October 2022ENTERPRISE SECURITY| | 19for tackling bigger problems. There has also been an increase in diversity hiring--from neurodiversity to diverse backgrounds--as companies seems to realize that the more diverse perspectives on a team; the more creative solutions to tough problems. Apart from staffing problem, ransomware continues to be a major concern. And, what we see as a result is cyber risk insurance costs have gone through the roof, pricing a lot of companies out of out of the market. I think there are still the basic things that people aren't getting: good backup strategy, good cyber hygiene, basic patching, and risk management that are mandatory for sustaining today. COULD YOU SHARE A FEW CONCERNS REGARDING ENTERPRISE RISK MANAGEMENT IN A POST-PANDEMIC SCENARIO?A company ought to have a holistic view of risk to help make well-informed risk-based decisions. Factors like the Great Resignation and changes in customer behavior in a post COVID world made it clear that the businesses had to evolve their customer service and view on workforce. And, to advance with those changing business and employee requirements, security has to be adaptive enough. Also, I think, this last couple of years has shown us that anything is possible. That's why, we are always concerned at a macro level that any time anybody's security can get breached. But, I don't think we need to give up on the notion that we can always be better. We just have to do a much better job at redefining what better security looks like, and setting the right kind of expectations to enterprise risk management. A FEW THOUGHTS ON THE APPROACH YOU'RE TAKING TOWARD RISK MANAGEMENT IN YOUR CURRENT ORGANIZATION?Like many other companies, we at H&R are on a zero-trust journey. We had to help facilitate better and more efficient ways of serving our clients while maintaining or hopefully increasing our cybersecurity posture. From a business perspective, the security of our customers' data is paramount. For that, we should be apt at identity and access management from our employees' perspective. This will prohibit any chance of data going into the wrong hands. Also, we have to be able to do a great job of ensuring authentication of our customers whether they're in an H&R Block office or remote, regardless of how they choose to interact with us. Obviously, we want to accomplish this with least amount of friction. But, we also want to be able to detect when customer behavior differs from their established patterns. We want to detect customers' interaction with us, help them be more secure while using our services, and interact with government agencies like IRS. This will help customers be more confident with our security stance and help us recognize any mistake from our end. TO accomplish this, we try to take a holistic view, both internally and externally, when we look at authentication, authorization, trust, behavioral monitoring, and aspects that flow out of a zero-trust journey.WHAT ARE SOME OF THE TRENDS THAT EXCITE YOU ABOUT THE FUTURE OF ENTERPRISE SECURITY?The trends of companies going multi-cloud and multi-platform are some of the interesting things going on in the security space. We're starting to see SaaS platforms upping their games by constructing their services to be secure by default. That being said, I believe that no product can completely solve the security issues. Tools and technology are there just to enforce policy and help implement programs. And, that's why technology is the last thing one must go to for problem solving. Instead, we must understand that it's the people that process those technologies and tools. And, in that regard, we must always strive to onboard more efficient talent. Presently, we're seeing a lot more willingness to bring in young people, even fresh out of college and give them the skills they need to be successful. I'm very pleased to see companies focus on talent and process and less on technology. We are seeing Governmental entities like the SEC increasing recognition regarding the importance of information security. Also, publicly traded companies have started adding CISOs to their board who directly report to CEO. As a result, such companies are going to have the right security topics discussed at the highest level within the organization. For InfoSec, this will help us value the good ideas that come up with the right talent and help offers our customers better security. ESFROM A BUSINESS AND SERVING THE CUSTOMER PERSPECTIVE, THE SECURITY OF OUR CUSTOMERS' DATA IS PARAMOUNT. AND THAT MEANS WE HAVE TO BE ABLE TO DO A GREAT JOB OF ENSURING THAT WE CAN AUTHENTICATE OUR CUSTOMERS
<
Page 9 |
Page 11 >