Cybersecurity Report: IT and Business Need To Talk

Cybersecurity Report: IT and Business Need To Talk

Most companies do a poor job of handling cybersecurity, even as their losses to cybercrime continue to mount, according to a report issued this month by the Internet Security Alliance and the American National Standards Institute. That’s because companies tend to turn over too much responsibility for cybersecurity to their IT departments — which may already be overburdened — and don’t involve the business side as much as they should. “Cybersecurity is far more than than a simple technical glitch,” said Larry Clinton, the CEO of ISA, in an interview. “It’s an enterprise-wide risk, an economic strategic issue, and people are not explaining it enough.” Called The Financial Management of Cyber Risk, the report is intended to be a handbook for companies on how to get their chief financial officers and other senior business staff involved in cybersecurity decisions so the company can better understand its true risk. The report cites federal data from 2008 estimating that businesses have lost more than $1 trillion in stolen intellectual property — and that number excludes losses due to theft of personally identifiable information, system downtime, bad publicity and customers who take their business elsewhere after a breach. Despite those losses, spending on cybersecurity has been reduced or deferred in the last year or so due to the economic downturn, and less than half of companies have a formal plan to manage information security risk. According to research by Deloitte, which the report cited, three quarters of U.S. companies have no chief risk officer, and almost none involve the chief financial officer in managing their risks. Also, senior executives have the additional disadvantage of being too old to have grown up with computers — they are “digital immigrants,” the report said, and are likely to face “‘language barriers’ when it comes to the rhetoric of information security.” ISA and ANSI have developed a six-step plan for companies to improve the way they handle cybersecurity — they developed this by meeting with people from 60 private sector organizations and government agencies at a series of conferences across the U.S.

Six Prevention Steps

The good news is that most cyberattacks are unsophisticated and can be easily prevented, according to data from PricewaterhouseCoopers, the CIA, and the NSA — the NSA’s Richard Schaffer told Congress last November that 80 percent of cyberattacks could be prevented “by using existing standards/practices and technologies.” So here are the six steps:

    1) Own the problem. IT people may need to educate their bosses on what the problem is — what role technology plays in the organization and how the IT department works.

    2) Appoint a cyber risk team with employees from across the organization. (The report helps identify who should be represented).

    3) Hold regular meetings, and meet in person if you can. Otherwise use videoconferencing so people can see each other.

    4) Use this group to develop a cyber risk plan that includes your IT architecture, its levels of risk and an incident-response plan in case of a breach.

    5) Then develop a cyber risk budget based on the estimated cost to your company of a breach.

    6) Implement and test your plan. Then use it.

Clinton said there’s been good response to the report so far. The FDIC has asked for a presentation, and Loyola University is looking at making cyber risk a part of its MBA program. Ultimately, though, he thinks companies are going to have to restructure themselves if they want to handle cyber risk. “American business has silos, with segmented roles and responsibilities, but cyber cuts across all those,” he said. “We have to rethink how to structure our businesses, and the rules of warfare, and our notions of privacy and the relations between the private sector and government. It’s the private sector now on the front lines of defense.” The report has been endorsed by Melissa Hathaway, who was President Obama’s interim cybersecurity coordinator before Howard Schmidt was appointed to the post in December.

devx-admin

devx-admin

Share the Post:
Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security.

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like

Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as opposed to the 176% return

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024 approaches, the industry seems to

Elevated Content Deals

Elevate Your Content Creation with Amazing Deals

The latest Tech Deals cater to creators of different levels and budgets, featuring a variety of computer accessories and tools designed specifically for content creation. Enhance your technological setup with

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security. These carefully designed learning courses

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers to better manage smaller unmanned

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like artificial intelligence (AI), semiconductors, and

Huge Savings

Score Massive Savings on Portable Gaming

This week in tech bargains, a well-known firm has considerably reduced the price of its portable gaming device, cutting costs by as much as 20 percent, which matches the lowest

Cloudfare Protection

Unbreakable: Cloudflare One Data Protection Suite

Recently, Cloudflare introduced its One Data Protection Suite, an extensive collection of sophisticated security tools designed to protect data in various environments, including web, private, and SaaS applications. The suite

Drone Revolution

Cool Drone Tech Unveiled at London Event

At the DSEI defense event in London, Israeli defense firms exhibited cutting-edge drone technology featuring vertical-takeoff-and-landing (VTOL) abilities while launching two innovative systems that have already been acquired by clients.

