Skip to main content

Cyber security everything an executive needs to know 1st edition by phillip ferraro isbn 1988071208

Page 1

Cyber Security Everything an Executive Needs to Know 1st edition by Phillip Ferraro ISBN 1988071208 978-1988071206 pdf download https://ebookball.com/product/cyber-security-everything-anexecutive-needs-to-know-1st-edition-by-phillip-ferraroisbn-1988071208-978-1988071206-16680/

Explore and download more ebooks or textbooks at ebookball.com


Get Your Digital Files Instantly: PDF, ePub, MOBI and More Quick Digital Downloads: PDF, ePub, MOBI and Other Formats

Key Marketing Metrics The 50 Metrics Every Manager Needs To Know 1st edition by Neil Bendle, Paul Farris, Phillip Pfeifer, David Reibstein 1292360860 9781292360867 https://ebookball.com/product/key-marketing-metricsthe-50-metrics-every-manager-needs-to-know-1st-edition-by-neilbendle-paul-farris-phillip-pfeifer-davidreibstein-1292360860-9781292360867-21406/

What Every Engineer Should Know About Cyber Security and Digital Forensics 1st edition by Joanna DeFranco ISBN B00FZHRLMI 978-1466564527 https://ebookball.com/product/what-every-engineer-should-knowabout-cyber-security-and-digital-forensics-1st-edition-by-joannadefranco-isbn-b00fzhrlmi-978-1466564527-16722/

Instagram Black book Everything You Need to Know About Instagram for Business and Personal Ultimate Instagram Marketing Book 1st Edition by Holmes ISBN 1519643934 9781519643933 https://ebookball.com/product/instagram-black-book-everythingyou-need-to-know-about-instagram-for-business-and-personalultimate-instagram-marketing-book-1st-edition-by-holmesisbn-1519643934-9781519643933-15726/

The Internet Book Everything You Need to Know About Computer Networking and How the Internet Works 5th Edition by Douglas Comer ISBN 9780429824449 0429824440 https://ebookball.com/product/the-internet-book-everything-youneed-to-know-about-computer-networking-and-how-the-internetworks-5th-edition-by-douglas-comerisbn-9780429824449-0429824440-15736/


Cyber Security on Azure An IT Professional’s Guide to Microsoft Azure Security 2nd edition by Marshall Copeland, Matthew Jacobs ISBN 1484265300 978-1484265307 https://ebookball.com/product/cyber-security-on-azure-an-itprofessionalaeurtms-guide-to-microsoft-azure-security-2ndedition-by-marshall-copeland-matthew-jacobsisbn-1484265300-978-1484265307-16706/

Cyber Security on Azure An IT Professional’s Guide to Microsoft Azure Security 1st edition by Marshall Copeland, Matthew Jacobs ISBN ‎ 1484227395 978-1484227398 https://ebookball.com/product/cyber-security-on-azure-an-itprofessionalaeurtms-guide-to-microsoft-azure-security-1stedition-by-marshall-copeland-matthew-jacobs-isbnaeurz-1484227395-978-1484227398-16708/

An Introduction to Global Supply Chain Management What Every Manager Needs to Understand 2nd edition by Edmund Prater,Kim Whitehead ISBN 1637424558 978-1637424551 https://ebookball.com/product/an-introduction-to-global-supplychain-management-what-every-manager-needs-to-understand-2ndedition-by-edmund-prater-kim-whiteheadisbn-1637424558-978-1637424551-24098/

Cyber Security Ultimate Beginners Guide to Learn the Basics and Effective Methods of Cyber Security 1st edition by Michaels Steven ISBN 1691906573 978-1691906574 https://ebookball.com/product/cyber-security-ultimate-beginnersguide-to-learn-the-basics-and-effective-methods-of-cybersecurity-1st-edition-by-michaels-stevenisbn-1691906573-978-1691906574-16658/

Cyber Security on Azure An IT Professional’s Guide to Microsoft Azure Security 2nd edition by Marshall Copeland, Matthew Jacobs 1484265319 9781484265314 https://ebookball.com/product/cyber-security-on-azure-an-itprofessionalaeurtms-guide-to-microsoft-azure-security-2ndedition-by-marshall-copeland-matthewjacobs-1484265319-9781484265314-20044/


What others are saying about Cyber Security “When it comes to cyber-security, Phil is the expert. Cyber Security: Everything an Executive Needs to Know is a must read for the Csuite. Phil takes his years of experience in a wide variety of roles and encapsulates the critical lessons he learned into a wellconsidered approach that even the most seasoned security professionals should read.” ~ Malcolm Harkins, Global CISO, Cylance “Ferraro’s transformational approach to IT Security leadership and innovation is unmatched. This book features decades of CISO experience packaged into one resource that provides critical steps you can take as a leader to better prepare your organization from future attacks.” ~ Chris Ancharski, Program Director, Evanta “Phil Ferraro is THE professional I lean on when covering major tech news involving cyber- security. He is extremely knowledgeable and provides great insight into the inner-workings of the cyber-security sector.” ~ Mauricio Marin, CBS TV Las Vegas News Reporter “Phil Ferraro’s no-nonsense guide to cyber security is brought to life with alarming, but real scenarios creating far-reaching business effects. Phil delivers a refreshing and powerful approach to educate business executives and aspiring technology leaders alike, without the typical scare tactics surrounding cyber-security. Readers benefit not only from the perspective of this passionate world-class Global Chief Information Security Officer, but also directly from the voices of outstanding peers across industries to showcase how rock star CISOs approach this challenge.” ~ Mike Stango, Director, Security 50


"In our digital age, the issues of cyber security are no longer just for the technology crowd; they matter to us all. In confronting the cyber security problem, it's important for all of us to become knowledgeable and involved. This book makes that possible -- and also fascinating. It's everything you need to know about cyber security, wonderfully presented in a clear and smart way.” ~ Peggy McColl, New York Times Best Selling Author


CYBER SECURITY:

Everything an Executive Needs to Know By Phillip Ferraro


Published by Hasmark Publishing judy@hasmarkpublishing.com Copyright© 2016 Phillip Ferraro First Edition, 2016 No part of this book may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording or by any information storage and retrieval system, without written permission from the author, except for the inclusion of brief quotations in a review. Limit of Liability and Disclaimer of Warranty: The publisher has used its best efforts in preparing this book, and the information provided herein is provided “as is." This book is designed to provide information and motivation to our readers. It is sold with the understanding that the publisher is not engaged to render any type of psychological, legal, or any other kind of professional advice. The content of each article is the sole expression and opinion of its author, and not necessarily that of the publisher. No warranties or guarantees are expressed or implied by the publisher’s choice to include any of the content in this volume. Neither the publisher nor the individual author(s) shall be liable for any physical, psychological, emotional, financial, or commercial damages, including, but not limited to, special, incidental, consequential or other damages. Our views and rights are the same: You are responsible for your own choices, actions, and results. Permission should be addressed to: Phil@phillipferraro.com Editor: Justin Spizman www.JustinSpizman.com


Cover Design: Patti Knoles www.VirtualGraphicArtsDepartment.com Layout: Anne Karklins info@annehk.ca ISBN-13: 978-1-988071-20-6 ISBN-10: 1-988071-20-8


This book is dedicated to my parents, Barbara and John Souza. Thank you for always being there for me, and for all your unconditional love, encouragement, and support. Without you both, I would not be where I am.


Acknowledgments To my wife and best friend Sandra without whose constant support, encouragement, and love this book would not have been written. To my editor, Justin Spizman, for his constant source of great creative ideas and helpful suggestions for this book, and his ability to teach me how to be a storyteller by putting my thoughts and experiences into words. To my friend and inspiration Bob Proctor, I thank you for teaching me a much greater understanding of how to overcome and change paradigms and unlock unlimited potential in my life. Your coaching has changed the way I view life. To Peggy McColl, for amazing training, guidance, and encouragement not only on how to write a book, but also on how to write an international best seller. I would to like to thank a number of my colleagues – Malcolm Harkins, Bruce Brody, Lou DeSorbo, Scott Goodhart, and Jay Leek – who were incredibly generous with sharing their expert advice and experiences in creating a world class cyber security organization. I am very grateful for them taking the time from their very busy schedules. I also have been very fortunate to work with so many fantastic people in my long career. Without wanting to make this acknowledgement section longer than the book itself, I want to express my gratitude to my mentors, supervisors, co-workers, team members, and friends who all have contributed to my experiences, which have led to the writing of this book. You know who you are. Thank you!


Table of Contents A Letter to the Reader Chapter 1: Are You Next?: Assessing Your Internal Risk The New Age of Infiltration The Evolution of the Invisible Thief A Real Threat Is My Organization at Risk? Assessing Your Risk Building Structure from Within Cyber-Screwed Chapter 2: From Top to Bottom: It Takes a Village to Prevent a Breach Where Does it Begin? Managing Risk Management Human Error Communicating Your Message Executing the Action Plan Security Culture Chapter 3: Perceived Threats: Separating the Real from the Fake Understanding the Risk Anatomy of an Attack Visualizing the Threat Fact or Fiction? Size Really Does Matter Chapter 4: Damage Done: Understanding the Impact of a Breach How Deep Does it Go? Brand and Reputation Damage Intellectual Property Class Action Lawsuits Fines Damage Done


Can You Be Held Liable for a Breach? Chapter 5: Protecting Your Business: Creating a Rock-Solid Program Pre-Planning Your Program The Hiring Process Executing the Game Plan Functional Areas Business Integration Chapter 6: Leading the Charge: The Role and Responsibilities of a CISO Rock Star Qualities The Responsibilities of a CISO Security Assessments Risk Management Policy and Governance: Auditor Not Implementer Security Architecture and Engineering Security Monitoring Incident Response Cyber Threat Intelligence Forensics Investigations A Day in the Life of a CISO Chapter 7: Breach Management: Recovering from the Carnage The Day of Dread Crisis Action Team Containment, Mitigation, and Forensics Recovery and Lessons Learned The Aftermath Chapter 8: Cyber Security Roadmap: The Path to a Rock Solid Program The Cyber Security Roadmap The Experts Roundtable A Cyber Farewell


About the Author


A Letter to the Reader Dear Reader, There was once a time when a business’s worst nightmare would be a group of clandestine and hood wearing thieves smashing a window, cracking the safe or cash register, and making away with a pile of hard-earned cash. But times have changed. The threat landscape is significantly different, as well as much more sophisticated and aggressive. Now, and scarier than ever, a welltrained and computer savvy thief can enter your business while you are literally sitting at your desk and obtain extremely sensitive and protected information and, with the click of a few buttons, open the flood gates and release client information, credit card numbers, Intellectual Property, trade secrets, and other content that could cost your company time, effort, and endless amounts of money. The masked bandits have been replaced with calculated and infiltrative computer hackers that can rob you blind while looking you directly in the eye. We call them cyber security thieves. A cyber security breach can put an organization out of business, or at the very least cost it tens, if not hundreds, of millions of dollars. And that may pale in comparison to the significant damage to brand and reputation. The Board of Directors and the Executive Leaders of the organization are responsible for the success of the business. As such, they should anticipate and be prepared for any future events that could significantly impact the organization. One of those events is a cyber security breach. The Board of Directors and C-Suite Executives face an enormous challenge: a limited understanding of cyber security business risks, the full financial and business impact a breach can have, analyzing and evaluating the right level of investment to protect against these threats, and where and how cyber security should be managed within the organization. The goal of this book is to help you gain an in depth understanding of each of these significant areas, while learning exactly what steps


you, as a leader, can take to properly prepare your organization to face today’s constantly evolving threat landscape. My name is Phil Ferraro, and I am one of the top Chief Information Security Officers (CISO) in the country. For over 15 years as a CISO, I protected and defended organizations against the world’s most sophisticated cyber attackers. I give international keynote talks on all aspects of cyber security, and I am one of the few CISOs in the country asked to present on Capitol Hill on cyber security and advanced threats to Senate and Congressional committees. In short, I have seen it all. While serving as a CISO in the Federal Government, in the Department of Defense, Intelligence Community, and the Federal Communications Commission protecting the nation’s most sensitive national security information, I developed and implemented cyber security programs designed to protect and defend against the world’s most sophisticated attackers. And I am confident my experience and education can greatly benefit you and your company. Following nearly 30 years of government service, I served as CISO in Fortune 500 companies developing and building comprehensive global cyber security programs. In October 2014, I was presented with the prestigious Top 10 CISO Breakaway Leader Award that celebrates world-class information security leaders, and honors CISOs and senior security executives whose leadership elevates their people, partners, and business. Most books on cyber security focus either on technologies or a very speculative high-level approach. The technology approach is written for CISOs and below; the hands-on operators and what technologies they need to implement. The high level approach gives you a 50,000-foot view and then describes the threats to organizations and couches them in great fear, uncertainty, and doubt. Those books do not take the time to provide the level of details needed to understand the overall concept and sensitivities found within cyber security, how it can impact an organization, and what can be done


