CEO Blog

Tweet about this on TwitterShare on LinkedInShare on FacebookShare on Google+Email this to someone

Governance, Risk and Compliance in Real-time for real security

Is your IT Security team equipped to protect your organisation? Does your executive team get WHAT they need, WHEN they need it….to make informed decisions? Providing meaningful, actionable intelligence about security issues, to multiple stakeholders in a language they can understand is fundamental to the success of business. Reports that meet the needs of middle managers differ from those appropriate for operational teams, or from those intended for the board. Reporting should be tailored for the audience.

The majority of enterprises are required either by law or an industry regulator to meet a variety of information security standards: PCI-DSS, HIPAA, NIST or the Australian Signals Directorate’s ISM/UK CESG’s GPG13, to name but a few. Alignment with internationally recognised information security standards, such as COBIT or ISO 27001, can also demonstrate to customers, suppliers or partners that your business takes information security seriously.   The question is though….. how do you get measureable improvement in your security posture as a result of ongoing investment in your information security?

 Security Management and GRC

The three main pillars of organisational control, Governance, Risk and Compliance (GRC), underpin any effective information security management system (ISMS), irrespective of whether it’s a home-grown ISMS or based on a standard like the ISO 27000 series. Each of these foundational pillars should be integrated into the DNA of the business to allow relevant information to flow between the management and security teams, to make sure the business’s strategy is successfully implemented despite the variable cybersecurity environment.

GRC has become synonymous with assurance frameworks and costly audits that deliver little in the way of sustained improvement in security resilience. The importance of these controls demands closer attention; and that is why Huntsman® originally released continuous GRC reporting and dashboards to enable continuous operational feedback for organisations as they negotiate today’s operating environment.

Huntsman® delivers Real-time GRC Reporting

Huntsman Security understands the importance of security GRC and how it should be embraced as an enabler to improve operational posture; but it’s more than that, particularly as it relates to cyber security, where the implications of GRC need to be understood by stakeholders across the organisation.

A new approach is required that more directly addresses the interdependency between the business and its operational security team. GRC has the ability to tie security into the organisation at all levels so the relevance of any change in the technological status quo is recognised for both its security and business impact. Business stakeholders need security GRC information to be translated into a language they can understand and a form that they can act upon.

Huntsman®’s Answer for business: Real-time Role Based Reporting

Our challenge was to develop a business-centric reporting solution that provides tailored security metrics to meet the needs of the different business stakeholders for fast, effective decision making.  They needed to align with GRC controls and compliance frameworks with information being available in real-time, as dashboards, displaying context to each audience to allow responders to comprehend and action threat intelligence.

I’m delighted to say that the Huntsman® team has now delivered a brand new reporting capability that we are extremely proud of: Role Based Reporting. The interface provides business-relevant security and compliance reporting, that highlights the effect of any given risk across the governance and compliance landscape, immediately reporting on its implications for the report audience.

No longer will business managers be trying to understand what the operational security GRC report means or its implications for the board. Role Based Reporting will highlight what the GRC report means to them, the business implications and any bases upon which resulting business decisions need to be made. In a digital world cyber security is like any other risk, it needs to be managed and Huntsman® Role Based Reporting makes the identification, implications and management of that risk much easier for all stakeholders.

Cisco’s latest report shows why automated threat verification should be a key weapon in your cyber security armoury


I was concerned to read the latest findings of the Security Capabilities Benchmark Study in the Cisco 2016 Annual Security Report. Concerned, but not too surprised. The global study surveyed security heads in organizations of various sizes from different industries. It looked at their perceptions of security operations and practices.

One of the report’s key findings was that the confidence of security professionals in their security readiness seems to be dwindling as cyber threats become more sophisticated. The report concludes, inter alia, that organizations should deploy tools that detect threats, and explore effective solutions to help ensure an integrated threat defence.

I couldn’t agree more.

So, why is confidence in security readiness falling?

Too often, I’m hearing concerns from organisations I visit about products that just don’t deliver as promised. They not only feel they have wasted some of their precious security budget – they are also starting to lose faith in the efficacy of security products. And the dearth of solid, independent advice on the right technology to invest in is making it even harder for them to make an informed decision.

Automated threat verification brings a step change to how business can deal with cyber risk.

