December 2020ENTERPRISE SECURITY| | 9during the sales cycle can often help to speed up the process and can be a differentiator between providers.Meeting Customer Compliance Expectations and Contractual CommitmentsCustomer Compliance is often considered the primary driver of cybersecurity and privacy programs. In a typical year, companies may field dozens if not hundreds of cybersecurity related RFPs, RFIs, questionnaires and audits. Every one of these, at its core, is focused on cybersecurity and privacy concerns. The primary driver of this scrutiny is that many of the major breaches are tied to 3rd party vendors. Because of this, customer's scrutiny around cybersecurity and privacy compliance has led to an environment where many institutions' requests have become unduly burdensome. Well documented and managed cybersecurity and privacy programs will help to efficiently facilitate, and reduce the overall impact, of these requests on your organization. Regardless, customer compliance continues to be an item that drives your programs to be better.Recruiting and Retaining Top TalentOne often overlooked facet of a cybersecurity program is providing a feeling of protection and comfort with the environment within which one works. In the same way that physical security controls provide overt mechanisms to show outside personnel that you take employee security seriously, making employees aware of cybersecurity controls gives them confidence that their data is protected and threats against them are addressed. An organization that communicates and markets the importance of its cybersecurity and privacy programs will often generate stronger employee engagement resulting in a higher level of employee satisfaction. A few words about Privacy and RolesPrivacy is mentioned above in conjunction with cybersecurity. In many organizations, both functions will, by default, end up the responsibility of the information security organization. However, as companies continue to struggle with meeting and maintaining compliance with existing and upcoming privacy and cybersecurity regulations such as GDPR, CCPA, NYDFS and others just around the corner, it will likely make sense to place regulatory and risk based functions under the guidance of a single leader, or at least coordinate these activities more closely. The best way to think about the increasing scope of the role is that the CISO may morph into the "CISPRO" having responsibility for information security, privacy and risk. It is simply too expensive to separate these functions in many organizations. It won't happen in all organizations, as larger organizations may want or need to keep these functions managed separately. It is likely that this shift will take place over the next three to five years.Wrap-upInformation Security and Privacy have been and will continue to be increasingly important as we seek to win business, protect our assets, ensure customer compliance and recruit top talent. As you move forward, strong cybersecurity and privacy programs and controls will not only be necessary, they will be a competitive differentiator. ESInformation Security and Privacy have been and will continue to be increasingly important as we seek to win business, protect our assets, ensure customer compliance and recruit top talentLeon Ravenna
<
Page 8 |
Page 10 >