Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Risk Management

Four Essential Building Blocks of Cyber Security

Despite increased investments in preventive security measures, many organizations are losing the war against cyber criminals.

The data breaches at Target, Home Depot, Staples, Michaels, Kmart, eBay, Anthem, and Sony Pictures Entertainment, were just the tip of the iceberg.

Despite increased investments in preventive security measures, many organizations are losing the war against cyber criminals.

The data breaches at Target, Home Depot, Staples, Michaels, Kmart, eBay, Anthem, and Sony Pictures Entertainment, were just the tip of the iceberg.

New methodologies developed by the National Institute of Standards and Technology (NIST) and other industry standards bodies (e.g., the Payment Card Industry) are being implemented by many organizations, but best practices for addressing cyber security threats remain vague. At the same time, board members are demanding quantitative risk data that spans all business operations, while business units need to neutralize the impact of cyber-attacks. So what can be done to minimize cyber security threats?

IT Risk ManagementAs news of more data breaches and third-party originated cyber-attacks make the news, businesses and regulators alike are sharpening their focus on how to report on and mitigate these risks. According to Gartner, worldwide spending on information security will reach $76.9 billion in 2015, an increase of 8.2 percent over 2014, it appears. However, at the same time we’re seeing an increase in security incidents, which are raising doubts about the effectiveness of these investments. A PwC survey (Managing Cyber Risk in an Interconnected World, PwC, 2015) of 9,700 companies found that they had detected nearly 43 million security incidents in 2014, a compound annual growth rate of 66 percent since 2009.

It’s clear that the dynamics of the threat landscape have changed, and that organizations need to respond accordingly. An effective starting point is to focus on the four essential building blocks of any cyber threat defense strategy, namely:

1. Continuous Monitoring

Most organizations rely on best-of-bread, silo-based tools (e.g., fraud and data loss prevention, vulnerability management, or SIEM) to gather security data. This creates an endless high volume, high velocity, and complex stream of data feeds that must be analyzed, normalized, and prioritized. Unfortunately, relying on manual processes to comb through mountains of logs is one of the main reasons that critical issues are not being addressed in a timely fashion.

Implementing continuous monitoring as propagated by NIST only adds to the big security data conundrum, as an increase in frequency of scans and reporting exponentially increases the data volume. Big data sets can definitely assist in putting specific behavior into context, but there are some real technological challenges to overcome. Big data risk management software can assist organizations in aggregating the different data sources, leading to reduced costs by unifying solutions, streamlining processes, creating situational awareness to expose exploits and threats in a timely manner, and gathering historic trend data, which can assist in predictive security.

2. Cyber Risk Visualization

Advertisement. Scroll to continue reading.

One of the most efficient ways to identify imminent threats to an organization is to create a visual representation of its IT architecture and associated risks. This approach provides security operations teams with interactive views of the relationships between systems and their components, systems and other systems, and components and other components. Ultimately, it enables security practitioners to rapidly distinguish the criticality of risks vis-à-vis the affected systems and components. This allows organizations to focus mitigation actions on the most sensitive / at risk business components and increase board / auditor transparency.

3. Risk-Based Prioritization

Effective prioritization of vulnerabilities and incidents is essential to staying ahead of attackers. While security monitoring generates big data, in its raw form it remains only a means to an end. Ultimately, information security decision making should be based on prioritized, actionable insight derived from the data. To achieve this, big security data needs to be correlated with its business criticality or risk to the organization. Without a risk-based approach to security, organizations can waste valuable IT resources mitigating vulnerabilities that in reality pose little or no threat to the business.

Furthermore, big security data needs to be filtered to just the information that is relevant to specific stakeholders’ roles and responsibilities. Not everyone has the same needs and objectives when it comes to leveraging big data.

4. Closed-Loop Remediation

Lastly, closed-loop, risk-based remediation leverages subject matter experts within business units to define a risk catalog and risk tolerance. This process entails asset classification to define business criticality, continuous scoring to enable risk-based prioritization, and closed-loop tracking and measurement.

By establishing a continuous review loop of existing assets, people, processes, potential risks, and possible threats, organizations can dramatically increase operational efficiency, while improving collaboration among business, security, and IT operations. This enables security efforts to be measured and made tangible (e.g., time to resolution, investment into security operations personnel, purchases of additional security tools).

By focusing on these four cyber security building blocks, organizations can not only fulfill their board requirements for quantitative risk reporting that spans all business operations, but also serve their business units’ need to neutralize the impact of cyber-attacks. These methodologies can also help break down security silos, improve time-to-remediation, and increase visibility into enterprise risks.

Written By

Dr. Torsten George is an internationally recognized IT security expert, author, and speaker with nearly 30 years of experience in the global IT security community. He regularly provides commentary and publishes articles on data breaches, insider threats, compliance frameworks, and IT security best practices. He is also the co-author of the Zero Trust Privilege for Dummies book. Torsten has held executive level positions with Absolute Software, Centrify (now Delinea), RiskSense (acquired by Ivanti), RiskVision (acquired by Resolver, Inc.), ActivIdentity (acquired by HID® Global), Digital Link, and Everdream Corporation (acquired by Dell).

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...