The Complex Realities of a Cybersecurity Program
By Mark Morrison, Chief Information Security Officer, OCC
As October is Cybersecurity Awareness Month, I’d like to share what I believe are some significant cybersecurity issues that don’t always make it into today’s headlines.
Limited Standards for Technology Infrastructure Are Problematic
The companies who develop the underlying information technology infrastructure are rarely held accountable for creating secure operating systems, cloud technology, website servers, and network infrastructure. Yet the design and implementation of these products are crucial for creating secure systems.
"CISOs should instead be concentrating on the integration of security capabilities to achieve business objectives while operating in a risk-acceptable environment"
Aside from a few highly regulated environments, the U.S. government’s cybersecurity regulations are for the most part reliant on voluntary adherence to “industry best practices,” rather than a set of mandatory security requirements. For example, the federal government produces airplane and automobile safety requirements such as seatbelts and airbags but has no such cybersecurity equivalents.
As a result, CISOs are constantly plugging holes in both legacy and newly acquired information technology components that never should have existed in the first place. This is not optimal. Ideally, CISOs should instead be concentrating on the integration of security capabilities to achieve business objectives while operating in a risk-acceptable environment.
For example, there is an ongoing push to adopt blockchain technology within the financial sector. While blockchain offers enticing improvements in financial data processing and information security, it runs on existing infrastructure. As we have seen, sophisticated cyber adversaries are adept at exploiting infrastructure vulnerabilities so that the security of the application is rendered less meaningful.
This is like building a fortress on top of a foundation of sand. We need cybersecurity across the entire technology stack. The same principles apply to cloud technology, as we have seen with recent examples of the Spectre and Meltdown process layer vulnerabilities.
Consumer Trust Is Misplaced
A related challenge is the issue of misplaced trust. Many people both at work and at home erroneously assume technology vendors, social media providers, retailers, medical providers, and financial institutions will be able to protect their most personal information. Ceding trust in this way can harm the average consumer or business.
For example, Facebook was recently exploited by attackers in part because the company lacked a detailed understanding of its own business processes, potentially making consumer information vulnerable. Or, with the Equifax data breach, people trusted the company to protect their confidential information, yet Equifax was lax in patching a known security vulnerability.
Considering the increasingly digital world we live in, reliance on technology has become a necessity. Data breaches may become more common, with people accepting them as a cost of doing business or living within the digital world.
Cyber-Attacks Not Seen as an Every-Day Occurrence
Part of the high consumer trust may be related to reporting on cyber-attacks.
While the media rightfully reports on the Department of Justice and FBI indictments of domestic and foreign adversaries (Russia, China, North Korea, along with recent CIA and NSA employees), this emphasis leaves the mistaken impression that cyber-attacks are rare occurrences perpetrated by a small number of state-sponsored actors that are part of the global geopolitical landscape.
In fact, organizations face constant cyber-attacks, sometimes on a daily basis. Most news readers don’t realize this. And, this paradigm shift has yet to reach many companies. In the business world, cyber risk is still assessed and considered as an independent risk factor and has yet to be fully integrated into the overall corporate risk assessment acceptance process. It needs to be factored in with business, financial, operational, and other regulatory risks.
As a CISO for the world’s largest equity derivatives clearing organization, I know that it is important to effectively measure the effectiveness of your security program and calculate the residual risk, especially in the context of dollars, as best understood by your board of directors. Too many times we establish metrics that focus on what we can measure versus what we should be measuring.
The challenge is that the metrics must be inextricably linked to the critical business process and operations. A broad scope of testing at multiple levels is key; it provides empirical data and demonstrates some independence for the overall security program.
A Proper Fix Requires a Proper Identification of the Problem
As was well-documented in the annual Verizon Data Breach Investigations Report, about 85 percent of the security vulnerabilities being exploited are known vulnerabilities with an issued vendor patch. So our largest and most significant problem is basic security hygiene—blocking and tackling.
These are the most common types of attacks. And cybersecurity professionals across many industries deal with them frequently.
The more widely this fact is understood, the sooner we can address the root of the problem and build a solid foundation for more secure technology.