This year marked another great Gartner Security & Risk Management Summit with over 3,000 attendees, bringing together CEOs, CIOs, CISOs, IT Directors, Risk Managers, and other risk and security professionals to National Harbor, MD from June 12-15. An underlying theme emerged from the numerous sessions I attended and the various conversations I had: all roads lead back to business value. Whether it’s a new vendor that a company is looking to onboard, or a cloud technology the organization is implementing, everything should tie back to a business decision.
Cybersecurity Should be a Critical Part of the Business
Security teams do not want to be blockers to business progress. There is a need for them to be part of business discussions rather than in their own silos viewed as shooting down ideas from the business. Although CISOs and CIOs meet regularly with their Board of Directors, there is a lack of understanding between business needs and security requirements. Paul Proctor, for example, highlighted that there is no such thing as "perfect protection." Companies take either higher risk with lower costs, or take less risk but at a much higher cost. As their business needs change, the company moves along that spectrum, and security must be an important part of that dialogue. This process highlights the need for executive reports that measure the link between where the business is going and how risk management, including vendor risk management, fits into that narrative.
Growing Concern: Complexities of the Third Party Ecosystem
Jay Heiser delivered a great presentation where he discussed security ratings and how they fit into a company’s vendor risk management strategy. The message is clear: continuous information outweighs a single point-in-time snapshot. In fact, organizations today are beginning to understand that continuous assessment processes are more reliable than rigorous assessments conducted once. Gartner estimates that by 2021, 50% of data will be outside of the physical control of enterprise IT, up from 10% today. As companies migrate their systems to the cloud, the need to scale their vendor risk management program and focus on cloud security will continue to grow.
The Need for Agility and Scalability in Risk Management
Security teams are being asked to be agile and adapt to the growing demands of the business. One of the themes that came up multiple times at the Gartner Summit is how organizations can do more with their existing resources. There is a need for organizations to scale their vendor risk management programs, adjust their approach with the speed of the business, and collaborate with internal and external stakeholders -- all with limited resources.