A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Lone Butte and Vee Quiva

It Security: A Practical Approach

Vulnerabilities. Data Breaches. Ransom­ware. In a world where a hacking activity takes place every 39 seconds, it’s easy to get trapped in a cycle of chasing the latest cybersecurity threats. But rather than putting your organization in a frenzied panic, consider taking a practical approach to your security program to help ensure a solid foundation and mitigate risks.

No matter what industry you are in, strategic planning and a relentless adherence to a written standard of technology is paramount. Start building your cyber defense wall with these practical steps:

1. Create a Strong Team

It’s important to identify the personnel, whether an internal employee or a security partner, who will be responsible for pushing your program forward. Even with a partner driving your security program, a

security champion should be identified internally who can be part of the crucial conversations that happen daily to ensure new initiatives are being communicated to your security partner.

2. Conduct an Internal Audit

What are the most valuable and critical assets to your company? This is the same question that ma­licious actors will ask themselves when they are casing your organization, wheth­er it’s during reconnaissance or even if an endpoint or process has already been com­promised. Yes, even processes are assets in your company, and they should be under the same scrutiny your security team uses for securing systems.

"The Rollout Of A Successful Security Program Is No Different Than The Rollout Of Any Other Large Project In Your Organization"

Identify the systems (servers, data­bases, file shares, cloud services, and oth­ers) that hold the data that is most critical to your organization. In tandem, identify the processes that are around all financial transactions.

An internal audit, for example, can help you assess how you’ve been monitoring logs for malicious activity. You can’t detect anomalies in your environment if you aren’t collecting the logs.

3. Set Goals & Define Policies

The adage “walk before you run” still rings true, especially when managing vulnera­bilities. Setting goals and defining policies will help you navigate through complex challenges as they arise. A good example of this is patch management. When was the last time each of your systems received an update? Patch management is a critical component for any organization’s security posture. Your policy should outline what systems are patched, how frequently they are patched, and how you audit that the patches were deployed successfully. Fre­quency should be set to an achievable goal at the offset of your security program and reduced as the patch management process is matured.

4. Educate Employees at All Levels

Phishing and social engineering attacks are increasing 16 per­cent each year – do your employees know how to spot clever hackers? Security awareness training does not have to be an ex­pensive endeavor with painful, rushed rollouts to the entire or­ganization. Start simple with a monthly newsletter that includes important security tips. If you have the luxury of a marketing de­partment, partner with them to help communicate a memorable message to employees. For example, a personal favorite of mine is “Trust but Verify.” Remember that people are your weakest link, and when it comes to cybersecurity and dealing with important or sensitive information and financials, it is always a better idea to over-communicate.

5. Evaluate & Adjust

The foundation of cybersecurity is built upon repeatable tasks that when done consistently, reduces your overall risk footprint. It’s important to ensure that as your journey continues, you are au­diting yourself along the way. Are all the new assets being classified? Are you analyzing new processes as they are im­plemented to ensure security risks are being addressed?

Although an internal mechanism should be in place to verify that process­es are being followed, a third-party audit from a trusted partner will help mature your practice and ensure nothing is slip­ping through the cracks.

Once you’re proficient at the prac­tical steps in security, the next iteration should be selecting a framework and closing additional gaps in your security practice. Some of my peers may argue that this should be done first, but I be­lieve the superior security frameworks that are available, such as offerings from NIST, ISO or CIS, should be brought into play once you’ve established the basics.

The rollout of a successful security program is no different than the rollout of any other large project in your organization. It requires ex­ecutive buy-in, dedicated personnel, a structured plan, and ac­countability. Your early wins should be celebrated, and a pos­itive mentality kept during the execution of the project. When failures occur, embrace them, and push your team forward doc­umenting these items along the way. Revisit them during your progress meetings and turn them into wins where opportunities for improvement were identified and successfully implement­ed. Keeping a positive mindset throughout your organization towards your security program will ensure the long-term via­bility of your practical approach to security.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top