Six principles of resilience to manage digital security

August 2016 Information Security, Security Services & Risk Management

Security professionals in South Africa need to protect their enterprise by building resilience. Speaking ahead of the Gartner Symposium/ITxpo 2016 in Cape Town, Tom Scholtz vice president & Gartner Fellow, said resilience is the best approach to address both catastrophic and daily threats.

“Resilience is our North Star,” Scholtz said. “And resilience isn’t only about catastrophic threats, it’s also about everyday and continuous threats.”

In South Africa although companies have excellent network security, they’re highly vulnerable with regard to applications. “To manage digital security, organisations should adapt six principles of resilience.”

1. Move from check box compliance to risk-based thinking

Following a regulation or a framework, or just doing what your auditors tell you to do, has never resulted in appropriate or sufficient protection for an organisation. Risk-based thinking is about understanding the major risks your business will face and prioritising controls and investments in security to achieve business outcomes.

2. Move from protecting the infrastructure to supporting organisational outcomes

You still have to protect your infrastructure, but you also have to elevate your security strategy in order to protect the things the business actually cares about, such as business performance, public service delivery, or a military mission.

3. Move from being the righteous defenders of the organisation to acting as the facilitators of balance

Resist the temptation to tell the business what to do and decide how much risk is good for the organisation. Instead of pushing back on business requests to move workloads to the cloud, for example, work effectively with your business counterparts to negotiate appropriate levels of security.

4. Move from controlling the flow of information to understanding how information flows

Digital business will introduce massive new volumes and types of information that must be understood and appropriately protected. You cannot apply appropriate controls to protect information when you don’t know where it is.

5. Move from a technology focus to a people focus

Security technology has its limits and, therefore, it’s necessary to shape behaviour and motivate people to do the right thing, not just try to force people to do what we want. For example, phishing is the initial infection vector of 80 percent of breaches. However, there are no totally effective technical controls to this problem. When employees are motivated and understand the limitations of trust, the click through rate on phishing e-mails dramatically drops.

6. Move from protection only, to detect and respond

The disparity between the speed of compromise and the speed of detection is one of the starkest failures discovered in breach investigations. In the digital world, the pace of change will be too fast to anticipate and defend against every type of attack. Security professionals should acknowledge that compromise is inevitable. Ultimately, it’s time to invest in technical, procedural and human capabilities to detect when a compromise occurs.

Scholtz will cover this topic in his presentation entitled “Managing Risk and Security at the Speed of Digital Business” at the Gartner Symposium/ITxpo 2016 in Cape Town, 26-28 September, South Africa.

For more information go to http://www.gartner.co.za.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Partnership addresses fire hazard mitigation
Brigit Fire (a Division of Hudaco Trading) Elvey Security Technologies Fire & Safety Security Services & Risk Management
Brigit Fire has partnered with the Elvey Group. The collaboration will see Brigit Fire distributing both the advanced C-TEC addressable fire detection systems (CAST Technology) and GreenMist lithium extinguishers.

Read more...
Fire protection for a solvent extraction plant in Africa
FS Systems Fire & Safety Security Services & Risk Management Mining (Industry)
A prominent mining site operates a state-of-the-art solvent extraction (SX) plant, integral to separating and purifying metals from ores, which pose significant fire risks, as SX processes involve highly flammable organic solvents and elevated operating temperatures.

Read more...
Taking fire safety seriously
G2 Fire Editor's Choice Fire & Safety Security Services & Risk Management
To gain insights into how fire systems must be designed, installed and maintained, SMART Security Solutions asked Nichola Allan, MD of G2 Fire, for some insights into the local fire market.

Read more...
SMARTpod talks to The Risk Management Forum
SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Videos Training & Education
SMART Security Solutions recently released its first SMARTpod podcast, discussing the upcoming Risk Management Forum Conference 2024, which will be held on 26 September 2024 at the Indaba Conference Centre in Fourways, Johannesburg.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
Get proactive with cybersecurity
Information Security
The ability to respond effectively to a cybersecurity breach is critical, but the missing piece of the puzzle is a thorough, proactive evaluation to ascertain weaknesses and identify any hidden threats.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
How to securely manage your digital footprint
Information Security Training & Education
Managing your online presence is critical to safeguarding your privacy and security. It is imperative to take a proactive approach, including using robust cybersecurity best practices.

Read more...