Between difficulty communicating with boards and executives, decreasing budgets, and difficulty measuring how exactly risk was being reduced, security leaders are under pressure to change the way they do things. The situation for security leaders was already changing heading into 2020, with decreasing budgets and increasingly skeptical boards citing little change in security performance to show for their investments.
All of that was accelerated in March when COVID-19 transformed into a global pandemic, and drastically changed the way we work. Suddenly everyone was working from home, business operations had to shift rapidly, and legacy processes across the board were left struggling to adapt. Since then security leaders are under enormous pressure to do things faster, cheaper and deliver results, stressing programs that have relied on traditional or one-size-fits all “best practice” methods for managing their security.
But for the forward thinking leader, this time of unprecedented transformation can be a time to thrive for those who embrace it, and turn security into a leading enabler of the business.
Strategies to Improve your Cybersecurity Program
Here are five ways you can transform your policies processes, and management of your third-party risk and security performance programs.
1. Measuring Program Effectiveness
How much are you spending, and what are the results you’re delivering to the business? Focusing on results is critical here, but they have to be the right results. Too often security leaders focus on what was accomplished instead of the business impact, and often neglect to provide context for their reporting.
Instead, security leaders, executives and board members should focus on how security is aligning with the overall objectives of the business. For example, if one of the objectives is to reduce downtime in a SaaS product, security might report on the speed with which new cloud vendors are being onboarded and reassessed, as well as an increase or reduction in vulnerabilities found throughout the attack surface.
2. Addressing The Expanding Attack Surface
The attack surface was already growing before the COVID-19 pandemic, but it has absolutely exploded since March 2020. With the large scale shift to work from home, any idea of a perimeter has disappeared, while the reliance on apps like Zoom, Microsoft Teams, Google Drive and Slack has seen new technologies both onboarded faster and become more critical to operations than ever.
While security teams often did what needed to be done to adapt to changing circumstances, there needs to be a long term strategy for how to manage the ever expanding attack surface. Security teams need to prioritize getting visibility into their entire attack surface, including shadow IT and any corporate associated assets like old URL’s or domains, understanding what their 4th, 5th and nth party risk is, and what their work from home risk exposure is.