enterprisesecuritymag

APRIL - 2023ENTERPRISE SECURITY| | 9At Allianz Australia, for example, we set a phishing reporting requirement this year for all managers and executives across the organisation. This was linked to individuals KPIs and not only encouraged the right behaviours for secure security practices but also facilitated the accountability required to achieve distributed responsibility for security within the business. As a result, we have seen improved uptake of training initiatives, improved results in phishing simulation exercises and increased security awareness across the business. For cyber security to be effective it needs to be viewed as a critical business enabling activity ­ something that is a key part of winning the next contract or maintaining the customer's trust in the firm and its products. When you lead with this objective and focus your conversations and culture to this objective, you will be heading in the right direction to improve your organisations security posture. ESThe next level of activity might be half yearly, quarterly or even monthly revalidation of account existence and the level and type of access the user has. For example, if you're an organisation processing millions of dollars each day, you will need tight control over who can approve those payments. In this instant, monthly review at the detailed permission level might be most suitable.Setting the right security culture is important for ongoing success. Security is everyone's responsibility but not everyone can, or should, be a security expert. You should ask yourself, what is the security role you want each employee to take? What relationship do you want the business and its people to have with your security team? How do you facilitate these roles and relationships with effective training and awareness? Effective cyber security is about knowing what is important to your business ­ that is, identifying the `Crown Jewels' and focusing security resources, such as people, time, money and attention, towards them
< Page 8 | Page 10 >