The New Rules Of Cybersecurity

© AdobeStock
The man who built the U.S. Army’s cyber command says online threats are going get worse before they get better. But that doesn’t mean leaders are powerless. Here's how to protect your information and leave no data behind.

The hardest one, and the one that concerns me the most, is the integrity of the data. What happens when an attacker is able to change your data and you don’t know it’s been changed? Today, all our systems depend on data and if you can no longer trust the integrity of the data, you have a significant problem. In my view, that’s the most dangerous threat we face in the future and one you need to prepare for today.

8. Get a Second Opinion. Second opinions matter—be careful of group-think. Bring in outside experts. It’s great to confirm your ideas, but it is even more valuable to get fresh thoughts and ideas from outside your organization.

9. Practice, Practice, Practice. If you do nothing else, prepare for a breach and be ready to respond. The best way to be ready is to train over and over and over again. Everything depends on it—your company value, your reputation. Have a strong incident response plan, have it reviewed and updated routinely, and most significantly, rehearse it, with internal and external participants, until everyone knows what’s required if they have to respond. I’m sure it won’t go as planned, but I can guarantee everyone will be ready to adjust as needed.

10. Keep Asking Questions. The last thing is to be engaged and keep asking questions. When I started cyber command, the only thing I knew was that I had a lot to learn. I counted on my experts to help inform me on what I needed to know, and I talked to a lot of outside people to get their views. Then, it was important to move quickly beyond the basics and to ask tough questions in order to close the gap between your expectations and reality.

Get engaged, as opposed to saying, “Well, that’s the cybersecurity people, or that’s IT, or that’s not important to me.” That doesn’t send the right message, and it doesn’t allow you to do the necessary strategic thinking and work required to appreciate what needs to be done to protect your business—and to ensure your mission.


THE KEY QUESTIONS TO ASK

Why would they attack us?
What are our crown jewels and where are they; who can access them; how do we know they’re protected?
How do we know threats are not in our network?
What are our most significant vulnerabilities and risks?
Do we have a framework to address cybersecurity and to ensure hygiene?
Do we have a culture of cyber-risk awareness and is the policy for personal responsibility and accountability clear?
Do we have visibility across our supply chain and is cybersecurity built into our contracts?
What is our risk appetite, and do we have an enterprise approach to risk management?
Are we ready to respond to a breach?
Source: NACD


WHAT LEADERS SAY

A recent Ernst and Young survey of 1,200 C-Suite leaders at the world’s largest organizations found worry and weakness when it comes to cybersecurity.

89% say their cybersecurity function doesn’t meet their organization’s needs.
87% say they need up to 50% more budget.
64% say malware attacks increased in 2017, compared to 52% in 2016; phishing is up 64% vs. 51%.
57% don’t have or have an informal threat intelligence program.
48% don’t have a security operations center (in-house or outsourced).
17% of boards have sufficient knowledge of effective oversight of cyber risks.
Only 12% feel it’s very likely they would detect a sophisticated cyber attack.


WHAT TO DO NOW

Do the Basics. Identify and patch all known vulnerabilities. Require multi-factor authentication, not just passwords, for access to your systems. Limit the number of people who have has access to the most important parts of your network. Be sure to guard your back door—supply chains and third parties.

Examine the Impact. Take the time to think about the impact of cybersecurity on your company. What’s the worst that could happen? Are you addressing it?

Get Your Board Right. Look hard at your directors to be sure that they’re suited for today’s world. Do you have cyber expertise on your board?

Be Ready. Rehearse your incident response plan. Some 38 percent of U.S. companies have no plan, and of those with a plan, one-third have not reviewed it since it was initially developed, according to the National Association of Corporate Directors.


MORE LIKE THIS

  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events

    Roundtable

    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)

     

    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.