I’d strongly advise all organisations to look into proven security solutions that integrate with and support existing investments. The Huntsman Analyst Portal® automatically aggregates and examines threat information from a range of sources across the enterprise to deliver real-time threat verification. Automating the threat verification process brings huge advantages. Obviously, the faster you detect and understand a security breach, the sooner you can respond, avert data loss, reduce impact, safeguard reputation, and meet regulatory obligations.

Automation also brings repeatable and streamlined processes that save analysts from fire-fighting, data-crunching, and dealing with a mountain of false positives. It frees them up to proactively hunt for undetected threats, active attacks, vulnerabilities or signs of misuse or compromise.

Investing in automated threat verification technology doesn’t mean you have to ‘rip and replace’ your current security technology. A major benefit of the Huntsman Analyst Portal®, for example, is that it integrates with, and leverages, your existing security investments and processes. It means that earlier security investments can continue to yield a return.

Creating the right culture is also critical.

As Cisco correctly points out, having the right technology is only part of the solution, because security is built up by technology, people and cultural processes working together. All organisations also need to create a culture that underscores the importance of security, to provide an environment that is as close to Cyber Resilience as you can get.

You can read the key findings of the CISCO study at http://apjc.thecisconetwork.com/site/content/lang/en/id/5279.

 

Can we really manage Cyber Risk?


When I used to speak to organisations about the need to manage their cyber risk, my recommendations were often met with blank looks and “we’ve never had a problem”.

Now, cyber-crime is rightfully recognised as a significant risk to the business of every organisation.

The nimbleness of cyber criminals, and the ease with which they regularly breach defences, has many managers asking: what should we do to manage cyber risk?

Firstly, there are no silver bullets and don’t believe anyone who is offering one.

There are however a few steps your organisation can take.

Internal controls

There are internal controls every organisation should have to boost cyber resilience. These include firewalls, AV gateways, malware sandbox solutions, IDS/IPS, network access controls, and host/endpoint protection. Building in-house security skills and awareness will increase the effectiveness of these investments.

Threat detection

Despite these internal controls, breaches can, and do, occur. So your organisation also needs to deploy threat detection and response measures.

Today, there are a few excellent applications – like Huntsman’s defence-grade security platform – that detect threats in real time and cut the time your organisation is exposed to cyber risk to seconds.

These applications can reduce the potential financial impact, reputational damage and remediation costs that inevitably flow from a breach.

Outsourcing

As well as internal controls and threat detection, your organisation will probably also need to outsource expertise in areas like penetration testing, assurance, incident response and – perhaps most importantly – monitoring. A 24/7 monitoring service can detect alerts and other indicators of security compromise like anomalous network traffic patterns, and unusual behavior on the IT system.

Insurance

Finally, there’s insurance, to assign your cyber risk to an insurer.

Like any insurance policy, the premium correlates with the size of the risk. So anything your organisation can do to limit that risk should reduce the premium.

But beware: if your organisation does not have the requisite internal controls in place, an insurer may prove unwilling to underwrite your risk.

Key take-out

So, in a nutshell, cyber resilience requires a balance of building internal capabilities, procuring outside help where you need it, and insuring against any related risks you can’t reasonably manage.

The investment may seem large. But the consequences of not adequately addressing cyber threats can be massive.

If you’d like to know more about how to boost your organisation’s cyber resilience, please feel free to contact me at Huntsman Security.

 

Cyber Security Predictions for 2016

  

Welcome back for 2016. As it turned out 2015 was a year marked by the increasing number, scale and prominence of security breaches as cyber risk to businesses increased and spread. Additionally and probably related, the technology environment in which enterprise security teams operate became more complex.

At the start of 2016, the continuing arms race between attackers and defending organisations suggests no let-up in the need for preparedness.

Traditionally, companies that suffer from attacks or data losses have been “fair game” for professional advice meted out by profile seeking experts. But we shouldn’t be too hasty in our condemnation of the victims. In a number of recent cases, once the furore died down, there was often more to a story than met the eye. Organisations that fall victim to many of these attacks are not always as careless or naive as first appears and we should learn from their experiences.

The continuing skills shortage of cyber security resources, for example, is a case in point. This talent shortfall impacts absolutely on what can be achieved when cyber defenders are faced with an increasing volume of complex attacks to address.

