Generating Competitive Advantage Through Compliance

All too often security compliance is regarded as a series of hurdles the business needs to jump through in order to achieve accreditation. It can tend to be regarded as red tape and a barrier to getting things done.

But changing the mindset of the executive body so that regulations are regarded as helping rather than hindering ambitions can pave the way for the business to become more efficient and more competitive in the marketplace.

From a security perspective, cyber risk is the predominant factor in the decision-making process and this seems to contradict the primary objectives of the board, which are to save money, save it faster, make money, make it faster and manage risks that threaten those objectives.

Yet the two need not be conflicting if controls are applied in such a way that they allow the business to achieve those goals, rather than acting as an impediment. 

A good analogy here is Formula 1 racing. Racing driver, Mario Andretti, famously said: “It’s amazing how many drivers, even at the Formula 1 level, think that the brakes are for slowing the car down”. In actual fact, those brakes are there to provide the driver with the control to enter and exit a corner and in so doing, optimise the performance of the car and the time taken to complete the circuit. Similarly, compliance can enable processes and procedures to be better understood. 

Streamlined By Compliance

For example, there may well be changes or improvements that the business wants to make to software or systems to boost its competitiveness and it’s at this point risk and compliance can become an obstacle. However, if the business puts compliance first and implements the necessary processes, expectations can be met quicker. By putting processes X, Y and Z through the risk management lens, it becomes possible to see what elements are or are not applicable and what could confer competitive advantage versus what could constitute a block.

Let’s use the hypothetical example of a US company selling software to a non-aligned market such as Russia or China. That team would face export controls on its software. By identifying where those barriers to export are at the earliest stages in the process, the business can get the product into production more quickly without the need to retroactively engineer further down the line which would cause delays. The process is effectively streamlined in accordance with compliance requirements.

To get to this position, the board needs to actively engage with its responsibilities from a regulatory compliance perspective. Of course, compliance with cyber security regulations and standards is not optional – it is a legal requirement that protects the company from fines and reputational damage – but complying with regulations versus utilising them are two very different things.

To establish where the business is in terms of its compliance maturity, it’s necessary to ask some searching questions.

Questions To Consider

First and foremost, what role does the board play in overseeing the company’s cyber risk management and compliance strategy? Is it purely passive or does it seek to lead? Does the board seek to stay informed about the latest cyber threats and trends or is it simply reactive? How does the board evaluate the effectiveness of the company’s cyber risk and compliance management, and applied security measures? What measures are in place to ensure that the company complies with relevant cyber security regulations and standards? And how would the board describe the company’s approach to ensuring that there is an appropriate incident response capability?

The answer to these questions should ideally see the board taking an active role in the security management of the company.

Effective leadership in this regard will help the business stay abreast of relevant regulations and standards and ensure that compliance efforts are thorough and proactive. This is vital because the regulatory landscape for cyber security is complex and ever-changing, so the board needs to be aware of its legal and regulatory requirements on an ongoing basis.

Compliance with Digital Operational Resilience Act (DORA) provides a good example as its relatively recent. Being able to demonstrate compliance with the standard is one thing but being able to articulate that in terms of the controls and risk management processes that are in place can be a strong business enabler. From a marketing point of view, compliance with DORA marks the business out, signifying it has met stringent demands. This then allows the business to win new customers or renegotiate contracts from a stronger position, thereby bolstering its competitiveness. 

Personal Accountability

The general direction of travel with respect to regulations is that the board is increasingly being held accountable. Revisions to disclosure requirements such as the Securities and Exchange Commission Form 8K, NIS2 on the continent and possibly the Cyber Security and Resilience Bill here in the UK, all require senior management to be able to demonstrate oversight of risk management. A failure to do so could result in those individuals being held personally responsible, making it even more pressing this issue is addressed.

The reality is that the board must now get to grips with compliance and should regard it as another critical aspect under its remit.

But this needn’t equate to an increase in workload. Senior executives at board level seldom hold cybersecurity experience so it makes sense to put in place a risk management and compliance board to keep them informed. The committee should include members with diverse expertise in finance, operations, legal, compliance, and strategic planning and should seek to evaluate, mitigate, and monitor various risks, reporting back to and informing the board. In addition to providing compliance oversight, such a committee can also identify risk, review policy, evaluate internal controls and ensure reporting mechanisms are effective.

Aided by these personnel, the board can then begin to use compliance as an enabler that that informs the decision-making process and strategically allows the business to position itself to capitalise upon market opportunities.

James Eason is GRC CRA Practice Lead at Integrity360

Image: Ideogram

You Might Also Read: 

Six Steps On The Road To NIS2 Compliance:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Safeguarding Your Business: 10 Best Practices For Mobile Device Safety
Social Media Algorithms & Their Effects »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Quotium

Quotium

Quotium provides automated testing technologies to make business software applications secure and robust.

QA Systems

QA Systems

QA Systems provides software testing solutions for safety and business critical sectors and software safety and security standards.

Exostar

Exostar

Exostar is the cloud platform of choice for secure enterprise and supply chain collaboration solutions and identity and access management expertise.

Vdoo

Vdoo

Vdoo provides an end-to-end product security platform for automating all software security tasks throughout the entire product lifecycle.

Altaro Software

Altaro Software

Altaro provide backup solutions that are intuitive, easy to use, well-priced and backed by outstanding 24/7 support as part of the package.

Red Snapper Recruitment

Red Snapper Recruitment

Red Snapper Recruitment is a market leading staffing services provider to the law enforcement, cyber security, offender supervision and regulatory services markets.

Absolute IT Asset Disposals

Absolute IT Asset Disposals

Absolute IT Asset Disposals is an IT asset disposal (ITAD) company providing safe and secure recycling of IT assets.

ArmorText

ArmorText

ArmorText offers a seamless channel for communication and collaboration for organizations concerned with keeping communication data private and secure.

CYDES

CYDES

CYDES is the first event in Malaysia to showcase advanced solutions and technologies to address cyber defence and cyber security challenges for the public and private sectors.

American Technology Services (ATS)

American Technology Services (ATS)

American Technology Services provides unparalleled services in information technology to support small and mid-sized business. From top-level strategy, to managed services and infrastructure support.

SolidityScan

SolidityScan

SolidityScan is an advanced smart contract scanning tool designed to uncover vulnerabilities and proactively address risks within your code.

Insane Cyber

Insane Cyber

Insane Cyber make cybersecurity easier to manage through automated, easy-to-use software and expert support and partnership.

CyberGrape

CyberGrape

CyberGrape is a client centric managed services company, providing enterprise leading security solutions and helping companies through their IT risk and security challenges.

Potech

Potech

Potech provides masterful services in Information & Technology and Cybersecurity to multiple markets across the world.

Styx Intelligence

Styx Intelligence

Styx Intelligence’s platform provides visibility and supports remediation against threats targeting your digital assets.

TrnDigital

TrnDigital

Protect your business with Microsoft security as a service. TRN Digital is a trusted Microsoft managed security service provider in the USA.