Proactive Cybersecurity
Proactive Cybersecurity
CYBERSECURITY
A Quick Guide to Understanding
Cyber Maturity
Foreword by ISACA®
P R O A C T I V E C Y B E R S E C U R I T Y : A Q U I C K G U I D E T O U N D E R S TA N D I N G C Y B E R M AT U R I T Y 1
FOREWORD
by ISACA
A
Gartner reported in a recent study that IT executives
ccording to a report from cyber threats. In general, the more mature your
see the talent shortage as the most significant
organization’s cybersecurity protective practices are,
Skybox Security, “Vulnerability the better equipped it is to prevent threats. adoption barrier to 64% of emerging technologies,
compared with just 4% in 2020.
and Threat Trends Mid- Maturity models provide the framework to measure
Even based on these results, it remains unclear for
the company in question’s level of maturity. Ratings
Year Report 2021,” the amount of are given for each domain based on its preparedness the time being how much worse cyberattacks could
to cyberattacks. These ratings often showcase potentially become in the coming years or how much
ransomware attacks grew by nearly which areas are sufficient and which are in need of these skill gaps could widen. But if IT leaders want to
correct organizational vulnerabilities amid the talent
20% and new vulnerabilities in improvement. A “0” rating indicates the organization
shortage, it may be time to start becoming a bit more
doing the absolute bare minimum to protect itself
operational technology (OT) devices while a “5” rating would suggest the company is proactive in their approach.
employing the best practices and controls to detect
increased by 46%. In the time of and prevent cyber threats.
To help you become more proactive and understand
cyber maturity to its fullest, we put together this
COVID-19, cybercrime is not only These assessments are crucial should an compendium containing the expertise and know-how
organization want to gain significant insights of leading cybersecurity professionals. Discover how
surviving, but also thriving. into their own security practices and their relative to build cyber resilience with risk-based solutions to
As digital transformation continues to accelerate at effectiveness. The results often can improve measure, assess and report on cyber maturity based
a rapid pace and the availability of the talent required communication between IT personnel and upper on current industry standards.
for such advancement decreases, cyberattacks are management and can be used to enhance existing And enjoy!
not likely to go away any time soon. and implement new cybersecurity protocols in lacking
areas.
So, what can organizations do to protect themselves
in an ever-evolving technological landscape that’s As far as when a company should take a
prone to further and further attacks? How ready are cybersecurity maturity assessment, there is no wrong
your cybersecurity defenses? The time to mature your time. However, many organizations are struggling to
operational cybersecurity is here. administer a maturity assessment or implement new
and/or recommended protocols and practices due to
Cybersecurity maturity is the term that refers to
the lack of available talent in the industry.
the ability and readiness of an organization to
protect itself against possible vulnerabilities and
P R O A C T I V E C Y B E R S E C U R I T Y : A Q U I C K G U I D E T O U N D E R S TA N D I N G C Y B E R M AT U R I T Y 2
Cyber Maturity and
Protecting Against Ransomware
SUBMITTED BY TOM CONKLE
CISSP, Optic Cyber Solutions
R
ansomware continues to Ransomware began with attackers simply gaining does not exist. Companies must take a holistic program. For starters, there are various industry The holistic approach for implementing a maturity-
access to, and encrypting, a company’s data. This view of their cybersecurity program and implement accepted cybersecurity guidelines, such as the based cybersecurity program, as realized in the
dominate the headlines enabled the attackers to sell a decryption key back capabilities across the entire program. National Institute of Standards and Technology CCP, enables companies to evaluate risks to
to the company to allow them to regain access to (NIST) Framework for Improving Critical establish tailored Target Maturity Levels. The CCP
in both cybersecurity company data. Ransomware has since evolved. One
Organizations need to defend their infrastructure
Infrastructure Cybersecurity (the Cybersecurity then translates these Target Maturity Levels into
on all fronts to thwart ransomware attacks. First,
method includes taking over a company’s access Framework), and the Center for Internet Security (CIS) Practices that can be implemented to mitigate
journals and mainstream media. control features and locking users out of systems
the organization must ensure the development
Common Security Controls (CSC). Additionally, there their cybersecurity risks to an acceptable level,
and integration of secure solutions within their
Companies of all sizes across until the victim pays the ransom. Attackers have even
environment. For example, when purchasing new
are many regulatory and compliance requirements including the risk of ransomware disrupting business
been known to weaponize regulators. After breaching across sectors, such as the Payment Card Industry operations. Additionally, the Model within the CCP
sectors are seeing continued company data and requesting payment, attackers
Software as a Service (SaaS) capabilities, companies
(PCI) Data Security Standard (DSS), the Health is updated bi-annually to ensure cybersecurity
should safeguard systems by changing defaults
will threaten to notify the regulators themselves if not Insurance Portability and Accountability Act (HIPAA), capabilities evolve with ever-changing threats and
increases in ransomware attacks. paid.