This will become a profound trend in 2016, one in which Huntsman® is at the vanguard, and that is the development of automation and orchestration of security technologies that:

  1. provide “cleaner” security intelligence by pre-qualifying alerts to weed out false positives, benign threats or mitigated vulnerabilities;
  2. support investigators to more quickly understand the threats that matter by aggregating relevant diagnostic data as it happens from networks, applications, platforms and end-points and automatically initiating the investigation processes;
  3. provide greater confidence in the interpretation of threats to enable faster and more certain evidence-based decision making; and
  4. integrate with network and systems orchestration technologies to implement a response to quarantine affected systems, mitigate ongoing attacks or increase the volume of diagnostic data collected about a particular threat.

Compounding these observations, is the growing complexity of the IT environments; both cloud and mobile adoption are continuing apace and the massive rise of connected devices (often referred to as the “Internet of Things”) means that the enterprise IT environment is increasing in scale and diversity, is less controllable, and increasingly suited to machine based analyses for timely threat resolution.

In short, businesses have an increasing challenge to secure their networks and that’s before you factor the plethora of new security technologies;  see the latest batch released at the recent Consumer Electronics Show in Las Vegas www.cesweb.org. As an industry we will continue to be challenged on a number of fronts in 2016 as we stretch the capacity, and maybe even the ability, of security teams to monitor their environments and respond to early signs of threats.

 

Cyber Risk reduction: Why Automated Threat Verification is key

  

Alarmingly, recent findings indicate that organisations are increasingly exposed to cyber security risk for longer periods of time. This is despite ongoing investment in deployments of up-to-date threat intelligence platforms and teams of highly skilled security experts. It’s little wonder that industry experts are calling for a new weapon to reduce the time between threat detection and resolution. Automated threat verification promises to do just that, filling an important hole in the incident management process.

Whilst large volumes of new intelligence provides valuable contextual threat information, there is no doubt that finding a better way to process is shifting to front of mind for the security industry. Mandiant 2015 M Trends Report notes: despite security investments the improvement over the last year’s average time from infection to detection was a single day, 205 to 204. This is a real problem and it’s before an analyst or data scientist starts to investigate and resolve a single threat.

Why so long? Well, all too often this flood of new threat intelligence is presented to the SOC team in inaccessible information silos that require manual collation, analysis and interpretation. On top of that threat intelligence is often mistakenly flagged as malicious when in fact it’s benign and will not impact the enterprise. This means security analysts often end up spending countless hours, distracted from the threats that matter, sifting through this logjam of potential ‘threats’ – only to find its a false alarms.

The cause of this situation is ‘intelligence overload’ as organisations try to interpret more and more new threat intelligence using their existing security resources. This manual solution, for an industrial problem, is proving very costly for organisations – not just in terms of the expense of finding, hiring and retaining these expert security analysts, but also because of the time at risk to cyber threats.

Adding to the problem is the apparently global shortage of security analysts able to comb through the mountain of potential cyber threats to find the ones that matter. Cisco suggests we are short 1 million analysts.

The solution is already here – automated threat verification

The Huntsman Analyst Portal® delivers a step change in threat management by automatically verifying threats, removing false alarms, and quickly pinpointing the threats that matter. This has two key benefits for every organisation:

  • It slashes the time at risk. Huntsman shrinks the delay between threat detection and response to seconds. This means security analysts can focus on the most risky threats; contain them, stop the loss, and minimize the time at risk.
  • It dramatically cuts costs. Huntsman reduces the workload of the security team by automating routine investigation workflows, and streamlining the processes of the Security Operations Center (SOC). The end result is better decisions at a significant cost saving.

Only this week Cisco demonstrated an aligned vision by announcing the deep integration of pxGrid and the Huntsman Analyst Portal®. PX Grid, launched one year ago, provides a suite of context sharing and network control capabilities that enable Cisco ecosystem partners to extend their reach into the network infrastructure and take “Rapid Threat Containment” actions. We are delighted to announce that Huntsman Security has integrated both the “User Access and Device context” and “network control” capabilities into the Huntsman Analyst Portal®, enabling delivery of:

Real time automated correlation of pan-platform intelligence

Real time threat verification of all validated threats

Rapid Manual & Automated Threat Containment…..in seconds

Put simply, when it comes to speed from threat detection to resolution, Huntsman Analyst Portal® is the fastest, most cost-effective way to slash your time at risk to seconds.