Extreme Weather WILL happen. Cyber Attacks WILL happen. WILL You be Prepared WHEN they strike??
In this blog, I compare cyber threats and natural disasters to explain why a cybersecurity strategy is an important component of business risk management. You can take a proactive, well-planned, level-headed and measured approach to security. The need for security is immediate, and it will never go away.
As part of your risk management efforts, you plan for potential extreme weather events …floods, tornados, drought or hurricanes. You want to make sure your business, and especially your people make it through the storms safely. So you appoint someone to be in charge of emergency management planning. Have you assigned someone to plan for cyber-related emergencies?
We hear: “My company is small. We really don’t think we are a target for cyber attack.”
Consider: Just like extreme weather, you must recognize that cyber attacks are inevitable.
In fact, the risk of cyber threats is eerily similar to natural disasters. The World Economic Forum recently published its Global Risks Report 2018, which assesses and ranks a wide range of Economic, Geopolitical, Technological, Environmental and Societal Risks.[ii]
That’s right. Cyber attacks are just as likely to occur as natural disasters. To ensure your organization’s ability to recover, you need to have a game plan BEFORE disaster strikes.
Government
Municipal, Federal and State agencies prepare widespread alert protocols using emergency response systems… storm sirens, evacuation plans and press conferences to warn the public of pending danger. The Government documents these protocols in Disaster Recovery Plans. The hope is that government agencies can minimize the impact of natural disasters and restore the hardest hit areas to a “normal” state as fast as possible. I hear my local government testing its storm sirens on the first Tuesday of every month.
Business
When your office building was designed, the architect added safety features to protect the building’s tenants.
When your business moves in:
Hopefully, you never have to find out if all the planning pays off.
Planning is critical to managing cyber risk. You should create topic-specific Security Plans:
Test Your Defenses
You also need to test your Cyber Incident Response and Disaster Recovery capabilities, at least annually.
Train Your People
When you run fire drills, its to make sure people know what to do if a fire strikes. You should do the same thing with cybersecurity. Ask your CIO if you have ever had a problem because a user clicked on a nefarious link in an email. Training may prevent those occurrences.
EVERYONE in your organization has some responsibility to protect the organization and themselves.
Hopefully, you now understand that just like with severe weather, you may not be able to stop a cyber attack from happening, but you can prepare for its impact. If your Risk Manager has security experts in-house, hopefully, you will get to work right away. If you don’t have security resources available, you may want to consider outsourcing the function, particularly if cost is a concern.
[i] https://smallbiztrends.com/2017/01/cyber-securitystatisticssmall-business.html
[ii] https://www.weforum.org/agenda/2018/01/these-are-the-biggest-risks-the-world-faces-in-2018/
About SCS
Secure Compliance Solutions LLC (SCS) provides a suite of cybersecurity consulting and managed security services to fortify your Information Security and Data Privacy programs. We implement technical solutions to safeguard your assets. We drive security strategies to manage business risks, meet regulatory requirements and promote a culture of readiness and resilience.