Cyber defence is not just about technology
Taking an integrated view of people, processes and technologies can help a company turn information risk into a business advantage
TODAY'S increasingly complex state of cyber risk is prompting organisations to question if they are truly resilient against cyber attacks. When evaluating their cyber defence, most organisations focus on the technologies they have in place and how their environment is secured using the best-of-breed solutions. Yet, recent well-publicised attacks on established organisations have demonstrated an important fact: building a technology fortress is just not enough to fully protect an organisation's valuable information assets.
Why is this so? Technology is a tool dependent on the people wielding it. Processes are also required to ensure that the solution remains effective even as cyber threats evolve rapidly.
What organisations should do is embrace a holistic approach. The maturity of a cyber defence system hinges not just on technology, but also on other factors such as leadership, people, information risk management, business continuity in a crisis, and compliance to regulations.
Board-level awareness of emerging cyber threats and their direct involvement in determining the response to a cyber threat is critical. This is necessary as investors, governments and regulators alike are increasingly challenging board members to actively demonstrate diligence, ownership and effective management of cyber risks. Incorporating cyber risk into the enterprise risk strategy is also vital. By doing so, leaders can quickly identify gaps in the current cyber security strategy and encourage an organisation-wide approach to countering cyber crime.
No cybersecurity approach is complete without carefully considering human factors.
Organisations should engage and invest in critical talent because their IT and security staff must be technically competent. They should also be disciplined in keeping themselves constantly updated on the necessary skills needed to be an effective part of cyber defence.
The organisational culture plays an even more significant role in combating cyber threats than the technical competency of the IT and security department. It is not unusual for existing staff behaviour to put an organisation at risk. Technological advances and changing work practices such as the use of cloud services and employee-owned devices are making organisations increasingly vulnerable.
To address cultural weaknesses and generate greater awareness of cyber defence, a comprehensive programme should be put in place to monitor staff attitude to meet the organisation's cybersecurity needs. Doing so can help an organisation detect threats or risks early. An effective approach to cybersecurity can only be achieved through a comprehensive and effective management of information risks, not just throughout the organisation but also through its delivery and supply partners.
Increasingly important in the cyber threat landscape is the organisation's approach towards preventing data leakage, both accidentally and intentionally. This includes assessing their service providers to ensure compliance to the organisation's security requirements. While cyber threats are frequently associated with Internet activities, many studies have shown that external threats from hackers only account for about a third of cyber incidents. The remaining stems from insider threats - the staff, vendors and contractors.
Since achieving 100 per cent security is not feasible, organisations can prioritise and focus on areas that matter by understanding their risk appetite and managing their information asset lifecycle.
One moment an organisation's website is defaced and the next moment, it is making headline news. This underscores the importance of being prepared against a cyber attack and critically, the organisation must be resilient in the face of an ongoing attack.
Putting in place a good resiliency plan through crisis and stakeholder management can prevent or minimise the impact of an attack. Practical drills and simulation exercises during peacetime can help an organisation improve plans, ensure the readiness of key personnel and enhance preparedness to respond to a cyber incident.
Control measures must be designed and implemented at a level appropriate to identifying risks and minimising the impact of a cyber attack. While there are various cybersecurity guidances available, organisations should have a clear understanding of their threat environment and the defences required instead of blindly following "what everyone else is doing".
Questions they need to ask include: Do we need to invest in best-of-breed technology? Are we underinvested in certain areas but overinvested in others?
Organisations are subject to increasing legislative and regulatory requirements to demonstrate that they are managing and protecting their information appropriately. A keen awareness of compliance requirements is important to avoid any compliance issues that could hurt the organisation. Organisations should implement a robust cybersecurity framework with clearly defined roles, responsibilities and accountabilities for decision making. The framework should also give due consideration to risks and controls.
Cyber insurance is another component which should not be dismissed. It can act as a means to mitigate losses from data breaches, service disruptions and other cyber damages.
Are organisations prepared and resilient against cyber attacks?
The answer is to look beyond pure technical preparedness and carry out a thorough review of the organisation's ability to protect its information assets.
Taking an integrated view of people, processes and technologies allows organisations to better understand areas of vulnerability, identify and prioritise areas for remediation, and demonstrate corporate and operational compliance. Drills and even cyber war gaming exercises can go a long way towards helping companies prepare for various scenarios.
A holistic cyber security approach can help a company turn information risk into a differentiating business advantage. Customers trust and have greater confidence in companies which display commitment to safeguarding their personal information and transactions.
The writer is head of IT Assurance and Security, KPMG in Singapore.
The views expressed are his own