Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 블로그

구독

What COVID-19 Response Strategies Tell Us About the Business-Cybersecurity Disconnect

As organizations around the world raced to develop strategies to respond to the COVID-19 pandemic, an independent business risk study shows cybersecurity leaders were largely left out.

The way in which organizations plan for and manage business risk is among the many profound changes taking place as a result of the global COVID-19 pandemic. Yet, many cybersecurity leaders are still struggling to get a seat at the table. 

In fact, a study conducted by Forrester Consulting on behalf of Tenable reveals an alarming disconnect between business and cybersecurity leaders. Although nearly all respondents (96%) say their organizations have developed COVID-19 response strategies, 75% say that business and security efforts are only “somewhat” aligned, at best.

This is deeply concerning at a time when the sudden, widespread embrace of work-from-home models in response to the pandemic is unleashing a plethora of end-user devices upon corporate networks. Remote desktops, once a nice-to-have offering for a select group of workers, are now essential tools used by scores of employees to keep organizations running. Employees are suddenly connecting to core business systems and applications using their own previously untested — and potentially vulnerable — consumer routers and home networks. The popularity of internet-of-things (IoT) devices makes them potential threat vectors. The average home network could include an Amazon Alexa or other voice-activated tool, internet-connected TVs and video game devices, and assorted laptops, tablets and phones belonging to spouses, children or others in the household.

The Brookings Institute estimates that, as of April 9, 2020, up to half of American workers were working from home, which it calls “a massive shift.” Indeed, a Pew Research study shows that, prior to the pandemic, only 7% of civilian workers in the United States — roughly 9.8 million of the nation’s approximately 140 million civilian workers — had access to a “flexible workplace” benefit or telework option.

And cybercriminals are swooping in to take advantage of the exponentially expanding attack surface. According to the Forrester study, as of mid-April 2020, four in 10 organizations (41%) had already experienced at least one business-impacting* cyberattack as a result of a COVID-19-related phishing or malware scheme. The data, based on an online survey of more than 800 business and cybersecurity leaders in 10 countries, is drawn from the study, The Rise of the Business-Aligned Security Executive

COVID-related scams were the No. 1 source of all business-impacting cyberattacks reported in the study. Although the World Health Organization had only declared COVID-19 a pandemic a few weeks earlier, by the time the survey was conducted COVID-related attacks had already outpaced other business-impacting attacks such as fraud (40%), data breach (37%), ransomware (36%) and software vulnerability (34%).

On a personal level, I find the survey results oddly validating: They confirm I’m not the only security leader worried about these trends. Two out of three respondents to the Forrester survey (67%) say they are very or extremely concerned that the workforce changes necessitated by COVID-19 will increase their organization’s level of risk. 

Making matters worse, roughly half of the cybersecurity leaders (48%) surveyed say they have only moderate to no visibility into their remote, work-from-home employees.

One of the key ways to bridge this disconnect is for organizations to bring cybersecurity into the fold when developing risk management strategies. 

How risk management can help you become a business-aligned cybersecurity leader 

CISOs, CSOs and other cybersecurity leaders are uniquely suited to taking on a bigger role in risk management and the related disciplines of business continuity, disaster recovery and crisis management. Our work puts us squarely at the intersection of technology and business. We have visibility into all of the systems, data and processes required to deliver on a business continuity and disaster recovery plan. Being involved in risk management can also make your job a little more manageable: If you can understand all of your critical processes and assets from a broad enterprise risk perspective, it will only make you stronger in cybersecurity as well. 

There’s also a clear operational benefit to be gained from performing risk management exercises which can serve as a bridge between the business and the infosec sides of the organization. What is revealed in the process will help the entire organization understand how to best prioritize resources — both human and financial — to keep the business running even during a crisis.  

Sentara Healthcare: a case study in effective alignment

Sentara Healthcare offers a case study in effective alignment. In an interview with Tenable, Dan Bowden, CISO at Sentara Healthcare, noted that at the start of the pandemic, the organization’s IT and security teams found themselves charged with two crucial tasks: enabling a large number of employees to work from home; and helping to convert regular hospital rooms to serve as intensive care unit (ICU) rooms by switching out the operational technology (OT) and internet of things (IoT) systems needed to care for a sudden influx of critically ill patients.

“In March and April, I would say over 50% of our total work effort was dedicated to building ICU room capacity, and figuring out how [we can] use technology to reduce personal protective equipment (PPE) burn,” said Bowden.

While the transitions were ultimately successful, the organization’s patching process was thrown into a two-month disarray as a result.

“I'm a very aggressive vulnerability scanning CISO, and my team is [as well],” said Bowden. “We have a demand-based policy of what happens when we find a new vulnerability. And we had to tweak our vulnerability scanning timing and our patching policy a little bit because our IT teams were changing the beds in hospitals. A regular [hospital] room is configured a certain way from a technology perspective. And when you change that to an ICU room, there's a cascading change across a bunch of technology systems and applications that accompany that. Our infrastructure and application teams were very busy changing our surface of beds that we offered from a small number of ICU beds to a very large number of ICU beds. So we had to figure out how to continue complying with our patching schedule in a way that we could manage risk efficiently and effectively. We relied on Tenable's Vulnerability Priority Rating a lot for that. We probably used it much more aggressively this spring and summer than we have in the past.”

By June, the patching process was back on track. Now, as the fourth quarter approaches, Bowden is faced with significant budget decisions — as are so many industry sectors that experienced the economic impact of COVID-19. “We're trying to reduce [operating expenditures] and get back on budget. How do we make 2020 a break even year? We are very focused on basic lights on, doors open operations as well as any new requests that arise due to variations in COVID-19 spread.”

Bowden adds: “We have a very progressive leadership team that is saying to all of us ‘be creative, help us figure out how we grow in the midst of all this.’ So we've got a few big projects to tackle relative to that as well.” 

Showing return on cybersecurity investments

At a time when organizations worldwide are facing a potentially lengthy period of economic uncertainty, it becomes more critical than ever to prioritize investments based on risk. The Forrester study shows that when security and the business are aligned, they deliver notable results. For example, 85% of business-aligned security leaders have metrics to track cybersecurity ROI and impact on business performance versus just a quarter (25%) of their more reactive and siloed peers. The business-aligned security leader is also eight times as likely as their more siloed peers to be highly confident in their ability to report on their organization’s level of security or risk. And the vast majority (86%) have a process that clearly articulates expectations and demonstrates continuous process improvement, compared with just 32% of their more reactive and siloed peers. 

Getting involved in the development of your organization's Enterprise Risk Management (ERM) strategy will put you on the path to becoming a business-aligned cybersecurity leader.

These six steps will help with your initial enterprise risk identification and assessment:

  1. Develop and distribute a risk assessment survey to key stakeholders. These are typically fielded to the senior director level and above and should include representatives from all of the major departments in your organization, including finance, legal, human resources, information technology, information security, sales, operations, marketing and R&D. Once your survey is complete, you’ll want to organize the responses into risk categories so you can compile an inventory of enterprise risks.
  2. Conduct research and analysis to compare your organization’s enterprise risks to industry risk surveys.
  3. Develop a risk assessment methodology, including probability and impact, to get a total risk rating. 
  4. Identify key leaders in your organization and devote time to interviewing them to get their feedback on risks and prioritization as well as risk probability and impact.
  5. Present your risk assessment results to executives to finalize the top risks and assign executive risk owners.
  6. Work with executive risk owners to identify mitigation activities for the top risks.

Performing the above steps is a painstaking exercise that yields a high degree of benefit by giving you a clear set of priorities. You’ll have an agreed-upon list of enterprise risks. While cybersecurity is likely to be its own standalone enterprise risk, it will certainly impact many, if not all of the enterprise risks in some form. 

Couple the enterprise risk assessment with a business impact analysis — essential to business continuity and disaster recovery to determine which critical systems and business processes your organization can least afford to live without — and the two serve as the foundation for developing a business-aligned cybersecurity strategy. You’ll emerge with a list of your most critical enterprise risks and processes, making it equally possible to clearly prioritize responses in a time of crisis — regardless of whether the crisis results from a cyberattack, a natural disaster or a global pandemic — and when normal business operations resume. 

In stable times, it’s all too easy for organizations to treat enterprise risk management as a mere check-box exercise best left to a segregated team of risk professionals. With COVID-19, business and technology leaders have found themselves enrolled in a crisis management crash course. It’s up to each of us to take this as an opportunity to rethink our approach to enterprise risk so we’re better prepared for the down times and well positioned to benefit when things are going well. 

Read the blog series: How to Become a Business-Aligned Cybersecurity Leader

Blogs in this series focused on the challenges of aligning cybersecurity and business and why cybersecurity leaders struggle to answer the question "how secure, or at risk, are we?". We also examined what COVID-19 response strategies reveal about the business-cyber disconnect, discussed why existing cybersecurity metrics fall short when communicating cyber risk, explored five steps for achieving alignment with the business and provided a view into a day in the life of a business-aligned cybersecurity leader.

