iTnews
  • Home
  • News
  • Technology
  • Security

Security chiefs urged to embrace risk

By Phil Muncaster
Apr 4 2008 4:01PM
Follow google news

Chief information security officers were urged to take a more strategic approach to guarding corporate networks at a gathering of security leaders in Amsterdam this week. The current obsession with tactical issues raised costs and impeded business efficiency, they were warned.


Speaking at the start of its Security Forum EMEA in Amsterdam, Forrester Research principal analyst Jonathan Penn argued that CISOs need to create efficiencies through strategies like outsourcing, and then invest in tools to measure and report on these efficiencies in a way their chief executives can understand.

"CISOs are asking themselves 'how can I meet the challenges if I don't have the budget or skills in my team that I need?'," he said. "They should be looking at things that aren't too complex but can make a difference."

"CISOs' lack of influence comes from having to respond to every single security issue and not focus on projects which can help them gain influence," he added. "So they need to work more with business groups by setting up things like security steering committees to get buy-in for projects."

Quick-win projects may include ensuring application bugs are fixed during the development phase, a greater focus on staff training, and introducing a proactive scanning and patching system for system vulnerabilities, he added.

IT security chiefs are rarely afforded much time to flesh out business cases, so it is imperative they can convey their priorities succinctly, argued Andrew Strong, global security director of Unilever. Getting business backing for security initiatives required him to design processes which were "lightweight, understood and business-relevant".

He estimated that he is given "half an hour" to explain security priorities t o other executives. Unless he can do that, he "won't get into their diary," he said.

Strong added that executive sponsorship is vital for transformational risk management initiatives, but that establishing dialogue with key sponsors can be a long process. "You need to determine their risk appetite, but it takes some time – new personalities can come in, people change and priorities change with that," he said.

He also advised firms to create a decision-making framework to ensure all stakeholders are working to the same consistent definitions of risk. This can enable the business to manage risk themselves and only use the security department "as a trusted advisor in an exception", Strong added.

The ability to define security policies in terms of risk was gaining acceptance with the financial services sector, reported Jan Douw, a director in risk and security at banking giant ING. Colleagues are practised at assessing risks, and find it easier to assess the business impact of IT security when it is expressed in terms of risk, he added: "The better it is understood and managed the more growth can be achieved."

But there can be dangers when explaining IT risks to business colleagues, he warned. "As risk managers we need to try and find a way to interest and work with business managers," he explained. "But never accept responsibility for risk, that is the line manager's responsibility."

Douw added that security risk managers should follow existing processes - such as the Basel II Advanced Measurement Approaches (AMA) for operational risk - when they engage with the business, rather than inventing new risk management processes

In an opening keynote at the forum, Forrester analyst Thomas Raschke argued that although CISOs are beginning to appreciate the importance of risk management initiatives, many still ignore "the risk elements that are not obvious". He added that technology should only form a very small part of the overall security strategy.

"You need to understand business risk and tolerance, translate risk decisions into risk policies, codify those policies into processes, then support the processes with technology and people," he explained. "Technology should not take up most of your time; it's just a small layer between the processes and people."

Forrester's Penn added that firms must include corporate as well as customer data in their data security programmes, as many firms underestimate the cost of intellectual property breaches.

"When you lose corporate data it won't get in the headlines but could be just as damaging and the controls you put in place should be the same," he explained. "There are a lot of compliance requirements looking at data protection and having a compliance framework to rationalise controls is important otherwise people spend recklessly on piecemeal solutions."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
itweek.co.uk @ 2010 Incisive Media
Tags:
chiefsembracerisksecuritytourged

Related Articles

  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
  • US gov shortens cyber fix window to three days US gov shortens cyber fix window to three days
  • Anthropic releases Mythos-class model for public use Anthropic releases Mythos-class model for public use
  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
Join our WhatsApp Channel

Partner Content

Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.