about it right now to ensure your business is protected against future threats. Since this book is written by a world class Fortune 500 CISO with many years of presenting to and advising Boards of Directors and CSuite executives, you’ll quickly find an inside the trenches approach to handling cyber security breaches before they actually occur. There is clear and concise information that executives need to understand cyber security and develop comprehensive cyber programs. This book will help readers immediately take the information and apply it to their own organizations. Comprehensive cyber programs include a large number of functional areas, and you will find that this book cuts through the fog and provides a clear picture of where and what to focus on to effectively manage cyber business risk. I am confident that reading this book will be an excellent investment of your time and money. This is one of those books that, after reading it, you will keep close and refer back to often, as you would a reference book. You’ll also learn a great deal about the cyber security industry, and exactly how some of the most well-known breaches of information actually occurred. From these stories you will learn valuable lessons that you can then implement into your organization to prevent it from appearing in a scandal on the frontpage news. You will gain a much better understanding of the cyber security threats targeting your business and your industry, why all these big companies are getting breached, and what you can do to significantly lower your risk and raise your security so as not to become a victim. You will also learn what you must do as a senior executive to implement a comprehensive cyber security program, how you can start your plan immediately, what the full impact and financial effects of a breach are and the damage caused to organizations, and you will determine the necessary steps to manage a cyber security crisis. Finally, you will gain access to one of the top cyber security experts in this country who can assist you in


developing your strategic plan and goals for protecting your organization. We now live in a world with cyber-threats around every corner. Even one small data breach can be catastrophic to your business. But preventative maintenance is not nearly as difficult as you think. Investing a little bit of time and money now can be the difference between success and ultimate demise. So together we can overcome the new generation of thieves who can literally rob you blind while wearing their pajamas and sitting in front of their computers.


Chapter 1:

Are You Next?: Assessing Your Internal Risk The New Age of Infiltration Times have changed. Significantly. For generations and decades before, we were concerned with a man in a hooded sweater throwing a rock through the front window of our business and cleaning out the cash register. But a far more frightening and unexpected threat has replaced the old smash and grab. Now, the most deadly and detrimental action to impact your business can occur at the hands of a guy sitting at his computer in his pajamas half way around the world. Now all it takes is a highly specialized set of skills and an Internet connection to bring your business to its knees. And the worst part: you will never see it coming. There will be no DNA, no fingerprints, and no video of the culprit. This thief will infiltrate your business through the closed circuit back roads of the Internet, leaving no sign of entry or exit. Scary, right? In 1983, a young computer hacker, while sitting in his bedroom and thinking he was playing a game, almost brought the country to a nuclear World War III with Russia by hacking into the US Department of Defense computer systems. True story? Actually, this was only the movie War Games. But the scary part is that reality is now mimicking art. The imagination of these writers is now within the realm of the ability of hackers across the world. A simple movie has awakened the senses and pushed countries to create security infrastructure to protect against these potential tragedies. In 1989, a college student named Robert Morris, son of an NSA computer scientist, wrote a program designed to hack into every computer connected to the fledgling Internet of that time and then replicate itself. This program, now well known as the Morris Worm, nearly took down the entire Internet. But this was just the start of a


huge proliferation of malicious software, known as malware. Antivirus vendors claim that there were over 317 million new pieces of malware created in 2014 alone. The Evolution of the Invisible Thief The threat landscape has significantly changed over the past several years. We used to worry about script kiddies, young boys and girls sitting in their bedroom or basement trying to hack into companies just for the challenge and fun of it. They would hack into company websites and deface them, and put images of their hacking name or club on the website simply to gain street (or in this case Internet) cred. The bigger the company you hacked, the more underworld fame you received. But others, who were more malicious, would create viruses that would spread through companies and across the globe like wildfire. They would send these viruses out in the form of email attachments. Their satisfaction came in watching the total number of infections around the world. The higher the number of infected systems, the greater satisfaction they received. Hackers would compete against one another to create bigger, faster, and stronger viruses. Some would create malicious viruses that would actually delete files. As their abilities developed, they realized that in addition to the fun and excitement of hacking, they could also start profiting by stealing user’s personal information for gain. While attempts at these types of things still occur today, even the most basic of security tools in an organization can generally protect against and prevent them from happening, as the methodologies used are now considered very basic. Antivirus and antimalware programs all detect these kinds of attacks…provided your IT administrators keep these systems up to date with the latest signature files. We have come a long way from the days of script kiddies, web defacements, and basic viruses. What currently keeps executives awake at night is the cyber espionage created by malicious actors. They come in many different varieties and aim at externally


attacking organizations through insider information. They are very, very sophisticated, well-funded, and have large teams that work 24 hours a day, 7 days a week, 365 days a year. They simply will not stop until the job is done. In years past, the stealthy attacker would sneak into a network undetected and remain hidden in plain sight all the while siphoning off company data bit by bit. Unbelievably, a 2013 study showed the median number of days attackers were present on a victim network before they were [1] discovered was 229 days, down from 243 days in 2012 . That’s seven and a half months of holding information hostage on a company’s network while simultaneously stealing intellectual property, trade secrets, Personally Identifiable Information (PII), Payment Card Industry (PCI) or other sensitive, protected, and extremely valuable information. As of the printing of this book, we are still seeing advanced attackers that have been on a victim’s [2] network for 6 – 7 months before their discovery. For example, in the case of the recent Target breach the attackers were only on the network for approximately 3-1/2 weeks, yet were able to steal 40 million credit and debit card records and another 70 million records containing PII, a shocking number in and of itself. More often than not, when an attacker is detected after a lengthy stay on a network, that discovery is made through an external third party, such as the US Federal Bureau of Investigation (FBI), and not the victim organization. These Government agencies are constantly [3] hunting on the Internet or “Dark Web” , or are working to detect malicious command and control communications to and from the victims’ systems and malicious Internet Protocol locations. In fact, nearly 69% of organizations breached were notified by an outside [4] entity rather than discovering it themselves. Leading the way in these sophisticated attacks are nation-state attackers, often referred to as Advanced Persistent Threats (APT).


Quite often, we hear in the news about state sponsored terrorism. Cyber attacks are just another form of that. Effectively, it is state sponsored cyber terrorism. And don’t believe that they only go after government agencies and defense contractors. They target all companies in all industries. Another very capable group of attackers are called Hacktivists. You might have heard of groups with names such as Anonymous, Lulzsec, and others. These groups also target companies in all industries but usually because they disagree with the companies’ ideology, policies, or maybe the color of a company logo. There’s no rhyme or reason as to who or where they attack. But remember, there’s a big difference between the APTs and the Hacktivists as to how they operate. The APTs will slip in quietly, remain hidden in plain sight, and siphon off intellectual property, trade secrets, sensitive business information, and similar types of data for their own gain; whereas the Hacktivists will breach an organization, find sensitive business data or potentially embarrassing personal information of executives, and then publish that information for the entire world to see. In later chapters, we will talk more about each of these groups, as well as other groups like organized crime, who like to break in and steal PII, credit card information, and/or Personal Health Information (PHI) to sell on the black market. A Real Threat Today the threat of a cyber breach is so high that no organization is safe. The cyber criminals have all the same security technologies that we have, and they use these technologies to develop malware that can evade detection. Although the attackers are very sophisticated with dangerous weapons and tools, a majority of the time they do not use these sophisticated tools because they are unnecessary to breach most organizations. Many companies think they are safe from intrusions by having firewalls, antivirus tools, and intrusion/detection prevention systems that will protect them. But


this couldn’t be farther from the truth. These security technologies alone are far from capable of stopping a determined attacker. In fact, most companies go so far as to help the attackers. They don’t just leave the back door open; they leave the front door wide open with no guard and a big welcome sign flashing over it. In today’s world there are three types of organizations: 1. Those that have been breached; 2. Those who don’t know that they have been breached; 3. Those who don’t want to know if they have been breached. Of these three groups, the ones who have been breached are actually better off. At least they are aware of how bad their security posture is and hopefully have taken the right steps to improve it. As times evolve, so does the amount of damage cyber-security thieves can cause. Those who don’t yet know they’ve been breached are in the most sensitive position, as they have failed to take the proper steps to understand their current risk posture and properly invest in a comprehensive security program. And by comprehensive I don’t mean relying on industry best practices, because industry best practices really are not anywhere close to the best. Businesses should go beyond best practices to have a chance of properly defending against real threats. And finally, the third group has their head in the sand. They are of the mindset that “I have never had a heart attack, so I never will.” But from past experience, I can tell you that it is not a question of if you will be breached, but when. Hacking used to be about the thrill and challenge. Today it is big business and it is growing rapidly. According to the 2015 Verizon Data Breach Investigations Report, there were more than 79,790 [5] security incidents in 2014 alone . This number may be on the low end as not all organizations report being breached. Do I have your attention yet? If not, let’s shine the light on your organization to determine your risk level. Is My Organization at Risk?


The short answer is yes. In the past few years, the frequency and magnitude of cyber-attacks on organizations has exponentially increased. Boards and C-Suite executives should recognize that cyber attacks are a persistent business risk and an everyday part of doing business in today’s world. Cyber attackers are targeting companies both large and small across all industries. To ensure your organization is properly protected, cyber security measures need to be a critical part of the board and CEO’s risk oversight responsibilities. Yet despite the news we hear every day of major cyber security breaches, there is a gap with many organizations refusing to take the steps to adequately address the organizational risk. One of the biggest challenges that organizations face in their cyber security risk is with the directors and senior executive’s lack of a detailed understanding of what cyber security is, where it should be managed within the organizational structure, and the impact cyber security can have to the bottom line of the organization. Too many executives see cyber security as an Information Technology (IT) function. One very important point to understand is that cyber security is NOT an IT function! While it is true that the IT Department implements the tools and technologies used to protect and defend the business, everything that cyber security does, or fails to do, can significantly impact the shareholder value of the organization. In short, cyber security is critical to the success of the organization. The board and the executive leaders of the organization should realize that a comprehensive cyber security program is required to reduce the level of cyber business risk. Without a comprehensive cyber security program, the organization is exposed to a significantly higher level of enterprise and financial risk. The board and C-Suite leadership should have a better understanding of the risk, the legal implications of cyber risk, and the full financial impact a security breach can have on an organization.


Organizations typically have a corporate structure that includes a Chief Operations Officer, a Chief Financial Officer, a Chief Human Resources Officer, Chief Information Officer, and other C-level executives who are experts in their specific fields who contribute to the overall business and success of the organization. Boards and CEOs wouldn’t think of building their organizations without having these positions. They are critical to its success and are experts in their respective areas. Cyber security also is critical to the success of the business. The C-level executive and expert responsible for cyber security within an organization is the Chief Information Security Officer (CISO). Yet, so often we see that organizations bury the CISO, if they even have a CISO, two or more levels below where he/she should be in order to be most effective to the business. The CISO role and responsibility is discussed in detail in a later chapter. The CISO should be a peer to the CIO, and they must form a strong partnership in order to be effective. There are some executives who think that rather than investing in a CISO and a cyber security program, they will just save the money and buy cyber insurance. While cyber insurance is a good idea (we will discuss it in more detail later), it will not prevent a breach nor will it recover all the costs of a breach. Cyber insurance will not help the company one bit with brand and reputation damage. It will not help with shareholder value significantly dropping subsequent to a breach, and it will not reimburse the company for lost revenue. What will help in all these areas is to have an experienced CISO who can build and manage a comprehensive enterprise cyber security program. A good CISO will have a well-trained Incident Response Team who can respond within minutes of detecting a breach to quickly contain it before it becomes serious. Assessing Your Risk So with that said, let’s take a look at what you need to do to assess the cyber risk of your company.


The Risk Assessment. The first step is conducting a strategic cyber security risk assessment. To this end, it is advantageous for the organization to bring in a 3rd party cyber security consultant who is an expert in cyber security risk frameworks. Ideally this consultant will be a former CISO, and will have the benefit of experience in both the federal government and Fortune 500 organizations. The consultant will base his/her strategic assessment on a proven risk management framework such as the National Institute of Standards and Technology (NIST) Cyber Security Framework. If you are in the Financial Services industry, then they would use a framework like the Federal Financial Institutions Examination Council (FFIEC) Cyber Security Assessment Tool, which is mapped to the NIST security controls. These frameworks provide organizations with a baseline set of industry standards that go beyond best practices for managing cyber security risk. They also assess the organization’s legal and regulatory exposure. In a later chapter we will discuss the components of a Request For Proposal (RFP) that you can use to source qualified consultants who can conduct this type of cyber security strategic assessment. Bringing in an external cyber security consultant to conduct a strategic assessment will determine the organization’s overall risk to the business as well as the current security program from a strategic perspective. Specific areas that should be assessed include, but are not limited to: · ·

Comparison of your program to an industry-leading program. Building a strategic plan to get your program to an industryleading program. · Reviewing how security decisions are made, tools are procured, changes are made, and policies are enforced. · In depth review of network architecture (ingress/egress to/from the network, connections to/from your crown jewels, remote access, network segmentation, and wireless access to networks).


