Showing posts with label Board. Show all posts
Showing posts with label Board. Show all posts

Thursday, 22 March 2018

The Security Blame Game: From the Past to Now, Who Takes Ownership When Things Go Wrong?


- Dr. Peter Courtney, BOHH Labs Director

Today security threats seem to be inescapable, with companies dodging attacks on an hourly basis and breaches being revealed daily. As such, the practices, technologies and management of security threats have seen a dramatic shift over the past couple of decades, especially in how breaches are accounted for and who takes ownership when things go wrong.

Before we can address where we are today, we first must look at the past and where we’ve come from. In the past, security flaws in a company amounted to losing a ledger-book, a cash box or a roller-deck. While the competitor might steal some customers if they obtained your roller-deck, the impact was modest compared to having an electronic customer file stolen, that might then be sold on, mined automatically or even put up on public display to embarrass the company, as is happening today. Additionally, the complexity of IT errors was much simpler in the past. For example, IT errors might have involved a functional code bug that only caused a problem under rare circumstances. In these instances, the impact on the company was relatively low, typically affecting a specific area of the company.  It was relatively easy to identify the culprit and move forward with a solution. Security breaches were dealt with in a similar manner to a project failing, the CEO would identify the accountable executive and either censure, discipline or fire them depending on the severity of the issue. Typically, the executive to blame was either the CIO or CSO, as security was their focus area and it was clear that they carried the accountability.

Today, more often than not, IT errors are deliberate attacks that target systems such as payments or CRM, they can invade the core processes of the company and may broadcast sensitive customer information to the public web. Unlike in the past, this means that the impact can stretch across the entire company, not just the area that is initially targeted.  The company can be damaged internally and potentially cause reputational and financial damage in the public domain. Because of this, the impact of the breach spreads across the company and accountability flows far beyond the IT/security department. It may be judged that the CFO, CSO, COO or even CEO should have exerted greater control over the company, its processes and its decisions. Today, it is much more difficult to clearly assign blame. Unlike in the past, the perpetrators of the breach may never be identified or the case proven with any hard evidence, making it difficult to hold any single person accountable. In addition many of the suppliers of systems and security are now external rather than having been developed in-house as was the norm.  Indeed, the external party may have been selected by a Board decision rather than simply the CIO or CSO, making it even more difficult to assign individual accountability.

Because the nature of security threats are becoming more complex and the impact a breach can have on the company is more widespread, the risk that accountability may not be contained to an expendable CIO or CSO is making security a priority for the whole executive and even non-executive Boards.  We are seeing more executives politically positioning themselves both in demanding scrutiny on security decisions in advance of them being made and also in positioning accountability away from themselves where that is possible.

The current IT world has been unable to prevent breaches from occurring and many institutions simply consider it a cost of doing business.  As we are seeing, if the threat is inescapable, then so too is the blame.  We now see companies spending huge sums on technology solutions that may not work but enable the company to say that they followed the process and did what they were supposed to do, so they should not be penalized. For now, companies are simply skirting around the accountability game when it comes to breaches, but if we are to move forward as an industry overall, we must come up with a better way. Surely it is time to find security solutions that actually fix the risks and solve the problems rather than waste political energy and money on avoiding blame when the inevitable breach occurs.



Thursday, 8 March 2018

Why Data Security Must Be Treated as a Core Business Value


- Ted West, BOHH Labs Chairman

What makes a company successful? Ask almost any enterprise today and they will tell you that strong revenue, a loyal base of customers and forward-thinking are the keys to ensuring long-term success. However, in our digitally-driven, cloud and mobile-dispersed business world, security is becoming a top priority for more and more organizations, especially for the customer, operations and transactions data they hold. When companies are hit with a data breach or expose sensitive data to “bad actors”, the ramifications can be huge: loss in customers, reimbursement to customers, legal fines and data recovery fees, or perhaps even something worse – damage to reputation. All of these repercussions of a data breach can greatly impact the success and revenue stream of a business, yet data security is still largely viewed as a role of the CIO, CISOs or whomever is in charge of the company’s security strategy.

