Time To Speak The Language Of Risk

Cybersecurity is transitioning from being strictly a technical problem to becoming a risk-based issue. 

The transition is becoming top of mind among cybersecurity professionals, executives, board members, shareholders, analysts and other thought leaders.

According to a survey conducted by Osterman Research, cyber risks were ranked as a top priority for the majority of board members surveyed, alongside other risks such as financial, regulatory, and legal. More than half of board members say IT and security executives will lose their jobs because of failing to provide them with useful, actionable information.

Boards speak the language of risk and are holding security leaders accountable for doing the same, yet many security leaders are struggling to do so.

The Osterman report also reveals more than half (54%) of board members agree or strongly agree that the data presented is too technical.

While in writing, the concept seems straightforward, in actual execution, it can be difficult. The role of the cybersecurity professional was created based on technology-based needs. 

How many DDoS events were blocked? How many vulnerabilities do we need to patch today? Cybersecurity professionals lived and breathed technology; they worked in a silo and were known across the business as the “IT team in the corner office.”

Considering cybersecurity professionals came from this deeply rooted, technology-focused place, shifting to speaking risk is almost like learning a foreign language. So how can they make the transition as smooth and seamless a possible?

Cybersecurity professionals must first learn how to think risk, which begins with defining it. Risk is the potential of loss caused by some event - it is a consequence of the alignment of threats and vulnerabilities against an asset of value.

A threat without a vulnerability or a vulnerability without a threat does not present a risk. For example, an unlocked window is a security vulnerability; but if that window is on the 50th floor of a high rise, it is unlikely that a burglar would scale the building to break in (the threat), and therefore it does not present much of a risk.  

However, if you put the Hope Diamond in that room, the risk is elevated because the diamond’s high value may entice a thief to attempt a threat, albeit a low probability one, but a threat nonetheless.

When assessing their cyber risk, cybersecurity professionals must first focus on identifying the most valued information assets, those that could cause the most damage if compromised, and then apply the risk equation. 

They should look at the threats to their most valued assets, identify associated vulnerabilities, determine the probability of those two meeting, the impact the compromise would have, and apply their cyber-security resources accordingly. 

They should ask themselves:

  • Am I thinking about probabilities and impacts in a structured way to prioritise my activities and resources or am I treating everything equally?
  • Am I thinking about threats, vulnerabilities and impacts in isolation or am I thinking about where they intersect to present a real risk to the business?     
  • Am I reporting business risks to the board together with recommendations that will increase or decrease that risk over time, or am I only presenting recommendations without the context of how they impact the business?

If they think like a true risk professional, speaking the language of risk comes easily. 

When reporting to the board, security professionals should:

  • Paint a picture that highlights the past, present and future state of the company’s cyber-risk, including lessons learned, goals and progress against those goals.
  • Focus on asset value and impact to the business if those assets were compromised.
  • Present the top risks impacting the business, with the top being the intersection between the most likely and the most impactful cyber risks to the company.
  • Show the trend of how these risks have increased/decreased through their organization's actions or lack thereof, ultimately based on the board’s guidance.
  • Show how they expect their proposed actions or lack thereof, will impact these trends.
  • Use specific data points about threats and vulnerabilities that are important supporting information to show the actions that affect the various cyber risks, but make sure these data points are supporting not leading.
  • Use a consistent format from month to month, with metrics that can be continually compared and trended over time for progress.

Security leaders that run around with their hair on fire in constant reactive mode are being left behind. Their goal should be to understand the company’s cyber risks and manage those risks in line with the board's direction and appetites.

To be successful at that, they need to be able to monitor, measure and report those risks, both in support of their operational plans as well as in support of communicating to their board so that they can provide informed guidance and resourcing.

Infosecurity-Magazine

You Might Also Read:

Strategies For A Cyber Security Culture (£):

Your Directors Don’t Understand Cyber Threats Endangering Business (£):

Board-level Cyber Literacy Is Low, Discomfort High:

 

« North Korea More Likely To Launch A Cyber Attack Than A Military Strike
AI Might Be The Ultimate Answer To Cyber Threats »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

FT Cyber Resilience Summit: Europe

FT Cyber Resilience Summit: Europe

27 November 2024 | In-Person & Digital | 22 Bishopsgate, London. Business leaders, Innovators & Experts address evolving cybersecurity risks.

HackLabs

HackLabs

HackLabs is a penetration testing company providing services for network security, web application security and social engineering testing.

PhishLabs

PhishLabs

PhishLabs provides 24/7 services that help organizations protect against the cyberattacks targeting their employees, their customers and their brands.

Intensity Analytics

Intensity Analytics

Intensity Analytics is a software firm that develops next-generation, physical user and entity behavioral authentication ("physical UEBA") security software technology.

Secarma

Secarma

Secarma provides penetration testing, security assessments, consultancy, and training services to ensure your digital infrastructure is secure from cybersecurity threats.

Nullcon

Nullcon

Nullcon provides an integrated platform for exchanging information on the latest attack vectors, zero-day vulnerabilities and unknown threats.

CSIRT-CY

CSIRT-CY

CSIRT-CY is the National Computer Security Incident Response Team for Cyprus.

DataArt

DataArt

DataArt is a global technology consultancy that designs, develops and supports unique software solutions. Areas of activity include software security testing.

Pareteum

Pareteum

Pareteum is a leading Global provider of mobile networking software and services. Our mission is to provide a single solution to the problem of fully enabling and securing the Mobile Cloud.

Keyless Technologies

Keyless Technologies

Simple, secure, and interoperable authentication. Keyless offers unmatched security, privacy and usability, while reducing risk and infrastructure costs.

AnaVation

AnaVation

AnaVation is a trusted partner delivering high-value, cost-effective solutions that solve the most complex technical and analytical problems for our customers.

Theta432

Theta432

THETA432 is a cybersecurity firm that provides 24/7/365 managed prevention, detection, response, Hybrid SOC, cyber defense monitoring services with dynamically defined defense (3D™).

Matrixforce

Matrixforce

Matrixforce is a vetted IT support provider that uses the patented Delta Method of streamlining technology for financial and professional service firms to reduce complexity and avoid risk.

Cymune

Cymune

At Cymune we help businesses to fight against cybercrime, protect patented data and diminish security risks.

Threat Con

Threat Con

Threat Con is a one of its kind event in Nepal, a series of annual international security conventions similar to the famous Black Hat and DEF CON conferences.

Simbian

Simbian

Simbian, with its hardened TrustedLLM system, is the first to accelerate security by empowering every member of a security team from the C-Suite to frontline practitioners.

runZero

runZero

runZero delivers the most complete security visibility possible, providing you the ultimate foundation for successfully managing exposures and compliance.