DECEMBER 2024ENTERPRISE SECURITY| | 19ERM IS A CONTINUOUS PROCESS; IT MUST ACCOMMODATE FAST-MOVING DIGITAL INNOVATIONS THAT DELIVER BUSINESS VALUE BUT OFTEN INTRODUCE NEW RISKS AND SOMETIMES NEW LEGAL REQUIREMENTSFigure 1 - ERM Cycle Figure 2 - Risk quantification gridThe 5X5 risk quantification grid (figure 2) is frequently used to communicate risk exposure, with each organisation defining the five levels of impact (e.g., impact level 5 may be defined as 20% of net profit). Inherent Risk is our estimate of risk exposure based on an assessment of the current control environment. Residual Risk can be thought of as the target risk exposure once all reasonable controls have been implemented and are operating effectively. A common risk framework such as this allows senior management to compare different types of risk and prioritise the allocation of resources. In a recent Gartner Board Directors survey (2023), almost half of Boards said they are prepared to accept greater risk to achieve increased growth. An ERM framework enables management to make trade-offs and adjust their risk appetite in recognition of growth opportunities.CYBER IS ALL ABOUT THREATS AND CONTROLSFrom a cybersecurity perspective, the reliability of the ERM framework is dependent on the methodical assessment of Threats and Controls. Factor Analysis in Information Risk (FAIR) is emerging as an industry standard for achieving this. Integral to this methodology is the identification of Threat Actors and Loss Event Scenarios (LES). A LES consists of a sequence of actions (exploits) leading to asset compromise and a quantified business loss. Its likelihood of occurrence is estimated using historical data, threat intelligence and expert judgement. This exercise can be used as the basis for identifying and implementing the most important cyber safeguards.A risk assessment should always take into account the effectiveness of the current control environment. A control is anything that reduces the likelihood or impact of a risk, e.g., multi-factor authentication mitigates the compromised user credentials being misused. One should always question whether the controls are operating effectively; for example, Data Loss Prevention (DLP) is a control designed to reduce data exfiltration, but it is only effective if an appropriate rule set has been configured into it and generated alerts are responded to in a timely manner.In conclusion, ERM is a continuous process that makes use of a common scoring framework to represent all types of risk. This enables management to make well-informed risk acceptance decisions. From a cybersecurity perspective, it is impractical to protect everything to the same level, but through methodical risk assessment practices, cyber defenders can prioritise to ensure the most valuable assets are protected against the most likely threats. ES
<
Page 9 |
Page 11 >