passwords, hardening configurations, deploying cloud
and North American Electric Reliability Corporation vulnerabilities.
protection capabilities (e.g., Cloud Access Security
This rise in attacks has resulted Attacks that lead to ransom payments being Broker (CASB)), and implementing Multi-Factor
Critical Infrastructure Protection (NERC CIP). There
Editor’s note:
are also tools, such as ISACA’s CMMI Cybermaturity
in companies paying out millions demanded have been realized through multiple Authentication (MFA). While each of these protections
Platform (CCP), that measure current cybersecurity
Find out more information about CCP here.
attack methods. One of the first ransomware attacks may not prevent a successful ransomware attack
capabilities and recommends specific solutions
of dollars or, in some cases, reported in 1989 occurred when an AIDS researcher alone, a multipronged approach to defending against
needed to mitigate organizational business risks.
distributed 20,000 floppy disks infected with malware ransomware reduces the chance of an attacker’s
failing due to the irreparable harm to attendees at a World Health Organization (WHO) success. The CCP tool includes 16 Capability Areas that
caused by the loss of ransomed conference. The malware has been used to exploit
Organizations also need to implement robust
represent a full cybersecurity program. Each area
known and zero-day vulnerabilities to allow access to assists organizations in defining cybersecurity
protective technologies to ensure systems are
data. Ransomware attacks will systems as a vector for ransomware. Malware used
routinely patched and vulnerabilities are managed.
capabilities needed to manage operational risk,
in ransomware attacks has been deployed through including the risk of a ransomware attack. The
continue to increase primarily due many methods, including social engineering attacks
Additionally, to provide a defense-in-depth approach,
CCP Cybersecurity Model (“the Model”) identifies
the organization must enable effective auditing and
(e.g., phishing), seeding parking lots with infected key proficiencies to help organizations prevent
to the successful monetization of USB drives, and even exploiting publicly available
logging to allow early detection of potential breaches
ransomware within its Capability Areas, including
that could lead to a ransomware attack. While an
attacks and because ransomware systems. Other forms of ransomware have occurred
attacker only has to be successful once to implant
System Trustworthiness and Protective Technology.
due to companies unknowingly leaving their data The Model also defines specific actions, referred
methods continue to evolve. exposed to the internet, allowing attackers to steal or
their ransomware malware, organizations must
to as Practices, that companies can take to detect
effectively defend their network at all times, across all
encrypt the data. ransomware before it spreads in the Incident
aspects of their cybersecurity program.
Detection and Continuous Monitoring Capability
Due to the variety of forms of ransomware and the
There are many resources available to assist Areas.
many ways it can be deployed, a single solution
organizations in defining a robust cybersecurity
P R O A C T I V E C Y B E R S E C U R I T Y : A Q U I C K G U I D E T O U N D E R S TA N D I N G C Y B E R M AT U R I T Y 3
ISACA’s CMMI® Cybermaturity Platform makes cyber resilience—and more effective conversations with your
With Your Board To learn more about the CMMI Cybermaturity Platform or schedule a demo,
visit [Link]/cmmi-cybermaturity-platform.
1 2 3 4 5
A
recent study from global Know your organization’s Communicate your organizational Know your security controls. Communicate security control needs. Show fiscal relevance.
cybersecurity risks. risks effectively. Understand what security controls Make sure that stakeholders are Boards need to understand what kind
technology association Ensure that you’ve identified and Understanding your risks is good—but are in place within the organization, aware when a certain control needs of financial commitments are required
documented all of the potential risks being able to effectively communicate ensure they are documented and more attention or funding. Gaining to support a mature cybersecurity
ISACA found that 87% of them to stakeholders is better. understand their efficacy. Don’t buy-in from leadership will ensure posture. Illustrating how cutting-edge
facing your organization. With strong
C-suite professionals and board communication and documentation, it Don't just tell leadership what the forget, security controls can take critical controls are maintained. cyber trends can impact the bottom
will be easier to obtain support for risk concerns are—provide context and many forms, from technical tools to Effective communication describing line may be the make-or-break factor
members lack confidence in mitigation efforts. illustrate potential effects in terms organizational processes such as the security control needs to the board for board approval.
of financial impact or damage to incident response plans, or people will help illustrate the importance
cybersecurity initiatives. How can your brand reputation. Ensure that such as physical security guards. of investing in these valuable
you talk to your board in a way you’ve identified and documented preventative measures.
all of the potential risks facing
that builds trust and gains buy-in your organization. With strong
communication and documentation, it
caused by the loss of ransomed will be easier to obtain support for risk
data. Ransomware attacks will mitigation efforts.
