0% found this document useful (0 votes)
5 views17 pages

Cybersecurity Challenges in Business Optimization

Chapter 9 discusses the critical role of cybersecurity in Business Optimization (BO), emphasizing its importance in protecting customer data, trust, and overall business integrity. It outlines the dual functions of cybersecurity in BO: securing business processes and leveraging AI for cybersecurity intelligence, while also addressing the complexities and challenges posed by AI integration. The chapter highlights the need for a strategic, agile approach to cybersecurity that balances risks and performance, as well as the importance of understanding the psychological aspects of cyber attackers.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views17 pages

Cybersecurity Challenges in Business Optimization

Chapter 9 discusses the critical role of cybersecurity in Business Optimization (BO), emphasizing its importance in protecting customer data, trust, and overall business integrity. It outlines the dual functions of cybersecurity in BO: securing business processes and leveraging AI for cybersecurity intelligence, while also addressing the complexities and challenges posed by AI integration. The chapter highlights the need for a strategic, agile approach to cybersecurity that balances risks and performance, as well as the importance of understanding the psychological aspects of cyber attackers.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter 9

Cybersecurity in BO
Significance and challenges
for digital business

CYBERSECURITY ASPECTS IN BO

Cybersecurity is integral to digital business. Cybersecurity in this discus-


sion is considered as a part of the overall Business Optimization (BO).
Cybersecurity is a differentiator for customer value, protecting not only data
but also the company perception and customer trust. This is so because the
cybersecurity image of the company impacts customer value. Cybersecurity
vulnerability in the organization’s systems can lose customers and subject
the organization to litigations. Proper handling of cybersecurity protects
customers and revenue, confidence, and accelerates growth opportunities
for the business. A holistic approach to cybersecurity has a positive impact
on the organization’s ability to handle disruptions, increase resilience,
ensure compliance, and enable business continuity. Cybersecurity discus-
sions in this chapter complement GRC and quality topics discussed in the
previous chapter.
Cybersecurity is considered across a broad range of AI applications in BO.
Starting from the edges of the organization (customer touchpoints), through
to analytics, user behavior, and the Cloud, cybersecurity applies every-
where and across the entire organization. The four aspects of Think Data
discussed in Chapter 2 (Figure 2.1) are revisited here from the cybersecurity
perspective. Security of the “handset,” “dataset,” “toolset,” and “mindset”
each requires an understanding of devices, analytics, processes, and people.
Cybersecurity standards and framework help protect data and enhance cus-
tomer value. Timely communication is another crucial part of cybersecurity
as a business strategy. Leaders, managers, network admin istrators, users,
and customers form an important part of the communication strategy.
A digital-savvy business using data in decision-making assumes respon-
sibility for the safety of that data. Cybersecurity complements GRC and
quality initiatives, which were discussed in the previous chapter. This chap-
ter discusses the crucial aspects of cybersecurity in BO with the goal of
ensuring customer value.

213
214 Artificial Intelligence for Business Optimization

Cybersecurity functions
Cybersecurity in BO has two key functions: securing the optimized busi-
ness processes and using AI to undertake cybersecurity intelligence (CI).
Cybersecurity is thus securing the data and business processes, and the use
of data and processes in detecting and preventing breaches. Descriptive,
predictive, and prescriptive analytics are used to detect and prevent security
breaches. Data analytics assumes importance in developing cybersecurity
strategies.
The typical data life cycle starts by ingestion through devices and users.
The data then travels over the networks. The cloud is the common mecha-
nism to store and analyze data. Eventually, the results are presented via
the networks onto the user devices for decision-making. Cybersecurity is
required at each point in this data journey. Furthermore, cybersecurity also
ensures that the data is retired correctly.
The cybersecurity function is only limited to a real threat or breach. At
times, the perceived threat is as important as a real threat and requires
similar, substantial handling. This is so because the perception of security
impacts decisions by customers and partners. Therefore, the perception of
security of an organization’s data is as important as, say, its regulatory
compliance of security and privacy.
AI in the cybersecurity space is a double-edged sword. Attackers tend to
use the same AI technologies and analytics that defenders use. For exam-
ple, attackers hide potentially malicious scripts by encoding in the same
way defenders do. The AI technology is unable to distinguish between the
attackers and the defenders. Attackers use AI to threaten, breach, and abuse
businesses and people. The ethics and moral aspects of AI and security
become equally important in the cybersecurity discussions as alluded to
separately in this chapter.

