enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Rogers Communications

Digital Crown Jewels - It's a High Stakes Game

Michael Laing, CISO & Senior Director of Cyber Security, Rogers Communications

Companies are increasingly relying on digital assets to drive growth as part of digital transformations."Digital Crown Jewels" or DCJ are the most valuable and critical assets that support an organization's success.With companies moving from centralized to decentralized technologies comes greater risk and impact, if DCJs are compromised.  A compromised DCJ can result in significant financial and reputational impacts.Protecting a DCJ requires a defense in depth approach whereby multiple layers of controls are deployed. But to do so, it requires an understanding of an organization’s DCJ and the threat landscape.

What are DCJ?

Digital Crown Jewels are the foundation of any company’s operations – from critical support systems to sensitive customer and company information. DCJ can include:

• Intellectual Property (IP): Patents, trade secrets, proprietary algorithmsthat can provide a competitive advantage.

• Customer Data: Personal information, credit card data

• Employee Data: HR records, payroll information, and sensitive employee data

• Financial Data: Critical financial records, accounting information, and transaction data

• Business Strategies: future plans, marketing strategies,and product roadmaps

• Life Impacting Systems: Critical support systems that if disrupted could result in impact to human life.

And just as precious jewels attract thieves, these valuable digital assets are subject to cyber threats.

The Threat Landscape:

The Threat Landscape for DCJ consists of three key categories: cyber attacks, insider threats, and physical threats.

Cyber-Attacks: Sophisticated hackers leveraging attack vectors like phishing, ransomware, and zero-day exploits to gain unauthorized access to digital crown jewel

Insider Threats: Employees or partners with malicious intent or negligence pose a potential risk to data security.

Physical Threats: Disasters such as fires, floods, or theft can lead to the loss of physical devices containing critical data.

Through this understanding, organizations can begin to develop a defense-in-depth approach and implement multiple layers of controls to protect DCJ.

Top 10 Controls to Protect Digital Crown Jewels:

1. Access Controls: Implement access controls to limit access to sensitive data to only authorized personnel. MFA should be implemented at a minimum on external facing channels and privileged accounts.

2. Data Encryption: Employ strong encryption techniques in line with industry best practices to protect data at rest and in transit

3. Regular Vulnerability Assessments: Conduct regular vulnerability assessments to identify, assess, and rank vulnerabilities. Vulnerabilities should be ranked based on the severity of the threat and potential exposure to digital crown jewels.

4. Patching: Automated capability should be deployed to apply patches in a timely, risk-based manner. Regular reporting and monitoring of patching status should be implemented to identify patches not applied on a timely basis or outside organization-defined timelines.

5. Cyber Awareness Training: Train employees on how to identify and protect against common attacks such as phishing.

6. Web Application Firewalls: Web application firewall(s) (WAF) should be deployed to protect web applications from attacks such as SQL injection cross-site scripting.

7. Code Scanning: static and /or dynamic scanning tools should be used for changes to code on the application. Vulnerabilities should be remediated prior to release to production.

8. Logging: Enable logging to capture critical security and system events. Logs should identify the user, type of event, date and time stamp, success or failure, and origination of the event. 9. Monitoring: Logs should be monitored on a continuous basis for potential malicious and unauthorized activities. Threat intelligence and indicators of compromise should be used to enhance the detection of emerging threats.

10. Data Backups: Where technically feasible configure backups to be immutable or regulatory stored offsite (disconnected from the primary network)

Conclusion

Digital Crown Jewels, like real-life crown jewels,represent high-value assets and should be protected using a defense in depth approach. By understanding DCJ and the threat landscape, organizations can deploy a comprehensive system of controls to protect its most critical assets using a risk-based approach.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief