Cyber Advisers

Cyber Advisers

Share

Cyber Advisers helps small and medium size organizations build advanced risk management capabilities by leveraging "Cyber-Security as a Service".

09/26/2023

Five dysfunctions in Cybersecurity – Report from the trenches.
Of late, I have been doing a lot of hands-on cybersecurity work in the trenches. I have gained a renewed appreciation for the need to use appropriate metrics to prevent efforts resulting in dysfunctional controls.
1. Dysfunctional Governance: Cybersecurity Governance in its essence, should clearly delineate “who makes what decision”. Instead of Security SMEs, decisions are often made by managers who are influenced by competing factors. Remember Trump vs. Fauci.
2. Dysfunctional Budget: A minimum of 1% of revenue should be allotted to security, privacy, compliance, and cyber insurance. It is the cost of doing business in a digital hyper-connected space. For reference, NATO recommends 2% of GDP on defense expenditure.
3. Dysfunctional Structure: Security leadership reporting to the Infrastructure Teams. This is often done in the name of streamlining and productivity. The two teams have conflicting objectives; because of this action, the fiduciary responsibility of the cybersecurity team is severely muted.
4. Dysfunctional Accountability: Securing sensitive and confidential information should be a full-time responsibility for any organization. Giving another leader the responsibility of securing the organization as an add-on responsibility is naive. Direct reports to the CIO are often willing to wear multiple hats to transition into the CISO role. If a leader is interested in taking responsibility for cybersecurity, the practical solution is to have them relinquish all other duties and transfer them into the security role.
5. Counter-intuitive Security Classification: For instance, tagging contractors or admins as a security control mechanism is counterintuitive. There is no correlation between insider threat and type of workforce. Inadvertently, you violate the zero-trust principle and send the wrong signal by implying that some are equal among equals.

11/30/2018

My first book on Amazon KDP.

Want your school to be the top-listed School/college in San Jose?

Click here to claim your Sponsored Listing.

Location

Category

Telephone

Address


2612 Painted Rock Drive
San Jose, CA
95051

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm