GSK

Strengthening Cyber Defences in a Growing Digital World

Steve Williamson is the Audit Account Director, Information Security and Data Privacy at GSK, leading a global team in assessing and mitigating information security risks. With an IT career spanning over three decades, he has more than thirty-five years of experience, specialising in cloud services, application security, and data protection. A recognised expert, Steve actively participates in CISO networks, contributes to peer-reviewed journals and speaks at industry conferences. As a Chartered Software Engineer and Fellow of The British Computer Society, Steve drives cybersecurity excellence, ensuring organisations remain resilient in an evolving digital landscape.

Through this article, Williamson emphasises the need for organisations to continuously adapt their cybersecurity strategies in response to an evolving digital landscape and emerging threats while ensuring robust risk management and resilience against cyberattacks.

Adapting Security Strategies to a Shifting Digital Footprint

I take the approach of ensuring the most critical assets are protected against the most likely threats. There are three elements to achieving this: identifying the most critical systems and data (commonly referred to as digital crown jewels), a good understanding of the external threat environment and a set of strong security controls that are implemented effectively and monitored.

Looking at the external threat environment, the most prolific threat actors are nation-state and cybercrime actors. In particular, cybercrime actors continually improve their tactics. Extortion through ransomware combined with the theft of sensitive information is prolific. Many organisations find they have little choice other than to pay the ransom.

Fortunately, there are many sources of threat intelligence. Breach reports from companies such as Verizon, Crowdstrike, Microsoft and Google are essential reading for cyber defenders. From these reports, we can glean information on tactics used in breaches. The most commonly used exploits involve stolen credentials, social engineering and exploitation of unpatched systems.

As organisations improve their cyber defences, the bad actors continually evolve tactics.

“A compliance-based approach is binary. If you are not compliant with a certain control, you have a risk. If you are compliant, then everything is OK. Cybersecurity is not that simple. When taking a risk-based approach, the aim is to reduce risk to an acceptable level through a reliable and reasonable set of controls.”

Internally, it is important to look at technology strategies and understand how the digital footprint is changing and expanding. One example is the move from on-premise data centres to cloud services. This is significant as it changes how security controls are deployed. In the cloud, everything is virtualised and configurable. AWS, Azure and GCP have comprehensive security controls. However, it is easy to mess it up through misconfiguration errors (the most common cause of cloud security incidents).

The Role of Low-Code and No-Code Tools in Cyber Security

Most organisations are embracing digital transformation. This involves deploying more automation, data analytical platforms, and a proliferation of AI-enabled solutions. Digital transformation keeps companies competitive, but from a cyber security perspective, this means an ever-expanding attack surface to defend. Many of the solutions may be citizen-developed applications. This used to be known as shadow IT, which has negative connotations. However, there are some good low- and no-code development tools available that allow for rapid development with good technology guardrails.

Understanding the Layers of the Technology Stack and Security Risks

Risk and audit professionals need foundation technology skills. They need to understand how different layers of the technology stack can be breached (or accidentally made inoperable). This knowledge is foundational for performing risk assessments and selecting the most appropriate mitigating controls.

Also, the ability to assess and report risk in terms of consequence and likelihood is essential. A compliance-based approach is binary. If you are not compliant with a specific control, you have a risk. If you are compliant, then everything is OK. Cybersecurity is not that simple. When taking a risk-based approach, the aim is to reduce risk to an acceptable level through a set of reliable and reasonable controls. The acceptable level reflects the company's risk appetite.

There are certain consequences—material impact events—that the company will want to avoid. Increasingly, high availability is essential; this is achieved by building resilient systems that continuously synchronise. However, a well-thought-out ransomware attack could still bring those systems down, resulting in an organisation at a standstill for several weeks. If they rely on digital channels for sales and customer interactions, then that type of outage could be material.

Key Advice For Aspiring Leaders

Continuously learn and self-develop. Digital technology is fast evolving, and the pace of adoption is rapid. Look at the uptake of generative AI. Regulations can’t keep up with the pace of change. Risk and Audit professionals must always stay current. Fortunately, there are many excellent sources of continuing education from leading industry bodies, such as ISC2 and ISACA. There are numerous conferences, webinars, and online resources, such as LinkedIn Learning. There is no excuse for not committing to continuing education.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.