You’re Going To Be Hacked, So Get Ready

Relentless Preparation

The worst thing leaders can do is wait and see. You can invest in the best people, processes and tools but if you don’t practice, the cybersecurity machine you invested so much capital in won’t be affective in real-world response and detection. Think of cybersecurity strategy as a soccer team. You can recruit top talent for every position. But if you don’t get every player on the same field practicing and scrimmaging together, they won’t win an actual game. Enter, wargames.

Testing out attack scenarios in wargames—simulations where mock attacks can be played out in controlled arenas—is a crucial piece of any cybersecurity plan. But not enough companies are taking advantage of them. Some cybersecurity questions tested during a wargame include:

  • What decisions are required of executives during a cyber attack?
  • What are the potential unintended consequences?
  • What risks present the greatest challenges during a cyber attack and why?
  • What internal and external communication channels are essential for effective response?

Leaders must establish regular wargame and exercise programs to train the C-Suite, cyber defenders, and IT administrators. These scenarios should not be solely focused on the capacity to mount a tactical cyber response. Rather, wargames should be firmwide and multifaceted to identify threat scenarios, enterprise needs, best practices, and stakeholder concerns.

Out of these regular wargame practice sessions, companies can develop, test, and constantly refine their response plans. This relentless preparation ultimately leads to increased cyber resilience and brand protection for any company, large or small.

Building a Culture of Security, From the Top Down

Practice alone isn’t enough. Government and business leaders need to foster a culture of security and provide individuals with the tools and knowledge to protect themselves. To do this, one common misconception must be addressed.

Many government and business leaders think security rests in the hands of a single person: the chief information security officer (CISO). But a company’s cybersecurity must not be the responsibility of one individual, nor should it be siloed to one team. Leaders must hold everyone accountable. From accountants and developers, to marketing professionals and sales teams – everyone has a role to play.

True security starts and ends with individual users across an organization. After all, phishing scams, or fraudulent emails, are still the number one form of attack today. The CISO can provide guidance and tools to empower leaders across a company. But all executives must be accountable and considered cybersecurity leaders. That tone of accountability and culture change must be set from the top.

There’s no cybersecurity silver bullet for leaders. Companies need to keep up with the best technologies, processes, and talent. But even the best are going to get hit. It’s a matter of preparedness. And to be prepared, sometimes it’s best to go back to the basics: practice and culture change. 

Meet the Author

Tags

Archive
1 - 4 of 8