If you’ve glanced at the opinion columns of security industry publications, you’ve probably seen the term “risk-based” floating around, as in “the time is now for a comprehensive, risk-based approach” or “a risk-based approach to security is key to business alignment."
However, many of these articles fail to define what exactly a risk-based approach to cybersecurity is. And that’s a problem — without a solid understanding of its meaning, “risk-based” could end up being just another buzzword, and all the benefits its supposed to bring about will never come to fruition.
What is a risk-based cybersecurity approach?
If someone tells you their company takes a risk-based approach to cybersecurity, what they mean is that when it comes to making security-related decisions, they consider risk above all other factors.
[Learn how to get accurate cybersecurity data and track progress over time.]
Risk-based approaches are often presented in opposition to compliance-driven approaches. Risk-based security teams are more concerned with reducing their organization’s real exposure to cyber attack and data breach than they are about checking boxes or passing audits (though those remain worthwhile goals).
A risk-based approach to cybersecurity is also proactive rather than reactive. Instead of focusing on incident response, a CIO at an organization using this approach is likely to invest heavily in testing, threat intelligence, and prevention.
Finally, this approach is inherently realistic. The goal of a risk-based cybersecurity program is meaningful risk reduction, not 100% security. That’s important, because the former allows CIOs, CISOs, and Board members to make pragmatic decisions about budget and resource allocation, while the latter requires sparing no expense, even when investments receive diminishing returns.
What does a risk-based cybersecurity approach look like?
A security program that’s fully committed to the risk-based approach will necessarily have a few distinguishing elements.
Continuous Monitoring
Risk-based approaches to cybersecurity rely on accurate risk knowledge. On one hand, that means that one’s idea of risk should be based on facts rather than opinion, trends, or headlines. However, in the fast-moving world of IT security, data must also be up to date. That’s where continuous monitoring comes in.
This approach to security doesn’t leave room for blind spots. That means point-in-time vulnerability assessments and penetration tests that only occur once or twice per year must be supplemented by other kinds of assessments that fill in the gaps.
Security ratings are one popular option for continuously monitoring cybersecurity risk. Ratings from a service like Bitsight provide insight into compromised systems, security diligence, user behavior, and other factors that increase an organization’s risk exposure. These insights are synthesized into one representative number, updated daily, as well as grades in individual risk vectors.
Independent research shows that Bitsight Security Ratings correlate to data breaches — companies with a Bitsight Security Rating of 500 or lower are nearly five times more likely to have a breach than those with a rating of 700 or higher.
Prioritization
A truly risk-based cybersecurity program will have a system in place to prioritize security needs based on their relative levels of risk exposure.