P R O A C T I V E C Y B E R S E C U R I T Y : A Q U I C K G U I D E T O U N D E R S TA N D I N G C Y B E R M AT U R I T Y 4
Genuine Parts Builds Improved Cyber Maturity with
ISACA's CMMI Cybermaturity Platform
®
G
enuine Parts Company
Genuine Parts needed to assess multiple units, The Solution "THIS VIEW PROVIDED ISO 27001 Informative Reference by Maturity Level.
demonstrate maturity that was aligned with the NIST Genuine Parts selected the CMMI Cybermaturity This view provided specific insights for measured
determined that its initial CSF, and specifically focus on demonstrating maturity Platform because of its alignment with globally SPECIFIC INSIGHT FOR vs. targeted maturity levels—an eye-opening
performance in managing risk; not just compliance- recognized standards, particularly the NIST Cyber experience and a rallying cry for achieving continuous
cyber maturity assessment based. Security Framework (CSF), as it is already an industry MEASURED VS. TARGETED improvement.
Genuine Parts customized the CMMI Cybermaturity benchmark with risk-based controls, as well as its
needed to create a baseline Key Performance Goals Achieved
Platform to target these specific areas for Informative References and alignments across MATURITY LEVELS - AN While the Genuine Parts Company Enterprise Security
against a common framework improvement in their assessment. the 20 CIS (Center for Internet Security®) Cyber
Team could not control the number of security
that aligns with NIST CSF and
• Apply governance elements Security Controls, COBIT Controls, ISA–62443-2-
1–2009 (Security for Industrial Automation and
EYE-OPENING EXPERIENCE incident tasks it received, it could control how it
• Apply risk strategy handled their resolution in a more efficient and timely
the ISO 27001 controls. Genuine • Implement risk management
Control Systems), ISO/IEC 27001 INFOSEC Controls,
and the federal controls NIST SP 800-53 Rev. 4 -1
AND A RALLYING CRY FOR manner.
Parts needed to assess multiple • Implement risk identification provide additional utility. To succeed, Genuine Parts
ACHIEVING CONTINUOUS Since the CMMI Cybermaturity Platform self-
determined that its initial CMMI Cybermaturity assessment in January 2020, they have:
• Ensure access control management
units, demonstrate maturity Platform maturity assessment model be:
• Apply data security protection IMPROVEMENT" • Reduced Mean Time to Task Resolution (MTTR)
that was aligned with the NIST • Apply organizational training
• Digital from nearly 24 days (23.9) over the previous three
• Risk-based quarters to an average of 6.5 days for the first two
CSF, and specifically focus • Ensure trustworthy systems
As Genuine Parts developed its customized risk quarters in 2020
• Provide a risk profile/map
on demonstrating maturity • Apply operational protection provisions
• Easy to use
profile, the descriptors for each frequency of
• Decreased the range of Backlog Days for Tasks
• Apply protection planning occurrence values led to invaluable discussions
performance in managing risk; • Customizable among the Genuine Parts senior leaders. Without
from as high as 117 days during the previous
• Apply protective technology provisions three quarters, to a low of six days for the first two
• Self-paced these definitions, calibrating their current state and
not just compliance-based. • Apply cybersecurity incident detection then defining improvement goals would have been
quarters in 2020
• Align to the NIST Cyber Security Framework (CSF)
• Apply continuous monitoring nearly impossible. Editor’s note: Read the full Genuine Parts case study.
Genuine Parts Company determined that its initial • Align to the ISO 27001 Controls for ease of self- For additional resources on cyber maturity, including
• Apply incident response assessment and improvement In addition, using the CMMI Cybermaturity Platform
cyber maturity assessment needed to create a a video on how ISACA’s CMMI® Cybermaturity
• Apply incident handling • Produce a roadmap for improvement Maturity Scorecard within each Practice Area
baseline against a common framework that aligns Platform helps CISOs, CIOs, and large enterprise
Assessment allowed employees to review and
with NIST CSF and the ISO 27001 controls. • Apply incident recovery organizations build cyber maturity, visit
understand the People, Process, and Technology
ISACA’s cyber maturity page.
(PPT) objective for each maturity level, and its relative
P R O A C T I V E C Y B E R S E C U R I T Y : A Q U I C K G U I D E T O U N D E R S TA N D I N G C Y B E R M AT U R I T Y 5