Most CIOs acknowledge that cybersecurity is a core expectation of their leadership, yet many believe that companies still view security and risk management as mere “compliance chores” and a “cost of doing business.” Industry analysts report that more companies are increasing spending on security investments. However, if companies are making investment decisions in security simply based on implementing what meets the minimum requirements of securing data, and they are not looking at how these investments directly impact business strategy and the bottom line, they will likely fall short of what is needed. 

Data is an asset

It’s clear data is an asset to businesses and holds a lot of weight to how successful a business can be. It’s no secret that most businesses today are happy to put investments in to analyzing data to increase sales and market shares, but those analytics are not useful if business can’t keep their data protected. Business leaders, starting from the Board of Directors and moving through the C-suite, must insist on their organizations adapting the most effective security measures in their IT platforms and workflows and processes today keep the data they hold secure. Their success depends on it. They have no choice, and they should expect nothing less. While this task is not always easy, there is a great opportunity for those businesses who do place importance on keeping data protected and treating it like a core business value to gain a competitive advantage and strengthen their ability to keep the “bad actors” from compromising their good data, their customers’ trust and loyalty, and their critical brands.

Data security is becoming existential, no longer circumstantial, for many organizations

With the current climate of breaches revealed daily and the number and scope of attacks on the rise, organization leaders must start asking themselves: Is fixing a security breach that exposes millions of client records and brings financial and brand damage merely a “compliance chore”, or is it more than that? Is the investment needed to prevent such a breach from happening again a simple “cost of doing business”, or is it more than that? Is fixing a breach, or guarding against it in the first place, a strategic issue impacting the trust and reputation of the organization and its position to grow and retain a loyal base of customers? We think so.

Tuesday, 12 December 2017

The BOHH Breakdown, Part 15: How to Get Your Board Involved in Your Cybersecurity Strategy


In our last post, we shared tips for individuals to stay safe as they begin their Christmas holiday shopping this season. Today, we will address an increasingly important topic – how to address cybersecurity with your board of directors. 

One thing is becoming increasingly clear in today’s climate of nonstop breaches: security matters and data is becoming an asset. It’s time organizations treat cybersecurity as a core business value. Business leaders, starting from the Board of Directors and moving through the C-suite, must insist on their organizations adapting the most effective security measures in their IT platforms, workflows and processes today. 

However, many board members feel they lack the technical aspects about what their role should be as directors when it comes to cybersecurity. Below are some tips to get the conversation started.

  1. Speak in language your board understands. Many board members may not know the technical terms when speaking about technology and security.  Try to break it down in terms that are simple and easy for a non-technical professional to understand.
  2. Talk about security investments and cybersecurity risks in terms of how it impacts the organization’s business and financial bottom line.
  3. Communicate everything in numbers. The board is the oversight of the company, so money matters. If you can relate security investments, potential breach loss, etc. in dollars, it will have a greater impact to how cybersecurity can impact the organization overall.
  4. Tie cybersecurity measures to the competitive marketplace. Highlight what the company’s competitors are doing, so the board can understand how the company needs to keep pace with the market. 
  5. Share examples of how cybersecurity breach incidents have impacted other organizations in your similar market (Equifax, Uber etc.) – did they lose customers, pay a breach settlement fine, pay a ransom fee?
  6. Present the facts of the company. To start a conversation on why having proper security strategies in place is important, gather a list of the organization’s valuable data assets that require protection, so you can customize the conversation to your company’s specific needs.
  7. Share a game plan on where and how you think the board should be involved in the company’s cybersecurity strategy. Having this prepared ahead of time will help show the board where they fit into the plan.
  8. Bring in a security expert to talk to your board about the importance of having proper cybersecurity measures in place. Having a trusted source always goes a long way in the decision-making process, plus highlights the consequences of a breach such as fines, potential senior job losses etc.
  9. Educate them on all of the laws and industry compliance rules in place. This will help them understand why a certain amount of the business strategy needs to be designated to security investments.  Highlight that General Data Protection Regulation (GDPR) is effective starting in May 2018, so there must be a strategy to meet this deadline.
  10. Be concise and clear. Do not waste their time. Prepare ahead of time the main points you want to hit to educate them on the necessary security investments.

Leaders who make security a business priority and an integral part of their organizations daily operations, can help navigate their organization to better long-term performance and success. 

Hopefully these will be a useful tool to get the conversation started. Come back next Tuesday when we take a look back at all of the developments and accomplishments made by BOHH this year.