thecybersecurityreview

CYBERSECURITY REVIEW 9 JUNE - JULY 2024EFFECTIVE COMMUNICATIONS BETWEEN CISOS AND KEY STAKEHOLDERSstakeholders is when operational metrics become a focus rather than those that measure and reflect key risks. A frequent error by security leaders is presenting metrics tied to events, such as the number of attacks against the company's web properties or the number of malicious emails received. Without context of the organization's capabilities to detect and protect against these threats, audiences can't understand the significance of such operational metrics.Risk discussions should include the context of how the CISO measures and communicates risk through risk appetite statements, connection to the enterprise risk management taxonomy, and measurement against defined risk thresholds. An area of increased focus is how to best move from a traditional qualitative approach toward risk measurement to a quantitative risk-based measurement of cyber risk. Directors and executives should clearly understand an organization's cyber risk and loss exposure in financial terms to enable effective decision-making which balances protecting the organization and running the business. Inherent risk--the risk that exists in the absence of any controls or countermeasures--is an important baseline for stakeholders to understand. This highlight risks that require the greatest focus or which could have the greatest impact on the organization in the event of control failures. The inherent risk of a threat type can vary, and the organization should have a structured approach toward understanding both the impact and the likelihood of given risks. Regulatory and compliance requirements, the volume and type of confidential data the organization holds, the potential reputational impact of cyber events, and the level of security training and workforce awareness, are the considerations in identifying inherent risk.An effective CISO can clearly outline how the security program lowers the organization's risk through effective controls and other risk mitigation strategies, such as training and secure development practices. The ability of the security program to drive down risk and maintain alignment with the enterprise's risk appetite represents a view of the "return on investment" of the cyber security program.How the effectiveness of cyber security controls and countermeasures are assessed is an important topic for the CISO to convey. Organizations should implement an approach that measures and monitors security control effectiveness, maintains awareness of how they impact residual risk, highlights gaps or changes, and ensures technology changes do not have unintended consequences for security controls.The discussion of the organization's cyber security program is incomplete without considering the people. The ability to attract, develop, and retain cyber security talent is a critical issue, and CISOs should describe their approach and plan, and provide regular updates on their status. Business and technology strategies directly impact the organization's cyber risk posture. Security is an overarching risk function that must be involved in business strategy as well as technology strategy, and security leaders should regularly engage with business stakeholder leadership, recognizing that they are drivers of technology change and are incurring cyber risk. Companies have seen their technology ecosystems become far more complex and extend well beyond their traditional network borders. Successful cyber-attacks against SolarWinds and Kaseya illustrate the cyber risk associated with enterprise technology supply chains. Threat actors attacked enterprise software and service providers to create the platform used to exploit critical business networks. Such supply chain events, and the cascading cyber risk associated with them, represent a significant challenge to traditional approaches toward assessing third-party risk.Just as lines of business and technology have strategies and associated initiatives, so must the cyber security function. CISOs should review with the Board and executive leadership their ongoing improvement plans ­ their roadmap ­ for the security function. Progress toward the target state of the cyber security program, alignment with the organization's risk appetite, and consideration of the company's program relative to industry peers should all be considerations discussed between board and executive stakeholders and CISO.Focusing on risk and quantifying it in business and financial terms, educating stakeholders on the risk and threat landscape, clearly describng the link between risk mitigation and reduction and planned investments, and staying aligned with the business units will all serve to bridge the communication gap and gain critical support for your program. The ability of the security program to drive down risk and maintain alignment with the enterprise's risk appetite represents a view of the "return on investment" of the cybersecurity program
< Page 8 | Page 10 >