What Every Business Leader
Should Know About Cyber Risk
As a nonprofit professional association with 125,000 certified cyber, information, software and
infrastructure security professionals, (ISC)2 and its members are working to raise awareness
of what occurs on the front-lines of cybersecurity practice to ensure a safer and more secure
cyber world. This paper shares their perspective on five fundamental areas that will help busi-
nesses take back control of cyber risk and be better prepared for the unknown.
Introduction: Cyber Risk is a Business Risk
Rapid adoption of technologies is transforming the do harm. Businesses and organisations have as a result
business landscape at a relentless pace. The pressure found themselves dependent on new capabilities long
is on to reap the benefits of connecting every before they have developed a clear understanding for
system, however sophisticated or simple, from the how they are leaving them vulnerable.
high-profile innovations such as driverless cars, and
remotely connected medical devices to the tasks that For most organisations, whatever their size, cybersecurity
allow product fulfilment and inventory management has been a consideration. Preparations, however, are
across a vast and distributed network of retailers. not standing up to the test of a real-world cyber-attack
It’s a transformation that reaches far beyond the or reflecting the impact being felt. This is because
systems themselves to enhance what people can information and cyber risk remains poorly understood
achieve and their levels of independence, delivering outside of the information security profession, limiting
huge productivity gains and new opportunities the commitment and ability to robustly quantify the risks.
for organisations. High-profile examples of incidences demonstrate this
daily, while companies are increasingly exposed to harsh
Unfortunately, the transformation comes with new risks press and regulatory scrutiny: Recent attacks forced the
as hostile individuals and groups have also exploited cancellation of non-emergency treatment across many
the changing landscape for nefarious purpose. Such NHS Trusts; Tesco Bank customers were defrauded of £2.5
threat actors have the skill, the motivation and the million1; Chrysler was forced to recall 1.4 million hackable
time to research targets, craft and launch attacks, cars2 and there are many other examples that can be
and are contributing to an evolving and proliferating cited. In all these cases, customer service, reputation and
threat landscape that has become both increasingly operations were severely disrupted. Smaller companies
sophisticated and easy to access by those that would too, are targeted as part of the supply chain of larger
[1] [Link]
[2] [Link]
What Every Business Leader Should Know About Cyber Risk
organisations or for having less sophisticated defences, On average, organisations suffer over 100 targeted
and often the attacks are not targeted, just aimed at cyberattacks a year. One in three of these attacks — an
those that can be penetrated. average of 2–3 every month — are successful.6 The
lessons being learned from current breaches are that
Reported breaches are now 60 times what they were a cyber risks do not just affect IT systems, but are also a
decade ago3, while Lloyds of London4 estimates a contributory factor, and even enhance the likelihood of
serious cyberattack poses a financial risk to the global business or physical risk. One incident from the steel
economy equivalent to that of a superstorm such as industry resulted in significant damage to a factory and
Hurricane Katrina. Cybersecurity cannot remain the blast furnace in Germany, when hackers successfully
concern of the Chief Information Security Officer (CISO) breached office systems that opened a window to
alone. Business leaders must rather move to work with production systems.
their CISO and overall security resources to actively
gauge their new dependencies, and the investment in The challenge of securing organisations therefore goes
risk treatments that are warranted. beyond the resources of cybersecurity professionals and
the small pockets of deeply technical experts that
To begin the process, we offer five action points to follow: analyse the threats. A holistic understanding of both the
nature of the cyber risk that your organisation faces and
1. Accept cyber risk is a business risk
the potential impact on your business is needed to
2. Align cyber spend to your risk guide the necessary treatments.
3. Create a culture that prevents vulnerability
The impact of breaches can include loss of revenue,
4. Get control of data intellectual property (IP) and customer data, as well
5. Ensure security and privacy are ‘baked in’ as reputational damage and loss of consumer trust. Such
to processes broad and varied concerns call for a fundamental
1 Accept Cyber is a Business Risk
Traditional business risks, such as failed product launches
and physical damage to assets are typically believed
to be far more potent and tangible than cyber risk. What
organisations fail to see is that a cyber event can have a
similar impact. For example, TalkTalk did not devote the
same attention to cyber risk as to other business risks and
failed to notice a critical vulnerability in its systems for
which a patch was publicly available. This oversight led to
a criminal cyber-attack, a record-breaking £400,000 fine,
the loss of 95,000 customers and ultimately cost TalkTalk
over £60 million5 as its share price tumbled.
