enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

GSK

A Framework for Safely Accepting Risk

Steve Williamson, Audit Account Director, Information Security and Data Privacy, GSK

Introduction

Enterprise Risk Management (ERM) is a process to Identify, Assess and Manage risk events that (if allowed to materialise) would prevent the organisation from fulfilling its strategic and operational objectives. A reliable ERM framework will enable the Board to take a holistic view of risk as it covers all relevant risk types, e.g., financial stability, regulatory compliance, reputation damage and the security of mission-critical operations. Cyber Security has become front and centre within ERM due to the ubiquity of cyber-attacks, which very often result in a material impact on the enterprise. For example, the effect of a ransomware attack could be the disclosure of sensitive customer data, a compromised Operational Technology network or a denial of service on e-commerce channels.

Cyber defenders have to protect against increasingly sophisticated attacks as threat actors evolve their capabilities and draw on the services available from the cybercrime-as-a-service ecosystem. This threat is further exacerbated by internal digital transformation programs, which aim to make business processes more data-driven and automated. As organisations become increasingly dependent on data, software and internet connectivity, the impact of a technology interruption is more immediate. This was evident from the cyber-attack on MGM Resorts (April 2023), which caused casino slot machines to stop functioning and thousands of guests to be locked out of their hotel rooms due to the failure of their digital key cards. The reported cost impact for MGM is more than £100 million.

Identify, Assess, Manage, Repeat

The generic stages of the ERM are illustrated in Figure 1. ERM is a continuous process; it must accommodate fast-moving digital innovations that deliver business value but often introduce new risks and sometimes new legal requirements. For example, in 2022, ChatGPT emerged as the first mainstream Large Language Model (LLM). 

 

  • ERM is a continuous process; it must accommodate fast-moving digital innovations that deliver business value but often introduce new risks and sometimes new legal requirements

 

It has now been adopted or replicated by many organisations across different industries. Artificial Intelligence (AI) technologies such as LLMs generate non-predictable outputs which may not be accurate. This is referred to as hallucinations, i.e., instances where the generated output is factually incorrect but has the appearance of fact. Consequently, Digital Trust has emerged as a significant new risk. One may argue that digital trust is not a cyber-threat as it relates to software functionality and data quality, but that would be a moot point because ERM takes a holistic view of risk with a focus on business consequences.                                              

The 5X5 risk quantification grid (figure 2) is frequently used to communicate risk exposure, with each organisation defining the five levels of impact (e.g., impact level 5 may be defined as 20% of net profit). Inherent Risk is our estimate of risk exposure based on an assessment of the current control environment. Residual Risk can be thought of as the target risk exposure once all reasonable controls have been implemented and are operating effectively. A common risk framework such as this allows senior management to compare different types of risk and prioritise the allocation of resources. In a recent Gartner Board Directors survey (2023), almost half of Boards said they are prepared to accept greater risk to achieve increased growth. An ERM framework enables management to make trade-offs and adjust their risk appetite in recognition of growth opportunities.

Cyber is all about Threats and Controls

From a cybersecurity perspective, the reliability of the ERM framework is dependent on the methodical assessment of Threats and Controls. Factor Analysis in Information Risk (FAIR) is emerging as an industry standard for achieving this. Integral to this methodology is the identification of Threat Actors and Loss Event Scenarios (LES). A LES consists of a sequence of actions (exploits) leading to asset compromise and a quantified business loss. Its likelihood of occurrence is estimated using historical data, threat intelligence and expert judgement. This exercise can be used as the basis for identifying and implementing the most important cyber safeguards.

A risk assessment should always take into account the effectiveness of the current control environment. A control is anything that reduces the likelihood or impact of a risk, e.g., multi-factor authentication mitigates the compromised user credentials being misused. One should always question whether the controls are operating effectively; for example, Data Loss Prevention (DLP) is a control designed to reduce data exfiltration, but it is only effective if an appropriate rule set has been configured into it and generated alerts are responded to in a timely manner.

In conclusion, ERM is a continuous process that makes use of a common scoring framework to represent all types of risk. This enables management to make well-informed risk acceptance decisions. From a cybersecurity perspective, it is impractical to protect everything to the same level, but through methodical risk assessment practices, cyber defenders can prioritise to ensure the most valuable assets are protected against the most likely threats.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.