Learn more:

*For the purpose of this survey, “business-impacting” relates to a cyberattack or compromise that resulted in one or more of the following: a loss of customer, employee or other confidential data; interruption of day-to-day operations; ransomware payout; financial loss or theft; and/or theft of intellectual property.

관련 기사

도움이 되는 사이버 보안 뉴스

이메일을 입력하여 Tenable 전문가에게서 적시에 알림을 받고 보안 참고 자료를 놓치지 마십시오.

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오.

Tenable Vulnerability Management 평가판은 Tenable Lumin 및 Tenable Web App Scanning을 포함합니다.

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오. 지금 연간 구독을 구매하십시오.

100 자산

구독 옵션 선택:

지금 구매

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오.

Tenable Vulnerability Management 평가판은 Tenable Lumin 및 Tenable Web App Scanning을 포함합니다.

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오. 지금 연간 구독을 구매하십시오.

100 자산

구독 옵션 선택:

지금 구매

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오.

Tenable Vulnerability Management 평가판은 Tenable Lumin 및 Tenable Web App Scanning을 포함합니다.

Tenable Vulnerability Management

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오. 지금 연간 구독을 구매하십시오.

100 자산

구독 옵션 선택:

지금 구매

Tenable Web App Scanning 사용해보기

Tenable One - 위험 노출 관리 플랫폼의 일부분으로 최근의 애플리케이션을 위해 설계한 최신 웹 애플리케이션 제공 전체 기능에 액세스하십시오. 많은 수작업이나 중요한 웹 애플리케이션 중단 없이, 높은 정확도로 전체 온라인 포트폴리오의 취약성을 안전하게 스캔합니다. 지금 등록하십시오.

Tenable Tenable Web App Scanning 평가판은 Tenable Lumin 및 Tenable Web App Scanning을 포함합니다.

Tenable Web App Scanning 구입

비교할 수 없는 정확도로 모든 자산을 확인하고 추적할 수 있는 최신 클라우드 기반 취약성 관리 플랫폼 전체에 액세스하십시오. 지금 연간 구독을 구매하십시오.

5 FQDN

$3,578

지금 구매

Tenable Lumin 사용해 보기

Tenable Lumin으로 위험 노출 관리를 시각화하여 파악하고 시간에 걸쳐 위험 감소를 추적하고 유사한 조직과 대비하여 벤치마킹하십시오.

Tenable Lumin 평가판은 Tenable Lumin 및 Tenable Web App Scanning을 포함합니다.

Tenable Lumin 구매

영업 담당자에게 문의하여 어떻게 Tenable Lumin이 전체 조직에 대한 통찰을 얻고 사이버 위험을 관리하는 도움이 되는지 알아보십시오.

무료로 Tenable Nessus Professional 사용해보기

7일 동안 무료

Tenable Nessus는 현재 구입 가능한 가장 종합적인 취약성 스캐너입니다.

신규 - Tenable Nessus Expert
지금 사용 가능

Nessus Expert는 외부 공격 표면 스캔닝과 같은 더 많은 기능 및 도메인을 추가하고 클라우드 인프라를 스캔하는 기능을 추가합니다. 여기를 클릭하여 Nessus Expert를 사용해보십시오.

아래 양식을 작성하여 Nessus Pro 평가판을 사용해보십시오.

Tenable Nessus Professional 구입

Tenable Nessus는 현재 구입 가능한 가장 종합적인 취약성 스캐너입니다. Tenable Nessus Professional은 취약성 스캔 절차를 자동화하고 컴플라이언스 주기의 시간을 절감하고 IT 팀과 참여할 수 있도록 합니다.

여러 해 라이선스를 구매하여 절감하십시오. 연중무휴 전화, 커뮤니티 및 채팅 지원에 액세스하려면 Advanced 지원을 추가하십시오.

라이선스 선택

여러 해 라이선스를 구매하여 절감하십시오.

지원 및 교육 추가

무료로 Tenable Nessus Expert 사용해보기

7일간 무료

최신 공격 표면을 방어하기 위해 구축된 Nessus Expert를 사용하면 IT부터 클라우드까지, 더 많은 것을 모니터링하고 조직을 취약성으로부터 보호할 수 있습니다.

이미 Tenable Nessus Professional을 보유하고 계십니까?
7일간 Nessus Expert로 무료 업그레이드하십시오.

Tenable Nessus Expert 구입

최신 공격 표면을 방어하기 위해 구축된 Nessus Expert를 사용하면 IT부터 클라우드까지, 더 많은 것을 모니터링하고 조직을 취약성으로부터 보호할 수 있습니다.

라이선스 선택

여러 해 라이선스를 구매하여 비용을 더 절감하십시오.

지원 및 교육 추가