- News & Resources: Listings >
- Blog
- How to Improve Safety and Security in Schools – Cloud Manage Network
- Top 10 Cybersecurity Threats in 2024
- Microsegmentation: Protecting Data from Cyber Threats
- Retail shoplifting and loss prevention: How to protect your business
- Generative AI Cost Optimization Strategies
- Why Do I Need to Protect My Cloud?
- 10 Reasons for Engaging Outside Experts to Manage Your Cybersecurity
- Why Hiring a 3rd Party MSP Expert Makes Sense and – and Cents (MANY cents!)
- Brand and Network Considerations When Adopting AI Corporately
- Integrating XDR, SIEM, and SOAR
- 3-2-1 –Go? Not so quick, this time.
- 5 Things a CISO Shoud Know
- 10-Step Patch Management Checklist
- Penetration Testing vs. Breach Attack Simulation
- Current big cyber breaches and impact on businesses
- Smart Infrastructure Gets Lit Up!
- Securing Industrial IoT: The Missing Puzzle Piece
- 7 Common Cybersecurity Mistakes Made by SMBs
- The Future of Physical Security: Cloud-Based Systems
- Autonomous and Sensor Technology Use Surging
- 2024 Facilities Trends Will Require Facilities and IT Teams to Work in Tandem
- NGFW vs. WAF. What’s the Right Firewall for You?
- Chris Hadfield’s Words To Live By
- Industrial Revolution 4.0 + IIoT
- Digital Fluency Drives Innovation
- Your Cloud Needs Protecting, Too
- Your building alarm systems could become obsolete. In 2024!
- Zero Trust 2.0: Zero Trust Data Resilience (ZTDR)
- We just got, or got used to, Wi-Fi 6. What is Wi-Fi 7?
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – 4th and Last in a Four-Part Series
- Why 2024 is the Year for AI Networking
- International Women’s Day is Tomorrow – Great Time to Think About…
- Data-Centric Security Step One: Classifying Your Data
- The Network – Unsung Hero of Super Bowl LVIII
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – Third in a Four-Part Series
- Boosting IT Team Performance by Fostering Intuition, Curiosity and Creativity
- Breach Remediation Costs Can Wipeout Bottom Line and Business
- Hoodied Hackers Now Favour Hugo Boss
- What Do You Need to Tell the Board? Business Metrics that CISOs Should Share – Second in a Four-Part Series
- How to Get People to Re-Engage After the Holidays
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – First in a Four-Part Series
- Android Devices MUST be Updated + IT Departments Being Cut as Privilege Escalation Escalates
- Today’s Common Cloud Migration and Management Concerns
- Protect Your Healthcare Network from Cyberattack – Lives are at Stake
- Happy Halloween: Black Cats Lead to Boo….Hoo.
- Insurance Underwriters are Protecting Their Flanks
- Insurance Companies Cracking Down as Cybercriminals Become Better Business Builders
- Scary Cyberattacks Stats
- Parents, Profs and IT Professionals Perceive Back-to-School Through Different Lens
- Zscaler’s new IDTR and other tools that leverage generative AI
- Vanquish Vaping, Vandalism and Villainy
- Fabric for Fast-Paced Environments
- Changes to Cyber Insurance Requirements – What you Need to Know
- Cybersecurity Readiness – Newly Released Report
- Passwords Leaked…Again
- 10-Step Patch Management Checklist
- Remote – Again – For Now… and Still Maintaining Engagement
- Protecting Pocketbooks, Passwords and Property from Pilfering
- Raspberry Robin: Highly Evasive Worm Spreads over External Disks
- Cisco Introduces Responsible AI – Enhancing Technology, Transparency and Customer Trust
- Managing Customer Trust in Uncertain Supply Chain Conditions
- Hope on the Horizon
- Toys of Tomorrow… What will spark your imagination? Fuel your imagination?
- Protecting Purses and Digital Wallets
- The Password that Felled the Kingdom + MFA vs 2FA
- The MOE’s RA 3.0 and Zscaler
- 7 Critical Reasons for MS Office 365 Backup
- Penetration Testing Important, but…
- Social Engineering and Poor Patching Responsible for Over 90% of Cybersecurity Problems
- Breach Incidence and Costs On the Rise Again + 5 Ways to Reduce Your Risk
- Cybersecurity Insurance Policies Require Security Audits and Pen Testing
- Wireless strategies for business continuity gain importance as enterprise expand IoT, cloud, and other technologies
- How Cybercrooks are Targeting YOU
- Enabling Digital Transformation with Cisco SD-WAN
- WFH Post Pandemic – What It Will Look Like. What You’ll Need.
