Many CISOs can probably relate to the old saying “half the money I spend on advertising is wasted; the trouble is, I don’t know which half”. Investing in cybersecurity controls, without the help of quantifiable data, means they are often unsure where to target their investment most effectively.
To address this, C-Risk has launched a three-part series of webinars, aiming to share best practice on how to factor IT security control performance in order to calculate cyber risk in financial terms.
When organisations have a better understanding of which controls give the most value, they can make more informed decisions about reducing their risks and minimising outages or loss events. This way, they can align security investment more closely with business assets that are most at risk.
The guest speaker at the webinar was Jack Jones, an authority in cyber risk management who created the FAIR standard, and who currently serves as chief Risk scientist at Risk Lens. “Organisations absolutely need to be very good at identifying where they need to be spending their time and effort,” he said. “If an organisation believes it should be investing in encryption, multi-factor authentication or a SIEM solution, or whatever the case might be, it’s their responsibility to understand whether that’s a good investment or not.”
The webinar looked at the role of FAIR (Factor Analysis of Information Risk), an independent standard for quantifying and managing information risk. This has generated a lot of excitement and anticipation within the risk management community, according to Tom Callaghan, Co-founder of C-Risk and co-chair of the FAIR Institute Paris chapter.
CISOs can use FAIR and its control analytics model, FAIR-CAM, to scope risk scenarios while assessing the performance of security controls in mitigating those risks. This way, they can understand which controls work for certain specific scenarios.
The webinar described one such scenario using a fictitious company that has an internet-facing web app that generates revenue – and is therefore valuable – but is victim to growing numbers of exploitable vulnerabilities.
“The goal is to reduce the probability of an extended outage of the service and the financial impact on the organisation… FAIR-CAM can help to identify the controls which directly or indirectly impact loss for a well scoped scenario,” said Callaghan.
Other topics covered in the webinar include:
To find out more about the model, you can watch back a free 49-minute webinar. To watch the previous episode and to sign up for the next two webinars in the series, click on the button below.
related to cybersecurity and Cyber Risk Quantification (CRQ)