The global cybersecurity market is currently worth $173 billion and expected to grow to $270 billion by 2026. Yet as organizations invest more in security technology, a new global survey by IBM Security and the Ponemon Institute suggests that security response efforts are “hindered by the use of too many security tools, as well as a lack of specific playbooks for common attack types.” Of those surveyed, 74% of respondents report that their response plans are ad-hoc, applied inconsistently, or that they have no plans at all.
This represents a critical gap in any security program. As organizations navigate evolving attack techniques and operational changes, such as an increasingly remote workforce, the survey suggests that companies are relying on outdated response plans that don’t reflect the current threat and business landscape.
However, with limited and overstretched resources, CISOs can’t possibly plan for every cyber risk scenario. A better approach is to develop targeted, proactive plans that focus tools and resources where they can have the greatest impact. Consider the following best practices:
1. Gain visibility into cyber risk hidden in the expanding attack surface
As an organization’s digital footprint expands, the number of applications, devices, and other assets that users interact with grows exponentially. Yet security teams often lack visibility into the inventory of critical assets that comprise these complex ecosystems — making them hard to secure. Security leaders may also lack insight into the level of risk associated with each asset, not realizing when a piece of software is misconfigured or runs a high risk of being breached.
In order to confidently grow and scale, organizations must find a way to achieve continuous visibility into these assets and the risk that may be hiding across their digital environment — in the cloud, and across geographies, subsidiaries, and the remote workforce. Only with this understanding can businesses make strategic planning decisions about prioritizing their remediation efforts and moving their cybersecurity programs forward.
To avoid overwhelming overstretched security teams, it’s also important for security leaders to rank areas where risk is disproportionately concentrated. For instance, a top priority could be remediating any incidents that involve a critical asset with a high risk of being breached. Rather than always fixing issues as they arise, security leaders can use these insights to develop proactive security policies that prioritize allocating resources based on the criticality and level of risk associated with each asset.
2. Continuously assess the organization’s security posture
As the IBM/Ponemon survey shows, investing in a variety of security tools does not always lead to an effective cyber risk reduction strategy. With an increasingly complex operational and threat landscape, security managers must find ways to build resilient security programs while optimizing their existing technology investments and workforce.
Since the business and threat environment is never static, a best practice for achieving this objective is for organizations to continuously and automatically monitor their cybersecurity posture over time to reveal areas of unknown risk, such as unpatched systems, misconfigurations, and other vulnerabilities.