- Leaders to looking to the IoT to improve efficiency and resiliency
- Cyber Security Vernacular – Well, some of it, for now
- Why You Need Disaster Recovery, NOT Just Back-Ups
- 10 Reasons Why Having an Expert Manage Your Cybersecurity Makes Sense and Saves Dollars
- Converting CapEx IT Investments into Manageable OpEx
- The Hybrid Workplace – Planning the Next Phase
- Cisco Cloud Calling: Empowering Customers to Thrive with Hybrid Work
- When You Can’t Access the Cloud
- How to Keep On Keeping On
- New Cisco Research Reveals Collaboration, Cloud and Security are IT’s Top Challenges
- Threats from Within on the Rise
- Cloud Covered? If Not, Take Cover!
- Zero Trust and Forrester Wave Report
- Password Based Cyber Attack: Like Leaving Keys Under Doormats
- So, What’s Up With Sensors?
- Sensors and Systems Create a Digital “Last Mile” and Help Skyrocketing Costs
- Scanners Provide Peace of Mind for Returning Students and Workers
- Sensors Improve Operations and Bottom Line… Easily and Cost-Affordably.
- Cisco Meraki Looks at 2021
- 2020 Holiday Shopping: Cybersecurity and Other Tips to Safeguard Wallets and Systems
- How to make the most of the technology you have
- Personnel, Planet and Business Progress: More Interdependent Than Ever Before
- Sure… you can get them all in the boat – but can you get them to work well together?
- Pushing the Zero Trust Envelope – Cisco is Named a Leader in the 2020 Forrester Zero Trust Wave
- Cloud Data Must be Protected, Too!
- Don’t Let Anyone Get the Dirt on You – Make It Instead!
- How IoT Devices Can Help You and Your business
- WebEx – A World of Possibility
- Creating Your Breach Response Plan Now Will Save You Thousands Down The Road
- Been hacked? Here’s what you must do next.
- The Need for Pen Testing is At an All-Time High
- 5 Ways an IT Reseller Improves Your Performance and Peace-of-Mind
- 5G and Wi-Fi 6: Faster, more flexible, and future ready. Are you?
- Network and Data Security for Returning and Remote Workers + Disaster Recovery Symposium
- Collaboration and Cisco WebEx: Protecting Your Data
- Thursday’s Virtual Conference Tackles Today’s Supply Chain Trials and Tribulations
- 10 Tips to Reduce Cloud Storage Risk
- COVID-19 Crisis Fuelling IT Spending
- Supply Chain/Logistics Experts Share Their Expertise
- Cisco Breach Defence Overview
- Announcing Our New Website and Blog
If you are in the role, you know that part of a CISO’s role is to share key data with their Boards and/or seniors executives who help determine how tightly the purse strings should be drawn. In our December 20th post, the first in this four-part series, we separated these many elements into 10 Key Categories:
-
Expanding Digital Footprints Increase Vulnerability
-
Data and Data Lake Segmentation
-
People, Phishing and Policies
-
Stakeholder Security, including digital supply chain security and third-party risk management
-
Incident Detection and Response + Testing Protocols and Practices
-
Infrastructure – State of Current Architecture and Equipment +Future Needs Assessment
-
New Technologies, including Enterprise -Wide and Department-Level Applications as well as use of IoT, ML and AI
-
Investment Levels and Efficacy + Regulatory Compliance and Insurance Coverage
-
Vendors and Portfolio Management
-
Financial Asset Risks + ROI and Losses
In the first installment, we covered Points 1 and 2. Today the focus is on some of the security-related elements.
Despite the many – far too many, and all too frequent – headlines about successful data breaches in which individuals’ private data, and corporations’ proprietary data, is released on the dark web and elsewhere, it is estimated that less than 40% of North American Senior executives and non-tech-related roles truly understand cybersecurity. As a result, digital transformation is often stalled. For small businesses, it also means that insufficient resources will be dedicated to providing a robust enough security posture that will enable it to withstand basic cyberattacks.
As you prepare to deliveries to reports, it can help to remind the purse strings holders that every dollar spent recovering from a cyberbreach, is one less dollar that can be spent on initiatives that will help the company grow. Getting senior management and/or board members to view cybersecurity as a way to engender consumer trust and the loyalty, rather than as a cost centre, can help with strategic investment in network-related conditions, including security solutions.
