enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Arkansas Blue Cross Blue Shield

Friction Caused by Security is Required for Forward Progress

Devin Shirley, Chief Information Security Officer, Arkansas Blue Cross Blue Shield

Increased attacks across all industries necessitate the requirement for companies to establish a cybersecurity program. A successful cyber program must continually work in conjunction with business, ensuring security enhances the business by enabling the achievement of goals, not restricting them. Security leaders must attempt to create the perfect balance of good security and business enablement, though attempts at balancing sometimes seem weighted in one direction or the other. Users in an organization may view security as an obstacle that prohibits them from achieving business objectives. Even technology professionals who understand the need for security many times view the controls as a burden, introducing cumbersome processes and security capabilities that interact with or are layered on top of the technology architecture. All this then forces the question: do we have too much security, and how much security can we forego and still achieve company goals? This can lead to friction in the organization between the security program and the rest of the company. This friction, though, is not always bad. Rather, there is a level of friction that should be in place to adequately protect the company, but not so much that it makes it ineffective.

Many organizations prefer to avoid friction and attempt to reduce or eliminate friction, specifically that created by security. However, I propose that the perception needs to shift, with companies understanding that some friction is beneficial and even required if they are to be effective.

Friction is defined as a force resisting the relative motion of solid surfaces, fluid layers, and material elements sliding against each other. This represents what happens in an organization that implements security controls through various policies and standards, as well as security technology capabilities. A great example is that of multi-factor authentication, requiring users to enter information at various steps in the process to obtain access to corporate systems. Other examples include restricting websites and the ability to download or copy data, or, using a simpler example, not allowing employees to piggyback through a controlled doorway. In all of these, employees perceive friction due to inconvenience and inefficiency.

“A successful cyber program must continually work in conjunction with business, ensuring security enhances the business by enabling the achievement of goals, not restricting them”

However, if we view friction as an enabler to help us achieve desired objectives, we can establish the right perspective for security programs. To do this, let’s compare a couple of non-security-related scenarios in which friction plays a significant role. Imagine a car driving down the road and it is moving towards a desired destination, with the goal of getting there safely, on time, and without incident. If there is no friction between the tires and the road, like the icy conditions, the car would slide out of control, eventually crashing. With cybersecurity, this is comparable to not having any security controls or inadequate controls. Without the appropriate amount of friction, a company will likely experience a security incident. Just like the car hitting the ice, it will slip and slide until it eventually crashes, costing time, money, and the health of the organization.

Now, let’s consider a different scenario with the same objectives. In this scenario, instead of no friction, the car has its brakes consistently applied. In this scenario, friction is working against the vehicle, preventing it from moving. This translates to overly restrictive security controls that prevent the actual function of the business. If, for example, a company restricts any outside access to required web-based services or limits emails to internal users only, business personnel would not be able to perform necessary work to be effective and remain in business. So, if there is too much friction created by security, the company may be hindered in making progress towards the objectives. However, we should also understand there are emergency situations when brakes must be applied to prevent an accident. Similarly, security controls may also be applied in an emergency to prevent security incidents.

Implementing the security controls and capabilities necessary to protect an organization is not about implementing as much security as possible, nor is it about doing the minimum. Rather, it should be an ongoing balancing act based on the organization’s risk appetite and what it is willing to accept. With too much security, there is the risk of hindering the business, but if you don’t do enough, you could be vulnerable to attack. Friction is something that always exists with security programs, and it should, if the company wants to reach the destination safely, on time, and without incident. With the proper balance of security controls, you can keep your company on the road without inhibiting forward progress while enabling it to react as needed.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.

Weekly Brief