Cybersecurity as a business decision


Cybersecurity breaches cost trillions of dollars to businesses globally. The
cybersecurity risks are, however, far more significant and complex than the
dollar figures indicate. Embedding AI within business processes increases
their complexity and usage of data. The dollar measure is an insufficient
way to measure the cybersecurity effort. Neither can cybersecurity be con-
sidered as a purely technology issue. While the data and analytics tech-
nologies are at the root of the cybersecurity challenge, the business context
remains foremost in implementing cybersecurity within BO. Thus, cyberse-
curity capabilities are considered a function of people, process, and technol-
ogy. This business context is a function of customer needs, business goals,
security costs, and performance of business processes. Cybersecurity func-
tion thus assumes business responsibility and is a business decision more
than a technology one in business optimization.
Cybersecurity in BO 215

As a business decision, cybersecurity risks are balanced with the effi-


ciency of business processes. For example, a completely and heavily secured
business can suffer business performance attrition to a level where it loses
customers. Therefore, the business mindset has to balance the risks of secu-
rity with that of performance loss in order to arrive at the right level of
security. This balancing act requires ongoing, agile management of the
cybersecurity function.
A strategic approach to cybersecurity is proactive in nature. Such an
approach comprises business goals, technical capabilities, availability of
resources, and the business environment. Outcome-driven business archi-
tecture1 helps in aligning cybersecurity capabilities with the desired busi-
ness outcomes. The cybersecurity capabilities are further prioritized using a
risk-based performance metrics. Cybersecurity decisions, based on perfor-
mance analytics, are made visible to staff, customers, and regulators.
Cybersecurity strategies require the development of controls around the
various data processes (refer back to Figure 2.3 wherein processes around
data are discussed). Security standards provide the basis for adequate,
reasonable, consistent, and effective cybersecurity controls. The controls
should also credible, demonstrable, and auditable.

Cybersecurity and penalties


Risks emanating from the regulatory bodies are exacerbated in data-driven
digital businesses due to the myriad rules and regulations surrounding the
use of data. Risks due to lack of control can also incur substantial penal-
ties. These penalties are business issues, because apart from the financial
losses the business also stands to lose substantial goodwill resulting from
penalties and litigations. Data-driven businesses can also fall prey to money
laundering and other financial misdemeanors.
Financial risks are an important consideration in cybersecurity budgets.
Understanding these varieties of risks, the corresponding value generation,
and the investments needed in the cybersecurity space is also a balanc-
ing act. Stringent cybersecurity implementations increase costs and may
degrade performance. Customer experience is an important factor in ascer-
taining security levels. Cybersecurity tools help in the early identification of
threats and provide insights to handle their eventuation.

Cybersecurity challenges during BO


As AI is embedded in business processes, it changes the way the business
operates. This change to business processes creates a potential for hacking
especially as the newer business processes are data-driven, complex, and
not always explainable. Data-driven business processes tend to be black
boxes with a minimal explanation of what is inside. In such situations,
216 Artificial Intelligence for Business Optimization

AI is seen with trepidation by both users and business leaders. The lack of
explainability of AI can also insert security-related doubt and uncertainty
in the minds of customers.
Cybersecurity function covers the security and privacy of data
and metadata. For example, cybersecurity deals with the security of
location-independent, cellular metadata that may not be owned by the com-
pany. In contrast, the cybersecurity function has to also protect the large
amount of data within the firewall of a company. Additionally, technologies
such as blockchains and ethereums that are becoming part of the digital
business present security risks that cannot be handled by a single busi-
ness on its own. These technologies require a collaborative, industry-based
approach to security.
Outsourcing of AI development and use of third-party data can create a
façade of shift of risks faced by the business during BO. Even though the
service is sourced from a provider, the overall responsibility of cybersecu-
rity is with the business providing the final service and value to the cus-
tomer. Transfer of risks to a vendor or partner is a complex legal quagmire
that stretches beyond technology and business decisions. Awareness of the
challenge is required but dealing with the actual threat of such multiparty
cyber risks is beyond the scope of this book.

Cybersecurity vulnerabilities and impact


­
Cybersecurity in BO 217

term indicating this phenomenon of skewing the output and, thereby, per-
ception with a minuscule variation in the input.
Tools, techniques, and systems are applied by businesses to secure their
data and business processes. For example, multifactor authentications are
now a norm rather than an exception. Configuration of networks and sys-
tems still play an important role in security, and poor handling of their
operations can also present security challenges. Similarly, physical security
of devices becomes a vulnerability of concern as it tends to get oft neglected
while the focus remains on the software and data security.

