Four Steps To Managing Cyber Security Better

Around the world 2016 was a somewhat successful year for attackers and consequently a challenging year for defenders.

Organisations around the world are now more aware of the risks and know they must take deliberate steps to address the threats. But how?

While high-profile breaches are not new news, the growing list of victims including Yahoo, Wendy's, the University of Central Florida and the Bangladesh Bank illustrate the continuing threat of cyber-attacks, 2016 demonstrated that the threats are ongoing and can target every type of organisation in every industry. No sector or group is immune.

Here are four approaches that companies can embark on immediately to more effectively mitigate risks and respond to the threats that they face:

1.    Double down on the basics.

Many organisations insufficiently invest in and execute on the fundamentals or “the basics” of cyber-security, identifying the assets that they need to protect and ensuring that the most recent patches and updates have been applied shortly after vulnerabilities are announced.

Each organisation needs to answer some basic questions: What is our strategy? Who owns the responsibility? What is their specific process and plan? Without a clear framework, dedicated resources and accountability, problems are inevitable.

In 2017, every organisation should commit to a strategy and adopt a cybersecurity framework to help them more effectively understand their current level of maturity and what the desired state should be. 

A framework should help an organisation identify key assets, how those assets are going to be protected and monitored, and how they would respond and recover should a breach occur. The NIST Cybersecurity Framework (CSF) is one option that is gaining momentum and adoption, as it is designed to be within reach of any organisation regardless of their current level of cyber-security maturity.

2.    Watch and secure the supply chain.

One of the fastest growing trends in recent breaches is for attackers to gain access to their victim’s sensitive data through unsuspecting third parties. 

For example, the intrusion into the US Office of Personnel Management in 2015 that resulted in the compromise of personal information on approximately 21.5 million people began in the network of a third-party OPM contractor.

While companies need to build and execute on their own internal security programs, they cannot neglect the “extended enterprise” composed of all of the of third parties, law firms, payroll agencies, marketing firms, etc. with whom they share sensitive data or privileged relationships that can be exploited.

The growth of outsourcing and online services has blurred or completely dissolved the boundary of the traditional network. The day has arrived where it is no longer sufficient for organisations to protect themselves. They also have to actively monitor and manage the security risks of those with whom they do business.

It is important to keep in mind that the management of third party risk is increasingly becoming part of new regulations and it is certainly necessary to check with your government information concerning the cyber regulations and requirements. 

3.    Invest in employee training.

It is almost a cliché now that when a breach is announced, the company states that the attack originated from an inbound malicious email or phishing attempt. An employee opened an email from an attacker and either downloaded a malicious attachment or was tricked into revealing sensitive system passwords.

For example, Snapchat revealed in February “with real remorse and embarrassment” that attackers obtained confidential data about 700 current and former employees by tricking an employee into opening an email that impersonated the CEO and clicking on a link that installed malware.

It has been widely reported that John Podesta, Clinton campaign chief, fell victim to a phishing scheme, a fake “account reset” email purporting to be from Google.

Technical controls should be put in place to neutralise some of these attacks (such as multi-factor authentication against password theft); however, technical controls are not sufficient. 

Organisations need to educate employees on the risks and how to respond. Humans make mistakes and will click on links and fall victim to attacks. A combination of technical controls and trained employees may be able to more rapidly identify issues and respond in order to limit the damage.

Employees should learn about potential threats and how to report suspicious activity within the company. Additionally, organisations need to make sure they have a detection and recovery plan in place for when, despite the training, the mistakes happen.

4.    Track metrics and work as a team.

Effectively mitigating against cyber risks requires a collective effort. The responsibility cannot simply fall on a single individual or group.

Having established a framework, organisations should set and track benchmarks to help them assess the effectiveness of their own efforts as well as of their critical third parties. Corporate risk and information security teams should be actively involved in developing and tracking performance metrics.

Cyber-security also should be a high-priority matter at the board level. Senior leaders should actively engage the board in discussing the strategy, the initiatives and the company’s progress and performance over time against its objectives. Performance and key benchmarks should be a regular item on board meeting agendas.

Given the risks and its fiduciary responsibility, the board must understand the need for and then support the development and maintenance of a robust cybersecurity program.

Boards cannot abdicate this responsibility or simply assume that senior management is taking care of everything. History has taught us that the reputational damage and financial impact associated with failing to execute is high.

The threats will continue unabated in 2017 and defenders will continue to be challenged. Organisations will be much better positioned by taking these steps in the year ahead.

Information Management

Directors Report January 2017. Cyber Security Checklist For Management (£):

Are Employees Your Weakest Link When It Comes To Security?:

Board-level Cyber Literacy Is Low, Discomfort High:

Cybersecurity Breaches Cost UK Businesses Close To £30bn Last Year:

 

 

« Geolocation, Russian Hackers & False Flag Operations
Google Lawsuit Could Be Fatal For Uber »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

International School of IT Security (ISITS)

International School of IT Security (ISITS)

The International School of IT Security (ISITS) is a leading provider of professional training in the field of IT Security.

Gilbert + Tobin

Gilbert + Tobin

Gilbert + Tobin is an Australian corporate law firm serving clients throughout Australia, and around the world, on a broad range of legal issues including cyber security.

CyberArts

CyberArts

CyberArts is founded on the belief that every single organization deserves and requires the creme de la creme when there is a need for Cyber services.

Salviol Global Analytics

Salviol Global Analytics

Salviol Global Analytics is a leading provider of Fraud, Risk and Operational Performance Solutions to a number of vertical markets including Insurance, Banking, Utilities, Telco’s and Government.

HUB Security

HUB Security

Hub Security provide Ultra Secure, Military Grade HSM (Hardware Security Module) Solutions for Blockchain and Digital Assets.

CSC Digital Brand Services

CSC Digital Brand Services

Our brand protection and security expertise give our customers peace of mind that no matter how fast the digital world changes, their intellectual property and digital assets will be secure.

WhiteHawk

WhiteHawk

WhiteHawk is the first online Cyber Security Exchange. We help you understand your cyber risk and match you to tailored and affordable solutions.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

GajShield

GajShield

GajShield Infotech provides Data Security Firewall solutions to Corporate’s and Government agencies.

Factmata

Factmata

Factmata is an social and news media monitoring and analytics product that uses AI to identify and track narratives online, highlighting those most likely to cause brand harm or misinform the public.

Eleos Labs

Eleos Labs

Eleos Labs' suite of security tools prevent Web3 cyber attacks, reduce economic risks, and protect digital assets.

Var Group

Var Group

Var Group is one of the main partners for innovation in the ICT sector in Italy.

Sayers

Sayers

Sayers is best known for its ability to solve business challenges with IT solutions. Our areas of expertise include cloud, storage, virtualization, security, mobility and networking.

ZeroGPT

ZeroGPT

ZeroGPT.com stands at the forefront of AI detection tools, specializing in the precise identification of ChatGPT-generated text.

National Centre for Digital Security (CNSD) - Peru

National Centre for Digital Security (CNSD) - Peru

The National Center for Digital Security manages and supervises the operation of Digital Security in Peru in order to strengthen digital trust.

Nordic Defender

Nordic Defender

Nordic Defender is the first crowd-powered modern cybersecurity solution provider in the Nordic region.