Intelligent CISO Issue 46 | Page 33

Cyber-risk is no longer an IT problem , but a boardroom concern .

PREDICTIVE INTELLIGENCE

Mitigating cyberrisk becomes top priority for the boardroom

Saket Modi , Co-founder and CEO at Safe Security , explains why cybersecurity is no longer just the concern of IT departments but has become a dominant issue for the boardroom itself . s businesses

A continue to invest in Digital Transformation and base their business models on technology , cyberthreats only become more imminent . Cyber-risk is no longer an IT problem , but a boardroom concern .

With cyberattacks disrupting Business Continuity , they pose a direct impact on the top and bottom line of an organisation ’ s balance sheet . Thus , making cybersecurity one of the top priorities of every organisation .
Challenges with traditional cybersecurity approach
The evolving breach trends verify that complying to frameworks alone can no longer holistically safeguard organisations . Frameworks such as ISO , NIST , PCI DSS and others are used as reference checklists for cybersecurity and risk management practices , however , they provide limited visibility .
Cybersecurity must be aligned in every organisation ; threats and missioncritical business needs , provided by products that deliver holistic and actionable insights .
The Frameworks ’ approach to risk-posture assessments is subjective , labourintensive and only offers point-in-time snapshots / assessments . They rely on a qualitative scale without any objective and quantitative measure to assess the security posture of an organisation .
Similarly , Security Rating Services represent an independent source of publicly accessible data to support some use cases . However , these services don ' t provide a complete assessment of security controls , as their information is primarily sourced from publicly accessing Internet IP addresses , honeypots , analysing Deep and Dark Web content and individual proprietary data warehouses .
New approach to cybersecurity
Today , the delegation of risk decisions to the IT team cannot be the only solution and must be a shared responsibility . The board and business executives are expected to incorporate the management of cyber-risk as part of their business
Saket Modi , Co-founder and CEO at Safe Security

Cyber-risk is no longer an IT problem , but a boardroom concern .

strategy since they are accountable to stakeholders , regulators and customers .
For the CROs , CISOs and Security and Risk Management Professionals to be on the same page , there has to be a single source of truth for communicating the impact that cyber-risk has on business outcomes , in a language that everyone can understand .
This is where Cyber Risk Quantification becomes a game-changer . There is a need for a solution which integrates with the entire security stack and gives a measurable analysis that supplements decision-making . This comprehensive information empowers CISOs and executives to make informed and timely data-backed decisions to ensure the cybersecurity of the organisation .
Continuous assessment of cybersecurity is the need of the hour
Compliance and government guidelines mandate the move to go beyond periodic assessments and into www . intelligentciso . com
33