Cyber attacker’s psyche


Cybersecurity is as much a mind game as a data and technology one. As
businesses aim to secure their optimized processes, attention is required to
the psychological aspect of security as much as to the technical one.
To begin with, the psyche of every attacker is nefarious. The unethi-
cal mind of a cyberattacker may have many reasons – some even justi-
fied in their own minds (e.g., seemingly unfair dismissals from a company
or desire to “settle scores”). Attackers find dedicated time and effort and
work without being paid for it as compared with the typical defenders.
Attackers aim for illegal financial gains but money is not the only purpose
to threaten an organization. Attackers continue to grow their capabilities
alarmingly and act proactively to hurt businesses. In comparison, defend-
ers are usually reactive. Attackers can sidestep defender tools by identify-
ing their characteristics and overcoming them. Attackers can encrypt and
hide the information being sent the same way defenders do. 3 Attackers
overcome encryption with tools that can help them bypass filters and evade
detection. Cybersecurity strategies benefit with the help of AI to identify
potential areas of threats, likelihood of breaches, and the impact of those
breaches on business. Defenders can be provided with greater resources
than are usually made available to them, including tools and skills, to
thwart the attacks.
The psyche of an attacker is to masquerade as a legitimate user sending
legitimate messages. The masked messages from attackers aim to infiltrate
targets in any way possible. Examples of such behavior include text encod-
ing, slipping past filters, and delaying defenders from figuring out what is
going on. Attackers aim to hijack an account, spread web worms, access
browser history and clipboard contents, control the browser remotely, and
scan and exploit applications. Attackers also study the defender psyche and
capitalize on lax user behavior and their possibly untrained mindset. For
example, attackers start with a list of emails of the people they are target-
ing in an organization (or even a country). Initial attack attempts are made
across the board to identify the “weak” users. Profiles of such users are then
built in order to create a sustained attack.
218 Artificial Intelligence for Business Optimization

As business processes are optimized, the analytics within those processes


provide valuable decision-making insights. Reliability and trust in those
analytics are absolutely essential for BO to succeed. Cyberattackers do not
need to do much if this reliability and trust are broken. Therefore, cyber-
security strategies need to incorporate this crucial understanding of the
attacker’s psyche in developing multipronged approaches to cyber defense
of the data, analytics, processes, devices, and users.

SECURING THE OPTIMIZED BUSINESS

Developing cybersecurity strategies requires a technical understanding of


the types of cyber threats. These cyber threats pose differing challenges to
the optimization effort. Threats are external as well as internal. Business
analysis capabilities aid in understanding the types of cyber threats and
developing strategies to counter them. The complexity of networks and data
storages in BO is such that there is no point in time where a cybersecurity
strategy can be said to be complete. Cyber strategies are continuously evolv-
ing in an agile manner. Traditional intrusion and detection analytics are
based on log files. A more strategic approach uses the latest techniques and
tools for collecting and analyzing network traffic datasets as a “trade-off
between expressiveness and speed.”4 This is so because cybersecurity as
a business decision has to balance network transmissions, IoT devices,
and Cloud searches with costs, performances, and people behaviors. The
effect of a particular strategy is understood only after it is implemented.
Therefore, agility in developing and maintaining cybersecurity is a must.

Types of cyber threats


Cybersecurity data has a range of characteristics that are important in the
understanding of cyber threats and developing countermeasures. For exam-
ple, even if an organization has collected a large amount of data related to
security, it is important to know how current is the data, how relevant it is
to the organization, and what is the impact of a threat or a breach on the
business. At times, a seemingly small breach can have a large impact on the
reputation of the business. Cybersecurity analytics assist in developing an
understanding of the availability of resources, possibility of early detection,
readiness of response, and approach to recovery.
Figure 9.1 summarizes the use of analytics and analysis in the cyberse-
curity space.
Figure 9.1 also summarizes four types of cyber threats: malware, phish-
ing, eavesdropping, and denial of sources. Additionally, these threats can
materialize from outside the organization or from within. A brief descrip-
tion of these cyber threats follows.
Cybersecurity in BO 219

Malware
Business Quesoning
(Costs)
Phishing

Modeling
Cloud People
(Storage) (Behavior)
dropping

Cybersecurity Prototyping
Eaves-

Analysis &
Analycs

Analyzing
Denial-of-
Service

Networks
Edge
(Trans- Advising
(IoT)
mission)
Insider
Threat

­Figure 9.1 Using cybersecurity analysis and analytics in securing business optimization.

Malware threats
Malware is malicious software that gets embedded with business pro-
cesses. Malware breaches a network through a vulnerability like a user
downloading or clicking a link embedded in an email or email attach-
ment. Automation and optimization can inadvertently introduce mal-
ware within business processes. This can result in the installation of
additional viruses that will proliferate on their own, spy on activities,
and block access for legitimate users. Ransomwares encrypt in particular
the data thereby making it unusable. Encryption key of such malwares
is known only to the attacker and Cryptocurrency (­Bitcoin) payments
are demanded. Spywares email attachment, ransomware, viruses, and
worms to the user. Cybersecurity strategies include scanning of all incom-
ing messages in v­ arious formats for malware bots. Anticipating bad mes-
sages with encryption that are masquerading as good messages is essential
for defense. A database of all known malwares and ransomwares as well
as forming a community of users with similar understanding is another
approach to handle malware.

Phishing threats
Phishing appears to come in an email or phone message from a known or
apparently reputable source. The message, however, is a fraudulent com-
munication that is searching for vulnerabilities. Phishing searches and asks
for sensitive data like credit card and login information. Cyber strategies
dealing with phishing threats need to upskill the users on an almost daily
basis. This upskilling of users includes the demonstration of the phishing
messages and their impact on business processes.
220 Artificial Intelligence for Business Optimization

Eavesdropping threats
Eavesdropping is the insertion of a spy module in an otherwise normal
transaction between two parties. Eavesdropping usually results from an
unsecure public Wi-Fi that hacks the legitimate communications in order
to steal. Cyber strategies to defend eavesdropping include the development
of prototypes in which various possibilities of these types of attacks are
experimented with. Furthermore, upskilling the users and providing them
with the necessary capabilities, organization wide, are essential in handling
these threats.

­Denial-of-service
­ threats
­

Insider threats
Cyber threats are usually considered coming from external parties. While
this is true in greater percentages, at times the employees or confidants of
the business can also attack the organization for reasons different to the
external attackers. These insider threats result from disgruntled employ-
ees, whistleblowers, and spies. Insiders can steal data, credentials, and data
storage or simply exfiltrate large amounts of data.
Tracking user behavior with analytics can help narrow down the possibil-
ity of insider threats. The risk in such analytics is the potential biases of the
analytics. Cybersecurity implementations need to collect data and logistics
keeping sensitivity of the insider threat in mind. For example, more surveil-
lance of a person can tarnish their image even if they are clean. People may
feel marginalized by the surveying once the surveillance becomes known.
Protecting physical data and resources from insiders requires the use of
multiple verifications from multiple sources, strict inventory control, and
NI-enabled data analytics.

DEVELOPING CYBERSECURITY STRATEGIES

The cybersecurity strategies provide the roadmap for implementing


security measures. Developing cybersecurity strategies includes data,
Cybersecurity in BO 221

analytics, and metrics. Cybersecurity data is sourced from various exter-


nal providers in addition to being collected internally. Partnering busi-
nesses, clients, and vendors add to this large collection of security data.
Regulators and policymakers make security data more widely available
for use in order to boost the security of the entire business community.
Data is extracted, analyzed, and visualized when the security strategy is
implemented. Cybersecurity analytics use a combination of the data gen-
erated and owned by the organization along with third-party provided
security data.
An important aspect of data-driven cybersecurity strategy is metrics and
measures. Metrics can help understand the level of security and vulner-
abilities of handset, dataset, toolset, and mindset. Each aspect of the afore-
mentioned think data needs a metrics and measurement program around it.
Cybersecurity strategies also need to incorporate the visualization aspect
of data. Data drives cybersecurity analytics, but it must be handled appro-
priately. Visualization of analytics has to be intuitive, relevant, and under-
standable in discovering vulnerabilities. Visualization should also not
jeopardize the security of what is being presented.
The argument for using data-driven analytics and analysis to make secu-
rity decisions is based on security, data collection, and eventual insights.
Data analytics reduce the impact of a data breach based on vulnerabilities.
Vulnerabilities expose valuable data to bad actors. Data-driven security
practices record known exploits in successful data breaches and analyze
them to spot future vulnerabilities. Correcting vulnerability reduces the
probability of the impact of data breaches. Vulnerabilities do not account
for all common exploits. Therefore, vulnerabilities are identified and priori-
tized based on their high-impact. Attackers focus on the rare vulnerabili-
ties than the well-known ones. Therefore, vulnerabilities with less-known
exploits need to be prioritized higher as they are likely to be attacked first.
AI-based data analytics can provide insights for prioritization. Furthermore,
dedicated resources and fine granular analytics enable a balance between
known and unknown exploits.

Organizing cybersecurity data and functions


Cybersecurity data and functions are organized in a multilayered format.
These layers apply to the data, processes, and people. Supporting these ana-
lytics are tools that offer antivirus protection and file verifications. At the
device level, data is collected by placing sensors in the right domain and
with the right vantage. At people level, training and educating the users is
also a multilayered activity.
At the core technology level, multilayered spam filtering creates multilay-
ered data that is subject to analytics. This data is collected and filtered for
activities. The suspicious data is analyzed. Comparison of data and data
222 Artificial Intelligence for Business Optimization

­Table 9.1 Organizing the cybersecurity function at a technical level


Aspects Description
Domain Network, Service, Host Active domains form the broad description for
security data collection.
Vantage Location of sensor packet is determined in vantage by interaction
between the sensor’s placement and the routing infrastructure of the
network.
Action What does a sensor do with the data? For example, report it, initiate a
response, control the analytics, and preserve them.
Validity Strength of the premise of analytics based on sensor data collected. This
validity also depends on currency of data – what is valid just now may
not be valid after an hour or a day.

sources to a list of known risks is undertaken. Spammers of data collection


and their domains as a likely source of spam or malware are also part of
data collection.
Table 9.1 summarizes the organization of the security function. The four
aspects of these security functions provide the framework for positions of
sensors and collection of data.
Security data source is part of security analysis. This security data is
gained by multiple sensors throughout a network. The sensors capture
source data from different parts of the network and store it into readable
files. Sensors are placed as network taps or they appear in firewall logs.
Collecting a large amount of data from any network is not the goal. Quality
security data is obtained by the density of security information with mini-
mal overload. Removing redundancies from logs, increasing reliability
of information of the connections between IP addresses, and validating
domain names are some examples. Vantage is another important aspect of
data collection. Source destination of data is improved by proper vantage.
For example, data coming into a router that is being split to a single work-
station and also a switch that is going to a different workstation as well as a
vantage ensure data is accurate and knows the exact place of its origination.
Cybersecurity data collection has to consider the devices used by the
end-user and those used for data collection as both are changing con-
tinuously. These devices (sensors) and their positioning in organizational
networks are part of data collection. Cybersecurity data collection also
identifies the formats packets and filters used. The speed and accuracy of
data transmission as well as breach detection, are factors of network archi-
tecture that limit the data captured and filtered from each packet.

Cybersecurity data analytics


­
Cybersecurity in BO 223

Ongoing Iterations
(Across All
Organizational Functions)

Specific Iteration
(within a Process)

Learn Predict

Recover Detect

Respond

Suggestions / Advise
/ Alternatives

­Figure 9.2 Agile iterations in detecting cybersecurity threats and response/recovery


actions.

represent the immediate and the ongoing series of cybersecurity activities


and actors.
Cybersecurity data is explored and analyzed through a combination of
descriptive-predictive analytics. These analytics are carried out iteratively
in order to narrow down on interesting possibilities of threats and breaches.
Typically, cybersecurity analytics start with understanding the contents of
the logfiles. Further, filtered data enables analytics on source and destina-
tion IP and produces outliers or skewing towards suspicious or abnormal
pattern of deviation from standard expectations.
Univariate descriptive analytics (e.g., histograms, bar charts, boxplots)
are used to analyze the logfiles for quantitative security variables. Bivariate
(e.g., scatterplots) and multivariate analytics can also be applied depending
on the sensitivity, urgency, and application of the analytics to cybersecu-
rity. Data analytics tools collect, analyze, and visualize various security
insights.
The design of analytics on security-related data has to keep the following
considerations in mind:

• Architecture of the sensor network and the positioning of sensors


across the network – including wired and wireless sensor networks
• Existing repository of cybersecurity data and the frequency of updates
to that data from the sensors in the network
• Reliability and relevance of processing of the data and the use of ana-
lytical insights in security decisions
• Granularity of analytics – as coarse granular analytics will work typi-
cally on historical, large datasets to identify patterns whereas fine
224 Artificial Intelligence for Business Optimization

granular analytics provide on-the-spot insights for immediate deci-


sions based on the most recent data
• Currency and validity of data and control of their sources in all forms
of analytics
• Safety and privacy in the retirement of data post-analytics
• Qualitative and quantitative analytics and manner of their visualization
• The manner in which decisions are made and actions undertaken
based on the analytics

Physical security for cyber assets


The physical aspect of data and information security is often overlooked.
While cybersecurity typically focuses on the storage of data and the breaches
in systems, serious loss or damage can occur if physical security of data is
breached. As compared to software attacks, breaches of physical data cen-
ters can be carried out with minimal technical knowledge. Cybersecurity
strategies ensure physical data centers are secured against physical attacks,
accidents, or natural disasters. Physical locks, biometric access, manual
security, surveillance with cameras, intrusion detection, and auto reporting
are important aspects of physical security.
GDPR and Industry Data Security Standards also require organiza-
tions to monitor access and restrict unauthorized entry in any facility that
stores, processes, or transmits customer data. Similarly, HIPAA prescribes
physical measures, policies, and procedures to protect a patient’s electronic
patient record. The measures dictated by these standards are incorporated
in a good cybersecurity strategy.

Cybersecurity analysis using


business analysis capabilities
Cybersecurity analysis (as against analytics) is the application of Business
Analysis (BA discussed in detail in Chapter 6) capabilities to the security
function of the organization. BA views and models the business processes
holistically. Therefore, analysis plays an important role in developing a
cybersecurity strategy than the mere statistical analytics of security data.
Business analysis capabilities view roles, activities, deliverables, and sup-
porting technologies simultaneously from the user’s perspective.
BA activities include asking the right questions about security to the right
people, documenting and modeling the answers and verifying the security
of the processes. BA effort in securing the organization is a continuous,
ongoing one that does not finish at any point in time. Therefore, BA capa-
bilities and approaches are ideal to develop a holistic defense strategy. This
continuously iterating approach to cyber defense is ideal for many threats
that are unknown and remain so till the attack happens. Unknown vulner-
abilities are a challenge to cybersecurity especially in the AI world where
Cybersecurity in BO 225

the vastness of data and the complexity of algorithms make it impossible for
a manual, piecemeal approach to succeed.
Analysis makes use of data and analytics to create opportunities for secu-
rity strategies in a proactive way. Data analytics includes descriptive, pre-
dictive, and prescriptive analytics on security data. Data, and in particular
Big Data, provides opportunities to describe and predict security threats
and occurrences of breaches. Examples of security data include networks,
log-files, user behavior, and device locations. Security analysis together with
data analytics identifies vulnerabilities in the optimized business processes.
Cybersecurity analysis, however, makes provisions to incorporate values
and judgments in security-related decisions. For example, instead of relying
entirely on AI to point to an attacker, analysis will also explore the possi-
bilities of biases. Biases are subjective elements that can appear in the data
(due to previous erroneous entry), algorithms (errors of misunderstanding),
and decisions (human biases).

Cybersecurity standards and frameworks


The most popular cybersecurity standard is the NIST cybersecurity frame-
work and ISO 2700x.5 Another standard for Cybersecurity Readiness and
Investment is the CARE standard.6 These standards provide the background
in developing cybersecurity strategies and aim to reduce cybersecurity risks
for businesses. Standards include collections of tools, policies, security
concepts, security safeguards, guidelines, risk management approaches,
actions, training, best-practice assurance, and technologies.
Best practices and techniques in determining cybersecurity capability lev-
els provide value to organizations implementing the standards and models.
Desired levels of cybersecurity form the basis for prioritization. Maturity
models measure how good the capabilities are. These matured capabilities
are aligned to the goals. Cybersecurity capabilities need continuous align-
ment to organization context.
CARVER (Criticality, Accessibility, Recuperability, Vulnerability, Effect,
and Recognizability)­7 provides yet another helpful framework in developing
the cybersecurity strategies. Having originated from the US defense, this
standard provides an approach to identify and rank specific targets so that
attack resources can be efficiently used. As a result, CARVER can be used
by digital businesses from an offensive (what to attack) or defensive (what
to protect) perspective.

