Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Wednesday, December 4, 2019

Play To Win In Cyber Security

Close your eyes and think of the goals for your cyber program.  Think of what a win looks like.



In American football, a prevent defense almost always means the other team has a chance to win. 


Are your cyber goals preparing your organization to win? Or, is your program playing the cyber equivalent of a prevent defense?

Saturday, November 16, 2019

Blue Team Building In Cyber Programs


There is a well known blue team problem in cyber security.


Blue teams defend everything.  

They have little hand in choosing the time or place of incidents.
A lot of threat surface area to defend.
And, too much to try to tackle at once.

Perhaps it’s time to change the dynamics.

Wednesday, November 13, 2019

Rethinking Gaps In Cyber Security Programs


Think about cyber in business terms for a second. A description of a cyber security program without a clear statement of program gaps is like a balance sheet without a liabilities statement. 




And yet, somehow, gaps seem to be an often minimized part of our conversations with executives. 


Perhaps as cyber leaders, we choose to avoid hard conversations about program gaps because we want to be positive. Maybe we avoid them because we have some level of fear of executive reaction to hearing about gaps in the cyber security program in the context of past investments. 

Wednesday, September 18, 2019

A Perplexing Cyber Risk Management Question


Question: Your cyber risk management program is effective at proactively finding risks.  




Answer: Effective / Not Effective.  (circle one)

How do you know?  What is being measured?

After all, it’s a key program for proactively identifying cyber risks.

Lots of resources, and frameworks, and effort.


The same expectations of any other program with that size and scale. 

But no obvious formalized way or feedback loop to evaluate, measure, or compare just how good that proactive risk identification is.

Wait, what?!?

Maybe teams don't want to know how effective they are. Does the question even matter? Or is the question just not often asked?  So many perplexing follow-on questions in my head.

In my thinking, the risks identified outside of the cyber risk management process that didn’t find their way into the risk register would seem to be as significant as a software defect not caught by the QA team. 

Some potentially serious root causes as to why were those missed. by the cyber risk program:   

Training issue? Process hole? Lack of resources?

Or, just the historically comforting knowledge that they aren’t tracked, goaled, or owned?

I’m feeling like this should be important or that I have missed a key concept someplace…

….particularly with the resources and effort involved.

How do you demonstrate that your cyber risk management program is effective for the resources and effort you've put into it? 

Join the discussion at #crazygoodcyberteams on twitter or Linkedin . Alo, follow me on Twitter for discussion and the latest blog updates: @Opinionatedsec1

SEE ALSO