enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Edenred

Cybersecurity as a Business Enabler: How to Justify Cybersecurity Spending to Business Leaders

Peter WONG, Head of Information Security and Compliance – APAC, Edenred

One of the biggest challenges for organizations is how to justify and prioritize the risks identified in cyber security with the effort to mitigate them and align them with business goals. This is because risk management is often seen as an isolated function, separate from the rest of the organization. As a result, organizations may be managing risks that are not aligned with their overall business objectives.

One way to address this challenge is to integrate risk governance with value chain analysis. Risk governance provides the overall framework for managing risks, while value chain analysis helps to identify and assess the specific risks associated with each activity in the value chain.

Risk governance is the framework and processes that an organization uses to identify, assess, manage, and monitor risks. It is essential for any organization that wants to achieve its strategic goals and protect its value.

Value chain analysis is a framework for understanding the activities that create value for customers and identifying the risks associated with each activity. It can be used to identify and assess risks across the organization's entire value chain, from sourcing raw materials to delivering products and services to customers.

 “Value chain analysis helps to identify and assess the specific risks associated with each activity and team in the value chain by aggregating them and mapping the risks to business value.”

Risk governance and value chain analysis are synergistic tools. Risk governance provides the overall framework for managing risks. At the same time, value chain analysis helps to identify and assess the specific risks associated with each activity and team in the value chain by aggregating them and mapping the risks to business value.

Integrating Risk Governance with Value Chain Analysis

A value chain can be modeled as a chain of activities, from business value to IT assets, as follows:

To integrate risk governance with value chain analysis, organizations can follow these steps:

1. Inventory the business solutions, business operations, business applications, and IT assets. This inventory should include a mapping of how each asset supports the business solutions and valu

2.List the audit findings, vulnerability reports, and security incidents and link them to each identified asset.

3.  Aggregate the vulnerabilities and threats to business solutions and link the risks to business value, such as revenue. This will help to prioritize the risks and explain the rationale to business leaders.

Benefits of Integrating Risk Governance with Value Chain Analysis

Integrating risk governance with value chain analysis can provide benefits including

● Increased visibility into risks across the entire value chain

● Improved alignment of risk management efforts with business goals

●  More effective risk mitigation strategies to reduce risk exposure.

Example

A company that sells retail products online has three business solutions: A, B, and C. The security team reported three vulnerabilities in two IT assets: server X, which supports both solutions A and B and server Y, which supports only solution C.

Normally, organizations might prioritize fixing server X because it supports two business solutions. However, by integrating risk governance with value chain analysis, the company can discover that solution C has the biggest business value. This is because solution C may be more profitable, have a larger customer base, or be more critical to the company's overall strategy.

Therefore, the company should prioritize fixing server Y because it supports the business solution with the biggest business value. This will help the company to protect its most valuable assets and achieve its strategic goals.

Conclusion

By integrating risk governance with value chain analysis, organizations can make more informed decisions about how to prioritize cybersecurity risks. This can help organizations to protect their most valuable assets and achieve their strategic goals.

 

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief