across the globe are operating without a proper cyber intelligence function that makes it possible to develop this data-driven plan in the first place.

Without it, they have nothing that tells them, quite simply, what their specific cyber risks are based on who they are as a company, including their:
• Customers and suppliers 
• Technologies used
• Internal business organizations
• Products manufactured and sold
• Data stored
• Overall brand and reputation
Under these circumstances, a clear plan and shared strategy is impossible.
Sadly, even with more coverage of breaches, more executives losing their jobs, more companies taking major brand hits… many companies are still putting cybersecurity squarely as a problem for the geeks. The engineers. The people (like me) who are awkward to be alone with in an elevator. As such, cyber is their problem. A technical problem that’s far too “in the weeds” for management to care about.

They get their hour in the quarterly staff meeting, you get some slides and spreadsheets and request for more money.
Until cybersecurity is seen and treated just like any other critical business problem with the same needs for intelligence gathering, tools and analysis to support decision-making, companies will continue to lose. Lose in bottom line revenue, lose customers and lose lots of cash to legal expenses in tough litigation that could also cost them brand and reputation. 
“Cyber intelligence” is “competitive intelligence” by any other name. Kinda the same way “cyber attack” or “data breach” has become just another alias for “legal fees.” 
Security Week:http://http://bit.ly/1VZRf4V

 

« Tor Gets Help to Anonymise Users of 'dark web'
A New Design for Cryptography’s Black Box »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Alarum Technologies

Alarum Technologies

Alarum Technologies (formerly Safe-T) is a global provider of cyber security and privacy solutions to consumers and enterprises.

HID Global

HID Global

HID Global is a trusted leader in products, services and solutions related to the creation, management, and use of secure identities.

Precise Biometrics

Precise Biometrics

Precise Biometrics develop and sell fingerprint software for convenient and secure authentication of people’s identity in mobile devices, smart cards and other products with fingerprint sensors.

Kryptus

Kryptus

Kryptus provides a wide array of solutions for hardware, firmware and software ranging from semiconductors to complex digital certificate management systems.

CSO GmbH

CSO GmbH

CSO GmbH provide specialist consultancy services in the area of IT security.

Cytellix

Cytellix

Cytellix is an industry-standards-based, managed cybersecurity service provider, specializing in proactive behavioral analytics and situational awareness of an organization’s cyber posture.

Keyavi Data

Keyavi Data

With Keyavi’s evolutionary data protection technology, your data stays within the bounds of your control in perpetuity.

SHe CISO Exec

SHe CISO Exec

SHe CISO Exec is a sustainable global training and mentoring platform in information security and leadership.

R-Tech

R-Tech

R-Tech GmbH manages the digital start-up initiative, whose goal is to build a sustainable start-up culture in the field of digitization throughout the Upper Palatinate district of Bavaria.

UK Cyber Cluster Collaboration (UKC3)

UK Cyber Cluster Collaboration (UKC3)

UKC3 has been launched to support Cyber Clusters and encourage greater collaboration across regions and nations of the UK.

Cyberplc

Cyberplc

Cyberplc is a global cybersecurity consulting firm providing services to government, the public sector and enterprises.

Arista Middle East

Arista Middle East

Arista Middle East is part of Global Arista Technologies specializing in OT Cybersecurity.

Munio

Munio

Munio is a leading Fortified IT Support and Cyber Security companies in the south east of the UK.

BuddoBot

BuddoBot

BuddoBot has been a pioneering force in cybersecurity and information technology since 2008.

Cyberlocke

Cyberlocke

Cyberlocke is dedicated to finding inventive solutions to meet the distinct IT obstacles of each organization we support.

Quantum Squint

Quantum Squint

Quantum Squint is a cutting-edge cybersecurity company specializing in the use of advanced regression management techniques to detect, analyze, and prevent vulnerabilities in digital systems.