Everyone, from the small business owner, to senior enterprise executives are confronting a seemingly insurmountable problem: Fixed and rising cyber security breaches. It appears it doesn’t matter what we do, there is always someone that was hacked, a new vulnerability exploited, and tens of millions of dollars lost.
In an effort to stem the tide folks have tried everything: From throwing money at it by shopping for the latest and greatest tech gizmos promising security, to outsourcing cyber security administration, to handing it over to the IT folks to deal with it. And, each time the result’s money lost, productivity decreased, and the attacks continue.
Many business people complain that we’re not just dropping a battle right here and there. We’re dropping the war. Is that true? The reality is that those that keep dropping their cyber battles and risk losing the war are making three critical mistakes:
1. They think cyber security is a technology problem.
2. They follow a cyber security check list as soon as-and-done.
3. They don’t have a cyber security awareness training program in place.
First, cyber security will not be a technology problem. Far from it. It is a business-critical problem, and more importantly: It’s a individuals problem, and we need to address it at that level.
Second, cyber security is a consistently evolving battlefield. The threats evolve, the attacks take new paths, the undermendacity technologies change. A static check list solves yesterday’s problems, not right this moment’s, and certainly not tomorrow’s.
Finally, if folks don’t understand the threat they will not even see the attack coming, a lot less be able to reply and protect themselves. Cyber security awareness training is the only way to prepare everyone for the new reality we live and work in.
Remember: Cyber security is just not an IT problem. It is a risk administration problem, a stay-in-enterprise problem. This is easier to understand in you work in a regulated industry. There, the concept, language, even governance of risk management is part of the day by day lexicon.
Not so with small and mid-market enterprise less acquainted with the risk management function. It doesn’t help that the very nature of the menace and the way the “payload” of the attack is delivered is via info technologies. It nearly makes sense to have IT deal with cyber security. However the victims usually are not the computers. The victims are the businesses and their people.
More importantly: A company’s Information Technology generates Value. It does so a myriad different ways depending on the enterprise you’re in, from the precise delivery of products to clients (e.g. software businesses, data companies, media and technology companies etc.) to complementing, enhancing, and realizing the mission and vision of the corporate (law companies, manufacturing, logistics, healthcare, etc.)
Cyber security, like all risk administration, is there to protect value. Due to this fact, you may never have cyber security (the worth protector) report to IT (the value creator). That creates a conflict of interest. Just like IT reports directly to the CEO, so must cyber security. They are parallel tracks keeping the business train aligned and moving.
Once you have the reporting construction correctly in place, it is advisable empower it with executive purchase-in and engagement. Cyber security needs your direction on firm goals and risk appetite so they can develop the appropriate strategy to protect the corporate’s assets. Cyber security professionals, working with the board and executives, including IT and business units, will develop the correct protection-in-depth strategy that’s right for the company.
If you loved this write-up and you would like to obtain additional info regarding Information Security United Kingdom kindly go to our web-page.