People, Phishing and Policies
It’s not news, probably not even surprising anymore, to say that stakeholders represent an organisation’s biggest vulnerability when it comes to cybersecurity.
Whether it’s a result of poor training, inattentiveness that allows someone to absentmindedly click on a suspicious email’s link, maliciousness or desire for personal gain (and these last two represent less than 5% of breaches), people represent malware’s gateway into your network.
Given that email is the number one way that cybercrooks get into your system, this is a good place to start. It can be difficult, however, to measure the effectiveness of cybersecurity awareness training, protocols and stakeholder messaging, but you can – and should – track weekly, and report quarterly, on the items listed below.
Obviously, if the number start to climb dramatically, you would need to report on this immediately – and then again more frequently until numbers returned to “normal” levels.
-
Actual numbers of, and percentages of, suspicious email that is flagged and/or quarantined by your email firewall and other security programs.
-
Percentage of suspicious email that gets reported by stakeholders, both internal and external, and the response taken to this mail.
-
Results from phishing simulations, and identification of users who are lured repeatedly, as they are high-risk to the organisation’s network security.
-
Percentage of passwords that have been hacked and/or are still not robust enough.
-
The number of emails that are available on the dark web. One of the free tools you can use to check for vulnerable emails: https://haveibeenpwned.com/.
-
Percentage of employees that are moving data and/or files between different permission levels within the firm and/or out of the organisation, altogether. To be truly valuable, this data should be grouped by function.
In most instances, senior executives also need to understand the concept of “least permission” also known as the Principle of Least Privilege (PoLP), and the policies that are being applied. With PoLP, users should only have access to specific resources, applications and data they need for the tasks they need to perform their specific roles in the company. Using this approach helps organisations reduce their attack surface and improve their security posture. So… if exceptions are being made, this needs to be reported on, as well as how it was handled
In most instances, senior executives also need to understand the concept of “least permission” also known as the Principle of Least Privilege (PoLP), and the policies that are being applied.
As part of your reporting, it is also important to include your mitigation strategies – and to outline your contingency plans in case the yoghurt does indeed hit the fan.
Stakeholder Security, including digital supply chain security and third-party risk management
For this section, we are going to borrow from another of our own blog posts:
With increasingly distributed networks, growing adoption of digital applications and transactions, and with hybrid working a fact of life today, organisations are routinely creating virtual spaces in which stakeholders can work collaboratively. All to the delight of cybercriminal enterprises, because once entry is gained into one corporate portal, the marauders can hop, skip and jump their way seamlessly into the networks of other connected organisations.
The result is that multi-stage, multi-vector attacks have become the norm.
Today, it’s also highly possible that one of the stakeholders with whom you collaborate regularly, or one of the firms within your supply chain, manufacturers its products offshore.
One of these companies may do business with a company in Russia, Iran, North Korea or China (the top sources of nation-state threat activities, according to Microsoft’s Digital Defense Report 2022). Now, your network could be vulnerable to a nation-state threat vector. All it takes is the smallest of security shortcomings somewhere along the line, for a massive problem to be unleashed. It’s akin to a small ocean wave encountering interference of some kind and being transformed into a rogue wave, which can be highly destructive.
This is not news to your senior team, so it will be important that you require implementation of the following, and then track and report on the related metrics:
-
The cybersecurity posture of suppliers, distributors and other stakeholders connecting to your network – and how they compare against others.
-
Results from penetration testing and other cyber security audits that your company chooses to require for organisations being given permission to connect to your network.
-
Patch management protocols.
-
A process for continuously monitoring of posture of your external stakeholders.
Incident Detection and Response + Testing Protocols and Practices
Equally important to showing that you are shoring up s cybersecurity shortcomings, is reassuring senior management that your team is able to detect and respond readily to various types of cyberincidents.
Among the metrics to track, assess and report on:
-
The frequency and types of types of tabletop exercises and attack simulations in which you engage.
-
How the red team scores against the blue team, what you learn from the exercises, and the protocols and practices you implement as a result.
-
The actual number of, as well as percentage of, successful incidents in comparison with the intrusion attempts.
-
Mean time to detect, to contain and to remediate.
-
Mean time for full restoration in exercises that simulate going down to bare metal.
We hope you found this of interest. If you would like more information, please contact us at [email protected] or call us at 416.429.0796 or 1.877.238.9944 (toll free).
Otherwise, please check back in February for Part 3 in the series.