[3] [Link]
[4] [Link]
[5] [Link]
[6] [Link]
What Every Business Leader Should Know About Cyber Risk
2
realignment in the way business risks are managed and
prioritised and a comprehensive assessment right across
Align Cyber Spend to Your Risk
the business.
(ISC)2’s Global Information Security Workforce study7 has
reported increasing security department and IT security
To make this fundamental realignment budgets for over a decade. Hiring of security personnel
happen, business leaders should: is also robust with 70% of hiring managers around the
» Acknowledge that cyber risk exists as a world participating in the survey planning to add to their
current and high-level threat to their business teams in the next 12 months. Despite this investment,
» Debunk the perception that information our Workforce study shows that since 2013 there has
and cyber risk is a technology problem to be been a declining global state of security readiness with
managed by the information security and organisations taking longer to recover from a breach
IT functions and often unable to identify the cause. Even though
they are armed with bigger budgets, cyber security
» Place cyber risk on the organisation
professionals are forced into a ‘fire-brigade’ approach of
risk register
simply addressing security incidents when they occur.
» Create or enhance the governance Instead, business leaders at varied levels must work with
framework to include cyber risk management
security professionals to proactively assess specific risks
» Bring the CISO into all risk discussions to their organisation, project or function, not just the
» Identify the key operational dependencies systems, to develop a robust understanding of the most
and prioritise resource for protection appropriate and level of resources required to mitigate or
manage them.
[7] [Link]
What Every Business Leader Should Know About Cyber Risk
Create a Culture that
3
There is no one-size fits all solution. Organisations
must develop their corporate ‘cyber literacy’ to Prevents Vulnerability
reflect the context of their industry, their business
Organisations require a dialogue that ensures
and their organisational culture. This provides the
cybersecurity is broadly appreciated as being more than
framework for managing the inevitability of a breach,
an IT or specialist concern and plugs into the business
including assuring a consistent and desired standard
acumen that is driving its success. This dialogue should
of response. It provides the guiding principles to help
cover how the organisation, its products, services and
identify, for example, key data assets, how they are
business processes are evolving, and must be grounded
processed and stored, and the controls and levels of
in the terminology of, not just risk, but also ambition,
protection that should apply along with any relevant
development objectives, sector traits and so on. Business
insurance considerations.
leaders should regularly and actively challenge IT and
information security leaders on how organisation
Business leaders should challenge their
developments and innovations could open them up
managers and the CISO to:
to new risks.
» Use a consistent and robust methodology
to identify, treat and manage cyber risks IT and security leaders must challenge the business to
» Highlight critical systems and data communicate not just their requirements, but also their
aspirations for how systems will be used by people,
» Assess regularly the vulnerability of those
employees and customers, so everyone can gauge
critical systems and data against an
potential risks. This is a two-way street: as much as
evolving technological landscape
information security leaders can push this dialogue,
and threat
business leaders must make time to listen, comprehend
» Implement cyber risk treatments and and discuss the risks so that everyone can fully develop
measure their performance over time their understanding.
» Show how risk treatments are effective at
reducing risk, through metrics, KPI or KRI Over time, an appreciation of the motives for attack,
the known habits and design flaws that introduce
» Demonstrate how investment is matched
to risk vulnerability, the trends prevalent within their sector
and the like, add to the organisation’s overall resilience.