· · · · · · · · · ·

Review of Payment Card Industry (PCI) infrastructure and Point of Sale (POS) systems. Review of applications on the network, dependencies, communications between systems, and vulnerabilities. Review Identity and Access Management systems and controls in place, managed and operated. In depth review of security architecture from perimeter to endpoint (what tools / technologies exist, are they sufficient, and what is needed). Review IT Compliance programs, tools, and technologies. Review policies, SOPs, and training programs. Review cyber threat intelligence capability. Review Incident Response capability. Review network monitoring capability. Review cyber organizational structure.

The consultant, or your CISO, should then prepare a Cyber Security Strategic Plan which tells you what needs to be done, how often it needs to be done, and what resources are required. Once this Strategic Plan is prepared, your CISO can then operationalize it and immediately start raising the security profile of the organization while lowering the risk profile. This comprehensive strategic assessment is your first step in determining how at risk your organization is, and what needs to be done to immediately raise your security profile. Building Structure from Within To this point, we have discussed a general overview of cyber security threats and the potential carnage they can create within your business. We then discussed assessment tools and evaluating the risk found within your own organization. Now, we will shift our attention to the steps your business leaders can take from the inside out to ensure you are guarded and protected against substantial threats. As with other business risks, cyber security risk must be managed and driven from the top down and at the C-Suite level. To be able to do this effectively, directors and C-Suite executives must


have an in-depth, leadership level knowledge of cyber security and exactly how it impacts the business. Risk is a constant across all organizations. Each business must determine its level of risk appetite, or in other words, the amount of risk the business is willing to accept. With risk comes rewards, but there is a point at which accepting too much risk, particularly cyber risk, becomes dangerous to the business and could result in egregious damage. Some businesses, such as startups, might be willing to accept much more risk than others. The board must determine the level of risk it is willing to accept and also the level of risk tolerance, or variance to the risk appetite. Determining and approving the level of risk is a core function of the board. Often boards delegate risk oversight to an audit or risk committee; however, these committees often lack the experience, support, or skills necessary to properly understand and address cyber security risk. Often the CIO is asked to provide information on cyber security, but CIOs are technologists responsible for keeping the lights on for all IT systems, applications, and infrastructure, as well as developing new technologies that support the business. They typically are not experts in cyber security, nor do they have the level of hands on experience with cyber security that would allow them to expertly advise the board or a risk committee. Because of the significant impact that a cyber risk can have on shareholder value and the financials of the business, it is advisable that risk oversight is a function of the full board. While the New York Stock Exchange imposes certain risk oversight to audit committees, the rules say that the audit committee is “not the sole body for risk” and that they are to “discuss policies with respect to risk assessment [6] and risk management.” The CEO should make cyber security one of the business’s strategic goals and priorities. This needs to be communicated clearly to all leadership, lines of business, and employees throughout the organization. It might require a culture change in the company. This


change must start at the top. Make security everyone’s responsibility. We will take a closer look at this in the next chapter. Cyber-Screwed Still don’t believe cyber security is an essential part of any business? Well, wait till you hear what happened to those companies that weren’t believers either. There are many reasons why malicious actors conduct cyber espionage. Sometimes the purpose is military or defense related, but more often than not is for commercial gain and profit. They want to steal your intellectual property, trade secrets, and sensitive business information. Rather than spending millions of their own dollars and many years of research and development, they can easily and effortlessly steal the information, and then manufacture the technology cheaper and faster than their competition. There are several examples of organizations who have gone out of business subsequent to a cyber breach and loss of Intellectual Property, but one of the best known is that of Nortel Networks. Once a Fortune 500 company and North America’s largest manufacturer of telephony equipment, they were breached by an Advanced Persistent Threat who remained hidden on their network for several years and stole their most sensitive data. Hackers working from Chinese IP addresses used seven passwords of Nortel senior executives, including a former CEO, to gain full access to all Nortel [7] networks owned by the company . In 2004, Nortel’s senior IT Security person discovered company data being sent to an Internet Protocol address in China. Further investigation showed that the attacker had been on the network since 2000, or possibly even earlier. Executive management failed to heed the advice of their CISO or provide him the needed cyber security resources. The company took little action to properly protect and secure their networks, data, and most importantly, their Intellectual Property. Executive guidance sent orders down the food chain to simply reset the passwords. For nearly ten years, malicious


attackers had access to everything on the Nortel networks. They downloaded research and development data, technical papers, schematics, business plans, corporate executives’ email, basically anything they wanted. All they had to do was figure out exactly what they wanted to take. Interestingly enough, during that time frame a Chinese telecommunications company, Huawei Technologies, with ties to the People’s Liberation Army (founder Ren Zhengfei was an engineer in the PLA and Huawei has many contracts with them) grew from a small provider of phone switches and phone products to the world’s largest telecommunications equipment provider. In July of 2000, Nortel’s stock hit a peak of $124.50, but by January 2009 it had dropped to 39 cents. After years of losing market share to Chinese companies, the former Fortune 500 Company filed for bankruptcy and is no longer in business. Nortel remains a good example of a business with its head in the sand, and one that took almost no preventative measures to ensure they were protected. They literally did nothing other than the basic firewalls, intrusion detection systems, and endpoint antivirus. Now let’s look at an example of a company, the Las Vegas Sands Corp, which waited too long before deciding that they needed to [8] improve their cyber security. The attack on the Las Vegas Sands was the first major destructive attack by a nation state attacker in the history of the US. Months later, this was followed by the destructive attack on Sony by North Korea. There is a strong probability that both of these attacks could have either been prevented or contained so quickly that any damage or loss of data would have been minimal. In both cases, the Board of Directors and the C-Suite executives should have made cyber security a high priority for the organization and implemented leading-edge technologies to protect the business from these kinds of attacks.


It was Sunday morning on February 9, 2014, and the sun had yet to rise. The Chief Information Security Officer for the Las Vegas Sands Corp, the world’s largest gaming organization with integrated resorts and convention centers in Asia and the US, was enjoying the last day of a rare weekend getaway to Park City Utah when his cell phone rang. It was the Vice President of Information Technology from one of the Sands properties in Bethlehem, PA. “We’re having some serious issues with email and several other systems. Can you help us please?” The CISO asked several questions and knew right away that it wasn’t an IT systems failure. The worst had just happened, and he was six hours from command central. He immediately jumped on his laptop and set up a conference call with his team and the IT team in PA. Just several months earlier, the board and senior executives at Sands realized that having IT implement best practices for cyber security was probably not the best approach, and so they elected to create a CISO position and build a real cyber security program. Shortly after coming on board, the CISO conducted a detailed global cyber security strategic assessment, and presented the results to the board of directors. It wasn’t pretty. This Fortune 200 Company that processed billions of dollars of transactions a day was extremely vulnerable to cyber-attack and exploitation. The board and the company President and COO said they’d provide whatever resources were needed to fix the problem. Hiring qualified and experienced cyber security personnel is not easy. There is such a huge demand for these men and women that attracting them to Las Vegas would be a real challenge. Additionally, the majority of security related tools, e.g. firewalls, IPS, endpoint protection, web proxy servers, etc., were legacy systems not capable of defending against present day threats. About the same time Sands hired one of the top CISOs in the country, they also hired one of the most well respected CIOs in the nation to transform the IT infrastructure into a modern, agile, innovative IT infrastructure. The CIO also completely understood the


importance of cyber security to the success of the business and made cyber security a top priority for IT. To be effective, the CIO and CISO, as they were in Sands, have to have an outstanding partnership, working hand in hand to protect and defend the business. At the time of the Sands attack, the CISO had only been able to hire about 50% of the staff needed to stand up and operate the Security Operations Center (SOC), and the correlating tools purchased with end of year funding were just arriving and not yet deployed. Fortunately, the CISO had served many years in similar roles for the Department of Defense, and immediately stood up a Crisis Action Team that included the C-Suite and the IT VPs from all locations. One of the first steps the CISO took was to cut off all Internet access to and from all Sands sites to prevent any further data from being stolen, and to cut off any command and control by the attacker. He also ordered the connectivity between sites cut to prevent the malware from spreading internally from one site to another. But even with this great effort, it was too late. Malware had already started propagating from PA to Las Vegas. Urgently, they had to stop the malware from getting to the extremely high revenue producing properties in Asia. If not, Sands could be doomed. As details trickled in, it appeared that this attack was destructive in nature. The attackers gained full control of the network in PA and accessed a domain controller. They launched a very destructive piece of malware that erased all partitions on the hard drives of servers and workstations. System after system crashed. To make matters worse, the attackers breached and defaced the Sands websites, which were hosted by a major cloud service provider.

How could this even happen? The CISO had previously faced the most sophisticated nation state attackers in the world. They normally were not destructive in nature. To date, no other US business had been the victim of such a destructive attack. The CISO called his contacts in the FBI, US Secret


Service, and other Government agencies to seek their assistance. He brought in a third party vendor to augment his SOC so they immediately went into 24/7 operations. He then brought in forensics experts to assist in the containment and mitigation. Concurrently, the CIO similarly called in experts from Microsoft and other organizations to augment the IT departments globally, which also went to 24/7 operations. As word leaked out to the press about the breach, the regulators, merchant banks, customers and everyone else demanded answers from the Sands. Was data stolen? If so, was it PII, PCI, financials? Were gaming systems breached? The teams worked through many scenarios and eventually obtained the identity of the attackers. It was a nation state attacker, more specifically, the Iranians. Could this be true? The CISO met with the government agency task force and they confirmed through separate sources that it was indeed a malicious nation state attack coming from Iran. In October 2013, Sands Chairman and CEO billionaire Sheldon Adelson was sitting on a panel at Yeshiva University in New York, partaking in a conversation entitled: “Will Jews Exist?” The discussion turned to the Iranian nuclear program, and Adelson made comments that a nuclear weapon should be dropped in the Iranian desert, and demand that Iran shut down their nuclear program or [9] the next one would be dropped on Tehran to wipe them out . Iran’s Supreme Leader did not take Adelson’s comments lightly. A few months later, a hacking group from Iran started the attack on Sands. Through the experience and leadership of the CISO and CIO, they were able to contain and mitigate the breach in four and a half days. This in itself is amazing considering the level of access the attackers had and the destructive nature of the attacks. Their quick actions prevented the attackers from reaching any of the Asian properties.


No gaming systems were accessed or impacted. While the breach was contained and quickly mitigated, it took another 4 to 5 months to rebuild systems and fully recover. The cost of the breach was between $40M and $50M! This attack would not have been successful had Sands made the decision to build a cyber security program six months earlier. But on the flipside of the coin, this attack would have been egregious and would have been successful in taking down the world’s leading gaming company had Sands not maintained the foresight to hire two of the top people in the country in their respective fields. The lesson here is that you cannot wait. You must take action immediately. Do your strategic cyber security assessment now. Make sure you have a qualified, experienced CISO and provide him/her with the necessary resources to protect, defend, and respond to any cyber threat. As we have seen, the threat landscape has significantly changed. From small sized companies to large sized enterprises, businesses in all industries are now targets, and are often successfully breached. You cannot afford to maintain the status quo. You must take action, and you must take it immediately. We’ve seen multiple businesses shut down from a breach, and have witnessed others lose tens to hundreds of millions of dollars for failing to properly protect their business. In the remaining chapters of this book, you will learn what the real vs. perceived threats are, gain a much clearer understanding of the full impact of a cyber breach, learn how to build a cyber security program tailored to your organization, and much more. Remember, the times of a low-rent thief smashing your window and emptying your cash register are no longer the norm. Now, more than ever, it is the highly trained and tech-savvy generation Y prodigy that is using his/her high-level computer skills to quietly sneak into your business, breach your security, and bring you to your knees. It is now time to exchange your alarm systems and double locked doors for a more advanced and secure security system. One


that is based on the changing times and the evolving threats: One that is rooted in cyber security.