2D Semiconductor Revolution

Disrupting Electronics with 2D Semiconductors

The rapid development in electronic devices has created an increasing demand for advanced semiconductors. While silicon has traditionally been the go-to material for such applications, it suffers from certain limitations.

Cisco Growth

Cisco Cuts Jobs To Optimize Growth

Tech giant Cisco Systems Inc. recently unveiled plans to reduce its workforce in two Californian cities, with the goal of optimizing the company’s cost structure. The company has decided to

FAA Authorization

FAA Approves Drone Deliveries

In a significant development for the US drone industry, drone delivery company Zipline has gained Federal Aviation Administration (FAA) authorization, permitting them to operate drones beyond the visual line of

Mortgage Rate Challenges

Prop-Tech Firms Face Mortgage Rate Challenges

The surge in mortgage rates and a subsequent decrease in home buying have presented challenges for prop-tech firms like Divvy Homes, a rent-to-own start-up company. With a previous valuation of

Lighthouse Updates

Microsoft 365 Lighthouse: Powerful Updates

Microsoft has introduced a new update to Microsoft 365 Lighthouse, which includes support for alerts and notifications. This update is designed to give Managed Service Providers (MSPs) increased control and

Website Lock

Mysterious Website Blockage Sparks Concern

Recently, visitors of a well-known resource website encountered a message blocking their access, resulting in disappointment and frustration among its users. While the reason for this limitation remains uncertain, specialists

AI Tool

Unleashing AI Power with Microsoft 365 Copilot

Microsoft has recently unveiled the initial list of Australian clients who will benefit from Microsoft 365 (M365) Copilot through the exclusive invitation-only global Early Access Program. Prominent organizations participating in

Microsoft Egnyte Collaboration

Microsoft and Egnyte Collaboration

Microsoft has revealed a collaboration with Egnyte, a prominent platform for content cooperation and governance, with the goal of improving real-time collaboration features within Microsoft 365 and Microsoft Teams. This

Best Laptops

Top Programming Laptops of 2023

In 2023, many developers prioritize finding the best laptop for programming, whether at home, in the workplace, or on the go. A high-performing, portable, and user-friendly laptop could significantly influence

Renaissance Gaming Magic

AI Unleashes A Gaming Renaissance

In recent times, artificial intelligence has achieved remarkable progress, with resources like ChatGPT becoming more sophisticated and readily available. Pietro Schirano, the design lead at Brex, has explored the capabilities

New Apple Watch

The New Apple Watch Ultra 2 is Awesome

Apple is making waves in the smartwatch market with the introduction of the highly anticipated Apple Watch Ultra 2. This revolutionary device promises exceptional performance, robust design, and a myriad

Truth Unveiling

Unveiling Truths in Bowen’s SMR Controversy

Tony Wood from the Grattan Institute has voiced his concerns over Climate and Energy Minister Chris Bowen’s critique of the Coalition’s support for small modular nuclear reactors (SMRs). Wood points

Avoiding Crisis

Racing to Defy Looming Financial Crisis

Chinese property developer Country Garden is facing a liquidity challenge as it approaches a deadline to pay $15 million in interest associated with an offshore bond. With a 30-day grace

Open-Source Development

Open-Source Software Development is King

The increasingly digital world has led to the emergence of open-source software as a critical factor in modern software development, with more than 70% of the infrastructure, products, and services

Home Savings

Sensational Savings on Smart Home Security

For a limited time only, Amazon is offering massive discounts on a variety of intelligent home devices, including products from its Ring security range. Running until October 2 or while

Apple Unleashed

A Deep Dive into the iPhone 15 Pro Max

Apple recently unveiled its groundbreaking iPhone 15 Pro and iPhone 15 Pro Max models, featuring a revolutionary design, extraordinary display technology, and unrivaled performance. These new models are the first