» Link cyber risk to organisational
This goes further than the need to develop user
frameworks such as Enterprise
awareness: engineers and department managers
Risk Management
must develop the instincts to ask the right questions,
» Invest in technology and expertise to identify requirements and provision solutions when
assess and manage the measures taken by and where relevant. For example, software engineers
partnerships and suppliers to maintain a
must anticipate security requirements, including the
level of cyber security proportionate to the
potential for misuse, not just usability, as part of the
identified risk
design and understand how to commission relevant
» Prepare, and regularly rehearse, ‘stress tests.’ Risk managers must be able to calculate
organisation response to cyber events in a costs against anticipated impact within the right
way that reflects the value of the data or context: A data breach at a healthcare organisation
systems breached and the potential impact
will likely produce a different cost equation than one
on their organisation.
at a chocolate factory. Eventually, every business unit
What Every Business Leader Should Know About Cyber Risk
should proactively build up a specific understanding of
how their organisation, or their latest innovation, might Building a culture does not happen
be vulnerable. overnight. However, business leaders can:
» Emphasise cyber risk in all their discussions
A good place to start this dialogue is with the human
» Encourage cross-departmental cyber
vulnerabilities, as this affects all employees. A common
security collaboration
and fast-growing technique, ‘phishing’ attacks, most
often in the form of fraudulent emails, lure employees to » Build awareness and education about
cyber risks into all the training materials
click on a link that could launch a malicious piece of
of the organisation
software, share sensitive information, or even transfer
» Link objectives, bonuses and pay to
money. In 2016, the CEO of Austrian aerospace parts
the identification and management of
manufacturer FACC, lost his job when he failed to spot
cyber risk
an email scam that cost his organisation $47 million8.
» Set expectations that all projects, business
The development of digital profiles across social
cases and initiatives address cyber risk and
networks means everyone can be effectively targeted. have consulted with the CISO
Training should be designed around the relevant
» Question and require regular reporting
concepts that apply to an individual’s job. Finance can
and updating from direct reports, the CISO
be tested on their ability to identify fraudulent attempts and other stakeholders on the cyber risk
to transfer money, and all staff can learn to recognise a status of the organisation
genuine email from their HR department. As everyone is » Mandate the creation or use of a cyber
effected, the effort to raise awareness around phishing risk governance framework, management
attacks opens the door to broader conversations about standards and methodologies.
cyber risks.
[8] [Link] [Link]
What Every Business Leader Should Know About Cyber Risk
4
principles and rules that will form the expectations of
Get Control of Data the future for doing business responsibly, and
competitively, while also creating a pathway for
Due to the ease of collection and the cheap cost of
expressing clearly the harm to a business, customer, or
storage, many organisations harvest as much information
society should a malicious or accidental incident occur.
as possible without properly defining its value or how
Customers rightly expect that organisations will take
they intend to exploit it. Harvesting, storing and sharing
good care of any information they share and any
information has to date been both technically easy
and low-risk. Yet the task of tracking and protecting organisation that can demonstrate that good care may
it is increasingly difficult. According to the Veritas be able to convert it into competitive advantage or into
Global Databerg report9, 85% of data held by European new products and services.
organisations is either redundant or has no known value,
leaving only 15% considered as business critical. Against To get control of data, business
this background, data exfiltration — the copying and leaders can:
theft of data — has become the number one concern for » Use legislation and regulation to ‘clean
201710 within security professional communities around house’, i.e. challenge why data is being
the world. If an organisation is ever to manage its cyber retained and push for old or out-of-date
risk, it must understand what information it collects, data to be deleted
processes, transmits, stores and destroys by assessing its » Identify information that is critical to the
information risk. business and discover where it is stored
» Identify information that may be subject to
Governments are increasingly coming to this legislation or regulation
conclusion and mandating the responsible use,
» Instigate projects to improve data quality
management and protection of data that is housed on
an organisation’s systems and within their products. » Ensure that relevant risk treatments are
Penalties are set to escalate in May 2018 when the
aligned to the value of data
European Union’s new General Data Protection
5
Regulation (GDPR) comes into force with fines set at
up to 4% of worldwide turnover and new rights for Design in Security, ‘and Privacy’
individuals leading to further costs and penalties.