Chapter 2:

From Top to Bottom: It Takes a Village to Prevent a Breach Where Does it Begin? It short, it literally takes a village to prevent a security breach. No one person alone can create or implement the infrastructure to stop a would-be hacker from overwhelming security measures and creating catastrophic carnage to a business and its reputation. The Board of Directors and the Executive Leaders of the organization are responsible for the success of the business. As part of that they must anticipate and be prepared for any future events that could significantly impact the organization. One of those events is a cyber security breach. In years past, cyber security was of marginal interest to boards and executives. Today it is front and center on their agendas; however, one of the biggest challenges that organizations face in their cyber security risk is with the Board of Directors and C-Suite Executive’s lack of understanding of what cyber security is, where it should be managed within the organizational structure, real versus perceived threats, and the impact cyber security can have to the bottom line of the organization. Too much of what is presented to boards and executives is based on fear, uncertainty, and doubt. As we discussed in Chapter 1, an effective cyber security program starts at the top and trickles down through the organization. First, the board must establish the strategic direction for the company’s cyber security program. Many senior executives ask the question: “How do we solve cyber security?” The answer is that cyber security is not a solvable type of issue. It is an ongoing and ever evolving business process. We want our businesses to be as innovative and progressive as possible. We want to provide as much convenience as we can for our customers, as well as our employees. Great advances


in technology and science are allowing us to accomplish these things as we incorporate these new technologies. However, with these new technologies come new vulnerabilities along with new attack vectors by criminals. To stay ahead of the attackers is a constant and ongoing battle. For this reason, cyber security must be on the agenda of every board meeting. CEOs must require a regular update from the CISO. Cyber security responsibility is a new role for directors and executives; one that they feel somewhat uncomfortable with because it’s an area of risk with which they are unfamiliar. But armed with the knowledge you will find in this book, you can develop and implement a comprehensive cyber security program that will lower your risk profile considerably. Think about your organization. Does your board have a member (or members) who maintains an in-depth understanding of cyber security? Do they understand cyber risks and how to properly address them? If not, your board might want to consider adding a well-versed director in cyber security and business risk management to provide a level of expertise currently missing on the board. This might be someone who has previously served as a CISO, or CSO if his/her CSO responsibilities included cyber security. Alternatively, the board might consider contracting with a cyber security expert on an as needed consulting basis, or create an advisory board position, a common practice in today’s market. In regards to cyber security oversight, one of the more important roles for the board is asking the right questions of the CEO and CFO. The questions the board might ask include:

Is our organization currently at risk? What is our risk versus security profile? The board must be informed of where the company is currently, where they need to be, and the plan of how to get there. · Is cyber security risk included in our business risk management framework? Cyber risk is business risk. The ·


·

·

·

·

·

· ·

organization must actively pursue mitigating vulnerabilities and liabilities to an acceptable level of risk. Do we have an established cyber security program led by a CISO who has been given the appropriate amount of resources to execute the program? The CEO must hire and appoint a CISO; preferably he/she is reporting directly to the CEO. The CFO must ensure that the CISO has a cyber security budget sufficient enough to hire the requisite number of staff, or outsource to a Managed Security Services Provider, and purchase leading-edge technology. How are we auditing the cyber security program? The program should be audited internally on a regular basis, and annually an external consulting firm should conduct a program assessment. Do we have an incident response plan that is tested and trained on regularly? The incident response plan is one of the most important parts of a comprehensive cyber security program. It must be fully documented including an annex that describes the roles and responsibilities for all senior executives during an actual breach. All executives, or their designees, must be trained regularly on the plan and actions to take during a breach. Do we have a cyber security strategic plan? The CISO should have and present a strategic plan to the board that outlines the roadmap to proactively protecting the organization from ever-evolving internal and external cyber threats. Do we have a security awareness training program? This is a team mission. Everyone at all levels of the organization must be aware of cyber threats, and must be properly trained on the do’s and don’ts of cyber security. Do we have current security policies in place? The foundation of the program lies with proper policy development and enforcement of those policies. Do we have cyber insurance? While cyber insurance won’t help with brand or reputation damage following a breach or loss


of shareholder value, it can provide reimbursement of many of the costs incurred during a breach. While the board might have ultimate responsibility for oversight of cyber security, it is a team effort. Everyone at every level in the company has responsibility for cyber security; particularly the senior executives who have responsibilities that directly contribute to the success of your program. Let’s take a look at some of their responsibilities: Chief Executive Officer (CEO) There were several very interesting results in a 2015 survey conducted by PwC of 1,322 business leaders across 77 countries. [10] These include: ·

CEOs are innovating and accelerating the impact of technology for their customers. CEOs say they are seeing real payoffs from these investments. They expect to take risks to operate within diverse and fluid networks; yet, · 45% of US CEOs say they are extremely concerned about cyber threats and data security (up 22% from the previous year). · 62% of this group says that cyber security is strategically very important to their organization. Tomorrow’s CEOs listen closely to their customers, the market, and the world in order to develop and refine their business vision, strategy, and goals to grow their business. They must incorporate cyber security into their strategy and goals to be successful. Chief Operating Officer (COO) The COO is another critical member of the organization’s cyber security program. The COO must have a more in depth understanding of cyber security than the CEO or board directors might have. As the chief of business operations, the COO must understand how cyber risks can impact business operations. For


example, if your company does a large of amount of revenue online, it would be advantageous if the COO understood what a Denial of Service attack is and what steps the CISO is taking to prevent such an attack. If your organization is in the retail space and has thousands of Point of Sale (POS) systems, wouldn’t it be good to know how the attackers of Target, Neiman Marcus, Home Depot, and all the others had their POS systems breached and what your CISO is doing to prevent that? The COO must know what the crown jewels of the organization are and where they are located. If he/she doesn’t know, then it makes it extremely difficult to protect them. This could be R&D information that you’ve spent years and millions of dollars developing, or it could be intellectual property, trade secrets, or maybe just very sensitive business information that gives you a competitive advantage in the market. Direct your business leaders to identify and locate this information and make sure it is provided to the CISO so he/she can properly protect it. The COO must know where the business is in terms of its cyber security maturity level. It is important to know if a major investment is required immediately, or if you are able to just make incremental updates to add in leading-edge technology to protect against new innovative attack vectors and prevent operational downtime. Also, the COO must understand the financial and reputation damage that a breach can have on the organization. The COO has oversight of and directs the company’s business operations. Often the lines of business leaders will report to the COO. This makes it incumbent on the COO to reinforce regularly to the business leaders the strategic importance of cyber security to the business and to make sure that the business leaders provide their full support to the CISO and the cyber security program. One reason we see so many companies vulnerable to a cyber attack is due to the disconnect between strategy and operations. The COO is in the perfect position to bring


these two together. The COO also plays a key role in the event of a cyber security breach. All the roles & responsibilities during a breach are discussed in a later chapter. Chief Financial Officers (CFO) Typically, the CFO is not considered a part of the cyber security team; however, CFOs play a significant role in the cyber security of the business. With today’s ever-changing threat landscape, the CFO must focus on cyber security and be a strong advocate for making critical investments that will protect the business's most valuable information assets. In addition to all their finance-related responsibilities, CFOs must have a strategic view of their organization’s cyber security environment in order to make better, well-informed strategic decisions related to the organization’s costs and budget. A major problem in many organizations is that the cyber security program is underfunded. Going back to the faulty thinking that cyber security is an IT function, the cyber security budget often falls under the IT budget. Because it is not the top priority for many CIOs, they fail to allocate the appropriate amount of resources. When times get a little tough, the first budget cut for a CIO is often security. This methodology is a recipe for disaster. Cyber security should not be under the CIO or in IT in the first place. The CISO should be a peer to the CIO. Regardless of where within the organization cyber security is, it should be its own department with its own budget that is separate from IT’s budget. The CISO should be responsible for the P&L of his department. The CISO must be able to understand and plan for CAPEX and OPEX, and build strong business cases for each investment. It is the responsibility of the CFO to establish this financial department and budget for the cyber security program. For general planning for the cyber security program, the CFO can plan on approximately 10 to 14% of the IT budget as the amount needed to fund the cyber security program. This amount could be reduced as the program matures. The cyber security budget will be reviewed and approved in the same manner as any other department, with one exception: These immediate


investments need to be a top priority. Waiting any amount of time could result in the organization being breached, as we saw with the Las Vegas Sands example in the previous chapter, which would result in exponentially higher costs to the business. The CFO also needs to understand the relevant SEC reporting and regulatory requirements relating to cyber security, and ensure the CISO has that same level of understanding and implements compliance to them in the cyber security program. It is important to review these policies closely, as the more costly breaches there are globally, the more exclusions insurance companies are going to put in into the policy. Today’s top CFOs save their organizations the embarrassment and financial impact of a breach by taking proactive steps to build a comprehensive cyber security program. The CFO is in a perfect position to advocate for necessary investments and provide the required resources that will assist the CISO in preventing a breach. Chief Information Officers (CIO) The debate on whether or not the CISO should report to the CIO or another C-Suite executive has been ongoing for years. Both sides will argue the pros and cons based on their personal experience or agendas. CIOs are getting fired due to major security breaches like we saw with Target. Part of Target’s problem was that they didn’t even have a CISO before being breached. Some might argue that the level of security does not go up or down significantly whether or not the CISO reports to the CIO or another executive. Rather than debate personal preference, let’s look at empirical evidence that proves that having the CISO report to an executive outside of IT actually does improve the organization’s security when measured against downtime and financial losses. [11] The 2014 Ponemon Global State of Information Security Survey states: · With more than 9,000 respondents from around the globe, the survey found that those organizations in which the CISO reported


to the CIO experienced 14% more downtime due to cyber security incidents than those organizations in which the CISO reported to the CEO. · And, when the CISO reported to the CIO, financial losses were 46% higher than when the CISO reported to the CEO. In fact, having the CISO report to almost any position in senior management other than the CIO (Board of Directors, CFO, etc.) reduced financial losses from cyber incidents. It can be said that the transformation of the CISO role in today’s world is similar to that of the CIO some 30 years ago. At that time, as organizations were adding in more and more technology, they created a CIO role. Unfortunately, they buried the CIO under business operations teams. Over time, as senior corporate executives realized the importance of the CIO’s role to the business, the position was elevated to the current point where many CIOs now report directly to the CEO, or in some cases the COO or CFO. You do not have the luxury of time to watch the CISO role prove its importance to the success of the business. In 2012, foreign hackers breached the State of South Carolina’s Department of Revenue and stole nearly 4 million social security numbers and 400,000 credit and debit card numbers. Subsequent to the breach, in October 2012, Governor Mikki R. Haley issued an Executive Order directing the state’s Inspector General to conduct an investigation not into the breach itself, as federal law enforcement was investigating that, but into how the state currently performed cyber security and to determine a way forward to improve it. In addition to internal state sources, the IG’s review also included interviews with experts from the private sector, the National Association of State CIOs, Multi-State Information Sharing and Analysis Center, Gartner, Deloitte, CISCO, University of South Carolina, and Clemson; CIOs and officials from six other states, including three states with experience in significant data losses; and cyber security literature from a variety of sources including, but not


limited to, CERT-Carnegie Mellon, Sans Institute, and Information Security Audit and Control Association. [12] In the IG’s report they indicated that cyber security tasks were being performed daily. Cyber security was, like many government organizations, under the CIO. The state IT Solutions Committee, which included CIOs of 18 agencies, agreed “There was a sense agencies were conducting mission critical INFOSEC [cyber security], but had little capacity to be proactive in an increasing threat and vulnerability environment.” The IG made six recommendations, which were subsequently accepted and implemented: Establish a comprehensive cyber security program; Establish a CISO position outside of IT to lead the development and implementation of a statewide comprehensive cyber security program; Establish a federated governance model – cyber security authority resting with the CISO to establish the program and policies and then delegate authority, as needed, to meet operational requirements, but still subject to oversight and audit; Designate a leader to take responsibility for proactively driving statewide cyber security issues while they created the new state CISO position and hired a new CISO into it; Establish a steering committee to expedite and provide oversight of the development of a statewide comprehensive cyber security program; Hire a consultant to assist in building the governance framework and in developing statewide cyber security implementation options. If we look at this example, we see they have successfully changed their model to make the CIO and CISO peers who report to a COO, and together they have successfully built a solid cyber security program that has not been compromised since the remodel.


As you can see, the CIO’s role in cyber security is still a critical one. The CIO and the CISO are partners. They must build a very good rapport and work closely together to make sure security and IT are aligned with the company’s business objectives as well as the risk appetite. This is best accomplished when they are peers and have an equal say in the discussion. The CIO must make cyber security a top priority and communicate that throughout his/her entire IT organization. He/she must direct their staff to work closely with the cyber security teams. The CIO’s teams are the implementers of security functions, whereas the CISO’s teams provide the governance, oversight, and direction of what security controls need to be implemented. For example, the CIO’s network engineers will manage the firewalls, but it will be the CISO’s security engineers who will approve any changes made to the firewalls. This is one example of how the security and IT check and balance system should work within an organization. The CIO will make sure that the IT developers and project managers include cyber security in all projects from the beginning of said projects in order to ensure that security can be built in rather than bolted on afterwards. Bringing in cyber security early on provides more accurate project timelines and budgets. Managing Risk Management Now that we have described the roles of the executives in relation to cyber security, let’s consider the best practices for executives in relation to the overall process of risk management. Some of these include: ·

Incorporate cyber security risk management into existing business risk management processes. Cyber security should not be considered a compliance checklist. The same approach taken for other business risk must be taken with cyber security. The same due diligence must be applied. Your CISO must work closely with your Chief Risk Officer, or


Turn static files into dynamic content formats.

Create a flipbook
Cyber security everything an executive needs to know 1st edition by phillip ferraro isbn 1988071208 by luiswood6684 - Issuu