CYBERSECURITY INTELLIGENCE (CI)

Cybersecurity intelligence (CI) is the use of AI to enhance cybersecurity


functions. Cybersecurity intelligence starts by identifying the security goals
226 Artificial Intelligence for Business Optimization

and acceptable risk levels. Prioritization of risks can be undertaken with


standards and frameworks mentioned above. Cybersecurity intelligence
starts with data, but the analytical part needs well-defined metrics and
measurements. People, processes, technologies, and money are used in a
balanced and holistic manner with the help of standards, metrics, and mea-
surements. An understanding of data sources used is a valuable input in
developing the balanced strategy. Due consideration to people issues is also
helpful in approaching cybersecurity in balance. For example, human error,
apathy, or negligence is the cause for more than half of security breaches.
Most software viruses are activated by a click of the user.8
AI analytics embedded in business processes become extremely complex.
AI-based cybersecurity tools become necessary to handle this complexity.
Security metrics and measurements from the basis of CI tools design and
choice of metrics, use of relevant analytical techniques, and understanding
of the mindset provide the backdrop for the CI functions.
Change to a security mindset is a people issue and CI aids and supports it
by narrowing areas for attention and action. Training and mentoring play a
role in enhancing the cybersecurity mindset.

Cybersecurity metrics and measurements in CI


CI uses security-related data in order to understand vulnerabilities. The
data is downloaded and analyzed using tools. CI is designed keeping the
business outcome in mind and the use of cybersecurity tools. Cybersecurity
metrics comprise external events (e.g., number of breaches) and internal
responses (e.g., speed of detection). The number of threats and the occur-
rence of breaches are external and not controlled by the business, whereas
the speed of detection is an example of the internal preparedness of the
organization. Example metrics include total malware incidents, percentage
attacks blocked, and so on. CI learns from every previous attempt to attack.
And each learning provides the opportunity to imagine further attacks. CI
helps narrow the areas of defense and make it cost effective. CI is part of
the overall business strategy.
Breaches impact business processes and corresponding customer senti-
ment. Data indicates the strength of firewalls and filtering mechanisms. CI
makes use of this data to measure the overall security design, data collec-
tion, transmission, and analytics. CI needs focus, position of the organiza-
tion, and areas of focus. Detecting breaches and preventing further attacks
have to be accompanied by transparency and honesty.
Customer value remains the focus of BO and, therefore, also of CI. Since
the perception of security by the customer is as important as actual security,
CI includes analysis of customer sentiments. For example, if customers are
unable to easily gain access to services, then even for a highly secured busi-
ness, the perception and quality of the offerings suffer. Data analytics not
Cybersecurity in BO 227

only prevent and detect breaches but also provide insights into customer
perceptions of security.
CI is both strategic and tactical. Examples of tactical CI include analyt-
ics on the daily/ hourly number of breaches. The ease of user login or lack
thereof is also tactical to CI. CI at a strategic level provides the overall secu-
rity position of the organization. Tools, technologies, systems compliance
audits, and competitor positions are of concern in strategic CI. Organizing
training in security to update the mindset of employees is crucial and
strategic.
CI includes a detailed plan of action in case of data security breaches and
related business disruptions. Actions are based on an understanding of the
business and competitors. CI aims to learn not only from the data within
the organization but also from across the industry.

Levensthein distance as a measure in CI


An example of CI is the application of analytics to cybersecurity data such
as the user logfiles. The contents of the logfiles include log-ins, frequencies
of log-ins, and relevance of users. Simple length data analysis is based on
header-length and record-length. Median, average, and standard deviation
are derivatives of value. Earlier filters can be used for further analytics for
nonurgent, nonstandard, and unexpected flags. Accessing and manipulat-
ing the log files are cybersecurity analytics.
An example of cybersecurity defense technique is the calculation of
the Levenshtein distance – which is a “string distance” between phishing
domains and authentic ones. For example, the Levenshtein distance between
“hello” and “hallo” is 1 – which quantifies the difference between phishing
and authentic domains. Defenders can use AI to quantify this distance for
a large number of domains to start flagging phishing emails. A phishing
attack attempting to redirect the user to “[Link]” instead of
“[Link]” can be caught this way.

Base rate fallacy in cybersecurity measure and


the validity of positives and negatives in CI
CI continually deals with sensitivity and specificity of potential threats and
breaches. Security-related data is collected through sensors which are not
only devices but also any other binary classifier.9 Collection of such cyber-
security data is followed by its analytics. Each sensor data has potentially
false positives and false negatives. CI analytics requires a balancing act (or
tradeoff) between the potential “false” readings.
This balancing act is based on the “base rate fallacy” that gives insight
into the use of CI. For example, a 99% accuracy can produce 100 false
positives for a 10,000 sample. These false positives are not equally spread
228 Artificial Intelligence for Business Optimization

across the sample. Therefore, these tests cannot be entirely used for detec-
tion on a network.
Intrusion Detection System (IDS) has to consider multiple types of prob-
abilities based on false positives and false negatives. Bayes’10 theorem gives
the probability of an event and is used in CI. Considering security data in a
mono-dimensional leads to what is called Base Rate Fallacy.
An IDS can incorporate the concept of Base Rate Fallacy11 in its algo-
rithms. Consider, for example, face recognition as an identification. Face ID
also works on percentages. For example, if an ID is 99% accurate for face
detection, it still leaves many opportunities for a face to gain illegal to entry.
IDS can factor in the possibilities of fallacies in its algorithms.

Filtering algorithms for email phishing for CI


CI also manages email rules and filters phishing emails. Managing emails
and filtering requires the application of AI. Analytics on emails establishes a
pattern for filtering. While the filters filter out suspicious emails to the spam
folder, the rules for filtering can create an imbalance. Filtering algorithms
model the email route, available hardware, networks, and devices. Regular
internal monitoring of emails and daily updates is an essential element of CI.
Transmission of emails, especially on the cloud, each requires a secu-
rity focus. Emails on the mail server can be accessed anywhere depending
on how the administrator sets it up. These mail servers are susceptible to
attacks. A service gateway is needed to create the email rules and filtering.
User location and access is out of the administrator control.
CI scripts parse through large datasets to find a string, manipulate
delimiters, split them by standards and rules, and arrange them in specific
patterns of possible encryption types. Once the patterns are established,
techniques for text analysis to decrypt the data are used. The techniques
produce the results that develop an understanding of how the encryption
works and fine tune another script specific to that encryption.
AI-based approaches to cybersecurity scale up to counter the cyberse-
curity risks. Cyberattackers also use tools, typically bots, which continue
to ping for vulnerabilities. Bots form a network of their own to scale the
breadth and depth of attacks.
Detecting cyberattacks requires the use of AI tools because of the need
for speed and granularity. This role can be played by AI technology. ML
algorithms can gather past security including attacks and breaches. ML
algorithms are then trained on such data to detect anomalies.
AI has its own vulnerability. For example, changing an image in a way
imperceptible to humans can mislead an AI program to label the image as
something entirely different. Alternatively, it is easy to produce images that
are completely unrecognizable to humans, but that state-of-the-art AI pro-
grams believe to be recognizable objects with 99.99% confidence.12
Cybersecurity in BO 229

Tools for cybersecurity intelligence


Cybersecurity analytics need tool support. SIEM tools provide this sup-
port. The security factors considered by SIEM include: ports and protocols,
size, IP addresses, time, TCP options, helper options, and filtering options.
SiLK13 is a standardized SIEM used by many organizations. Other exam-
ples of tools include Splunk and Webroot; SPAM Titan and Barracuda are
typically used in email filtering and analytics. These tools ingest datafiles,
suitably format them and manipulate fields in order to understand security
breaches and create security alerts. SIEM correlates a lot of data informa-
tion that aid cybersecurity.
The SiLK suite, also known as the System for Internet Level Knowledge
suite, provides tools for the collection, storage, and analysis of net flow
data. NetFlow is a router feature that enables the ability to collect IP
network traffic.14 SiLK provides a number of useful tools that can query
NetFlow, activity, policy violations, and time frame of a particular event
and analyze them in an efficient system. The security data is subject to
quantitative and qualitative descriptive analytics. Quantitative data pro-
duces statistics such as average and standard deviation whereas qualita-
tive data produces frequency and observations. This kind of information
can be crucial with IP data when visualizing what source contacted what
destination how often, for a basic example. The analytics are represented
in numerical or statistical fashion (quantitative), or in the form of ideas or
graphs (qualitative).
­
For example, the frequency of users accessing information compared to
all users provides qualitative analysis. The total number of times a group of
users is accessing the information asset per day, week, or month is a quan-
titative analysis. A query on the net flow files, including the IP addresses of
users and specified time frame, provides a profile of access and usage.

CONSOLIDATION WORKSHOP

You might also like