sb-nz logo
Story image

Addressing cybersecurity transparency for stronger protection

20 Sep 2017

Security firm Aleron says that cybersecurity management is a complex problem and transparency can result in even more ambiguity.

Because every organisation uses different processes to security, this can result in inefficiencies and weaknesses, the company says.

If organisations are to stop attacks, they need to have clear views of the threats they face and the ability to develop risk mitigation strategies.

“Two things are happening every day: new cyberattacks are launched; and new tools and solutions to combat cyberattacks are introduced. The rapid pace at which the threat landscape is evolving makes it difficult for senior managers to know if the company’s investment in security is effective,” comments Aleron director Alex Morkos.

“On top of that, there is often disjointed communication between security teams and senior leaders. This is partially because highly-skilled cybersecurity professionals often lack sophisticated business communication skills.”

According to Aleron, there are five key challenges to achieving transparency:

•  Getting a clear picture of the cyber threats they face  •  Understanding if their investment in cybersecurity solutions is effective  •  Making well-informed cybersecurity decisions that meet the organisation’s overarching objectives  •  Accessing the skills and resources needed to effectively protect the organisation  •  Managing security governance and compliance.  “Cybersecurity is a boardroom problem, yet information about cyber risks is not delivered as transparently and as clearly as it could be to that senior level, thus hindering board members’ understanding and ability to respond appropriately. To combat this problem, organisations need to find a better way to communicate the risks internally and respond appropriately,” Morkos says.

Organisations should consider choosing systems that allow accurate and simple views of the current risks, as well as ones that detail which risks businesses should focus on.

The company says that organisations must invest in tools and systems that also help them understand security risks, self-asses and gain quick insights into their security options.

Compliance tools can also accelerate problem identification, saving businesses time and money before an attack strikes.

Story image
Why zero trust could fail due to lack of understanding​, not technology
Security architects are being forced to re-examine the concept of identity, with many turning to a zero trust security model to provide a better architecture for protecting their sensitive resources.More
Story image
Experiencing ransomware significantly impacts cybersecurity approach
"The survey findings illustrate clearly the impact of these near-impossible demands. Among other things, those hit by ransomware were found to have severely undermined confidence in their own cyber threat awareness."More
Story image
Palo Alto Networks launches new SD-WAN solutions and enhancements
Palo Alto Networks has introduced two new SD-WAN appliances and enhancements to its next-generation SD-WAN solution, expanding the company’s CloudGenix SD-WAN solutions reach.More
Link image
The importance of data resilience in the current cybersecurity climate
Protecting an organisation's data is one of the most crucial functions of any CISO. Strategies should be in place where data is stored securely and cost-effectively.More
Story image
Surfshark rolls out WireGuard open source VPN protocol
When there is less code in a VPN, it is less susceptible to security vulnerabilities due to easier configuration and management, according to Surfshark.More
Story image
Report reveals relationship between boardroom and cybersecurity investments
“While boards are definitely listening and stepping up with increased budget for cybersecurity, they tend to view any investment as a cost rather than adding business value."More