Posts

Hidden C/S: Job Descriptions

Image
This post is part of a series about aspects of cybersecurity which are not obvious, especially to newcomers. This post is about the cybersecurity aspects of the humble job description. What does cybersecurity have to do with job descriptions? To answer that question, let us go down the cybersecurity chain from start to finish. (1) Senior management signs off on a cyber asset as critical, which means that the asset is to be protected from at least one specific risk. This is Identify in the NIST CSF . (2) Someone in the cybersecurity program (CSP) assigns a "control" to that risk for that asset. This is Protect in the NIST CSF. This step includes agreeing on what constitutes proof that the control is effective. (3) Monitoring that control becomes part of someone's job. This is Detect in the NIST CSF. (4) Sharing the results of that monitoring, the evidence which makes your CSP evidenced-based, with a supervisor becomes part of the same someone's job on which their per...

Hidden C/S: The Performance Review

Image
This post is part of a series about aspects of cybersecurity which are not obvious, especially to newcomers. This post is about the cybersecurity aspects of the humble performance review. What does cybersecurity have to do with performance reviews? To answer that question, let us go down the cybersecurity chain from start to finish. (1) Senior management signs off on a cyber asset as critical, which means that the asset is to be protected from at least one specific risk. This is Identify in the NIST CSF . (2) Someone in the cybersecurity program (CSP) assigns a "control" to that risk for that asset. This is Protect in the NIST CSF. This step includes agreeing on what constitutes proof that the control is effective. (3) Monitoring that control becomes part of someone's job . This is Detect in the NIST CSF. (4) Sharing the results of that monitoring, the evidence which makes your CSP evidenced-based, with a supervisor becomes part of the same someone's job on which thei...

The NIST CSF Adds Governance!

Image
One of the reasons we founded Pythia Cyber was to provide cybersecurity (C/S) that included the behavioral aspects of C/S. All of our founders were all to aware that human behavior plays a large role in how well C/S works, but so rarely saw that reality reflected in how C/S is rolled out in the real world. At long last, the Cybersecurity Framework from the National Institute of Standards & Technology has been expanded to include at least some of this under "Govern." Govern function joins the familiar five pillars of Identify, Protect, Detect, Respond & Recover. This function is what you would expect and a great step toward what is needed. Adding this function validates Pythia Cyber's top-down approach in which we start at the top of the organization to set the priorities, the budget and the goals. This function makes the link to Risk Management clearer as well. We hope that this official recognition of this concept will help move the needle on the tendency of CEOs...

The First Step, The First Time (part 2)

Image
(This blog post is the second of two; the first one is here .) Respond and Recover are different from the other pillars in that they are not something you do on a regular basis: rather, you do them on an as-needed basis. Ideally, you never need them but no one can count on that. Respond and Recover are two parts of what you do when there is an incident. Note that an incident can be the result of a threat, such as an attack act by a malicious human being. An incident can also be the result of a vulnerability, such as a power outage not covered by battery backup. Respond is what you do in the short-term and Recover is what you do in the long-term. This difference in time frame is why Respond and Recover are separate: Respond is about moving as quickly as possible to restore access to whatever systems or data were affected. Recover is about moving as deliberately as possible to undo as much damage as possible. Recover also has a review component aimed at figuring out what to do to pr...

The First Step, The First Time (part 1)

Image
(This blog post is the first of two; the second one is here. ) You are an organization without any formal Cybersecurity Program (CSP), but you have decided that the time has come to remedy that lack. What do you do now? The first thing you do is review that basic concepts behind Cybersecurity (C/S), which we assume that you have done by reading the appropriate posts of this blog. That means that you are familiar with these pillars from the NIST CSF: Identify, Protect, Detect, Respond, Recover As a quick review, here are the concepts we will use in this post, presented in a form that is meant to show you how these concepts relate to each other: The obvious way to approach this process would be to start with Identify, and work your way through the list to Recover, but that is actually not what we recommend when starting from scratch.  Instead, we recommend that you take stock of what you are already doing. In effect, we recommend that you start with Detect and work backwards through ...

Someone Else's Problem

Image
As noted in this blog post , we were recently reminded that when you ask CEOs the question "how much do you think about cybersecurity" the frequent answer is "not much." For many CEOs cybersecurity (C/S) is box that must be checked, of course, but a box that can be safely left to IT. In other words, to them, C/S is Someone Else's Problem (SEP). If you are the person running IT, effectively the CISO or actually the CISO, or the part-time CISO, this carte blanche  may seem like a great deal: you get a blank check and the CEO (and the rest of the management team) gets a pass on thinking about C/S. In practice, this is deal is not as great for you as it first appears. In a nutshell, the level of support indicated by "I trust you to do whatever it is that you do" may not be enough support for you to survive a C/S incident. Or two. Or three. You can certainly spin the wheel and hope that nothing too bad happens on your watch. You can even take all reasonabl...

Business Problems We Solve: What CEOs Should Talk About When They Talk About Cybersecurity

Image
The most basic layperson definition of cybersecurity is this: the balance of maximum authorized systems access with the greatest amount of denial of unauthorized access. Even if you're technically inclined, the details of cybersecurity get dizzyingly technical after that.  Face it: if you're running a business (or looking to invest in one) you aren't focused on technical details. Let's do some bench-marking. Here's what CEO's talk about when they talk about cybersecurity; see if this is what you talk about: Cybercriminals are more sophisticated than the Board; what do we do about that There's a lack of appropriate controls -- typically cybersecurity is a rear-view mirror Our critical assets are out there & accessible (e.g., product details or design leaks); too many leaders playing catch-up Nearly all CEOs need to feel in control so they defer cybersecurity to IT experts, but are their priorities your priorities? Are they overspending? What's your re...