


A Process-First Approach
So, you’ve just stepped into a new cyber security executive leadership role. The priority is an initial assessment of the current environment so you can advise the leadership team what needs to be done first.
The first instinct is to look at the tools and start pulling data and metrics to report on the threat horizon. That is all well and good, but it doesn’t set you up for the discussion at the right place. Reporting statistics based on a point in time or historical view puts a stake in the ground as a starting point, but what will drive the next action? What will resonate with a CEO, President or Board member to make them feel you understand the enterprise and priorities?
As an executive, the expectation is context driven planning. You don’t get that solely from metrics. You have technical expertise or you wouldn’t have gotten this job, but you need to talk in business terms. Businesses are moving and dynamic creatures that thrive on process. Cyber security is a business process, just like accounting. Using an accounting metaphor that group provides a vast inventory or metrics, but to get there they have built a comprehensive set of processes that link all the data from multiple sources that contribute to those metrics.
The Cyber Security Business Process starts with people, who are also the greatest risk to the organization. The process of people is all about onboarding, offboarding, classification of worker types, provision of hardware, access to software and transitioning or midboarding when there are internal changes. To portray the status of the enterprise for Cyber Security, you need to evaluate each of the processes associated with how people are brought into and out of the enterprise.
There is a four layer paradigm that can guide your analysis:
1. Access - what are the barriers for someone getting in the physical or virtual door?
2. Authentication - to let them in, how do you know who they are?
3. Authorization - once you know who they are, what do you allow them to do?
4. Containment - how do you keep them from jumping from one system to another?
"Cyber security is a business process, just like accounting. To portray the status of the enterprise for Cyber Security, you need to evaluate each of the processes associated with how people are brought into and out of the enterprise."
Understanding these core processes leads to physical inventory management, access control, licensing, procurement and vendor management and other outcomes. These key items link to the HR and Accounting systems and can provide you a pulse of the corporation.
As an example, how many people are onboarded and offboarded each month? That combined number is your churn rate if measured as a percentage of the total FTE population. You can augment this with the same statistic for contractors and consultants or combine all of them. The more churn you have, the higher your risk factor. That is a concept that any senior executive can understand. If you are a 1000 employee company with an annual churn rate of 40% and you have a manual process between HR, IT and business applications, you have a high risk factor, which supports investment in automation.
Following a method like this, you can look at more layers of movement within the company. How are people given application access? Who approves elevated access for users? How are the core IT systems managed and tracked? If you are wondering how to approach these processes, talk with your internal auditors and they can tell you exactly what areas they look at to assess the SOX risks. Those are the triggers for the processes you should focus on.
Here is the interesting thing. You can have a detailed conversation with the executives and business owners all based on risks that emanate from the current processes. Those risks create the framework for an investment plan and an opportunity to joint venture with the lines of business to fix gaps, improve your audit and insurance posture and bring real value to the business by protecting revenue streams dependent on these processes. All of that and you haven’t even talked about Managed Detection and Response tools. Think of MDR as another process you need to address. But you can’t articulate it until you’ve established a larger, business context for making the MDR investment.