The lack of understanding of cyber risk means that too
GDPR not only requires organisations to know about
many businesses continue to build, buy or use their IT
a significant sub-set of their data — that which has
without security in mind, thereby increasing their risk.
personally identifiable attributes for any EU citizens
— but also demonstrate that they have a legal basis Security must be designed into products and services,
to store it, use it, and are both managing and securing the strategic direction taken with IT systems, employee
it properly. policies and more. The consequences of not doing so
were aptly demonstrated when an attack exploited
This presents a clear need – and opportunity – to idle computing capacity to be found in internet-
identify information that is of value to a given business connected toasters, refrigerators and other appliances,
unit or process and eliminate the rest. It sets out to bring down much of America’s internet11 and the big
[9] [Link]
[10] [Link]
[11] [Link]
What Every Business Leader Should Know About Cyber Risk
companies that relied on it, including Amazon, Spotify, Organisations should bring security expertise into the
Netflix and the New York Times. beginning stages of any development to deliver robust
risk assessments and treatments. Building security in, just
Relevant considerations for your organisation include: like creating a culture, takes time.
business processes; new technologies you plan to
embed within your environment; their connection to
Business leaders can take positive
legacy systems; how suppliers work with and contribute
action, using the following steps:
to this environment; connections to other environments
such as inventory; design criteria for contributed » Mandate a cyber risk assessment for all
components, who is involved at every step and how you new IT-related projects
will protect your customers’ information at every point in » Require all project managers to build
the customer journey. in regular cyber risk reviews and
include cyber risk in major project
Many organisations simply do not understand review milestones
cybersecurity well enough to engineer their business » Adopt, where relevant, standards for
practices, systems and products so comprehensively, secure software design
leaving them heavily reliant on testing at the point of » Build in time for security testing
release of a new product or service. This not only limits throughout the development process
the scope of security assessment but also sets delivery » Halt projects where cyber risk has not been
teams up to resist implementing whatever results the adequately considered and remediate
testing turns up, as they introduce delay and often
» Buy in tested, secure products where
unanticipated cost as deadlines loom. The majority of
development is not considered viable or is
reported attacks exploit often well-known, but missed or outside the organisation’s remit.
ignored vulnerabilities.
What Every Business Leader Should Know About Cyber Risk
In Conclusion… Leadership is key About (ISC)2
The pace of change in today’s business landscape is (ISC)2 is an international nonprofit membership
increasing complexity and introducing new risks that association focused on inspiring a safe and secure
challenge our understanding of what good business cyber world. Best known for the acclaimed Certified
practice means in a connected world. It is time to set Information Systems Security Professional (CISSP®)
our organisations on a journey to becoming a resilient certification, (ISC)2 offers a portfolio of credentials that
thriving concern in this world. CEOs and Boards can look are part of a holistic, programmatic approach to security.
to the cybersecurity profession as advisors, managers Our membership, over 125,000 strong, is made up of
and fonts of front-line knowledge — but not as the front- certified cyber, information, software and infrastructure
line of accountability. Business leaders themselves must security professionals who are making a difference and
grasp the challenge, set the dialogue and motivate the helping to advance the industry. Our vision is supported
robust understanding and response required to stand by our commitment to educate and reach the public
the test of real-world cyberattack. through our charitable foundation — The Center for
Cyber Safety and EducationTM. For more information
Cyber risk is a business issue and responsibility, not just about (ISC)2 visit [Link], follow us on Twitter or
the domain of the experts. connect with us on Facebook.
References
(1) [Link]
(2) [Link]
(3) [Link]
(4) [Link]
(5) [Link]
(6) [Link]
(7) [Link]
(8) [Link]
(9) [Link]
(10) [Link]
(11) [Link]
© 2017 (ISC)2 Inc., (ISC)2, CISSP, SSCP, CCSP, CAP, CSSLP, HCISPP, ISSAP, ISSEP, ISSMP and CBK are registered marks of (ISC)2, Inc.