THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



For most industries, the future is digital—more automation, increased connectivity, Artificial Intelligence (AI) decision-making, and exponential data growth. The ability to transform and innovate using digital tech will become a growth differentiator, and companies that transform the fastest will benefit the most. However, the most zealous digital transformers could also become the most vulnerable unless they smarten up their risk management game.
The more a company relies on digital systems, the greater the potential for harmful business impacts in the event of a cyber-attack. Systems go down, planes stop flying, e-commerce companies can’t accept orders and manufacturing plants stop producing. For research-based companies, losing their intellectual property is like having the crown jewels stolen. Ransomware is rampant because it is profitable but destructive for its victims. These material loss events require disclosure to regulators, and this is not just an administrative exercise. The Securities and Exchange Commission (SEC) has already fined four organisations for making misleading disclosures about cyber risk and intrusions, with the fines ranging from $900,000 to $4 million.
The more we replace physical artefacts and people with digital assets, the more exposed we are to cyber events. Therefore, security and resiliency must be engineered to ensure mitigation of the most likely threats. This could cover everything from access controls to immutable backups.
The good news for cyber defenders is that industry control frameworks, such as CIS and NIST, are freely available and outline a commonly accepted security benchmark acceptable to auditors and regulators. Yet, compliant companies still get breached. Implementing a standard control set and making it truly effective is time-consuming, expensive and hard to achieve across a technology landscape comprising legacy and new tech. The threat environment is also evolving. In particular, financially motivated threat actors evolve their Techniques, Tactics and Procedures (TTPs) and continue to be successful as described in disclosure reports.
For management, there are two approaches to security:
1. A compliance-driven approach, which involves selecting a security control framework, implementing the controls and gaining certification
2. A risk-based approach starts with identifying the most likely threats and implementing the controls that reduce the greatest risk. A risk-based approach is about control prioritisation and residual risk.
The starting point may be identifying the most valuable assets and probable threat scenarios. For example:
An external threat actor launched a phishing campaign and has taken control of users’ devices. He identifies weak credentials, which allows him full access to the company data warehouse. He exfiltrates sensitive data, including intellectual property and holds the company to ransom.
This is a credible scenario because it has occurred frequently in the past. Many controls can mitigate this, but to select the most impactful ones, it is necessary to understand the tactics most used by the threat actors. According to the Verizon Data Breach Investigations Report, the most common exploit methods are misuse of credentials, social engineering and exploitation of unpatched systems. A recent threat report by Google shows a shift in tactics by attackers, showing that many target over-privileged service accounts in cloud environments, because they allow them to move laterally within an organisation's systems.
With this threat intelligence, defenders can identify the most critical controls. A high-priority starting point may include:
● Enforcing multi-factor authentication (MFA) for all administrator and remote access
● Applying Least Possible Privileges on all accounts
● Enhancing security awareness training and performing phishing simulations
● Deploying a Data Loss Prevention solution
This is not exhaustive. In fact, it is easy to compile a list of twelve or so controls that will all help to address this risk. However, the aim is to identify those controls that will provide the greatest risk reduction and implement them well! Cost and timeline for implementation are also factors. This approach seeks to move the risk plot from inherent risk to residual risk, i.e., what the company can tolerate.
Unlike a compliance approach, which measures security posture against a benchmark control set, the risk-based approach reduces risk to an acceptable level. Each control selected for implementation must contribute to reducing the likelihood or the impact of a credible threat event. The outcome is a residual risk, which recognises that a cyberattack may still happen, but is something the organisation can tolerate and will recover from.
An expanding technology landscape continually under threat from well-organised bad actors characterises a new normal for businesses. Whereas a compliance approach measures security against an industry benchmark, a risk-based approach is more targeted and should give a better return on security investment, thus allowing a business to dedicate more effort to digital transformation. A risk-based approach should always draw on threat intelligence and implement a control set that reduces risk to an acceptable level.