enterprisesecuritymag

July 2020ENTERPRISE SECURITY| | 9The above definitions are not meant to fully define the role of each division, but simply to summarize the core functions. And even if you just look at that, the linkages become obvious.Based on my experience in the APAC region, where I have seen the collaboration working well between risk and cybersecurity entails the following:· Risk quantifies and documents the risks that may impact the organization· Cybersecurity risks are then discussed and agreed to with the cybersecurity division· The heads of risk and cybersecurity (Chief Risk Officer and Chief Security Officer) then work together to determine a risk treatment plan · They will then jointly present this to the Board and Executives to:· Firstly, educate them on the cybersecurity risks likely to impact the organization with priorities assigned based on likely impact· Outline risk treatment plans for each prioritized risk· Present return on investment figures to the Board and Executives to gain support for the risk treatment plan that then becomes a cybersecurity program of works to enhance the organization's security posture and reduce its risk exposure.· Once the program is running, both `heads of' will regularly present to the Board and Executives the progress being made and clearly articulate the reduction in cybersecurity risk· The overall risk posture and treatment plans are then updated at least six months in light of new and emerging cyber risks.Three points need to be at this juncture:1. Cybersecurity initiatives should be part of the overall organizational risk management framework and cybersecurity risks should be prioritized and treated within this framework as any other organizational risk2. Any cybersecurity initiative should be aligned to the organization's risk management goals and justified in monetary terms with respect to risks reduced3. The Board and Executives should be a part of this process in terms of understanding the need for cybersecurity initiatives as well as be the ones that approve these initiatives. Regular and accurate reporting on this program of works is important in order to ensure the Boards and Executives have visibility of progress being made (security is a journey after all!)So to summarize, for cybersecurity initiatives to be successful in an organization, both risk and cybersecurity must work together:· Risk will help determine and quantify the cybersecurity risks that may impact the organization· Cybersecurity will validate these, help prioritize and implement controls that will help manage these risks. ESFor cybersecurity initiatives to be successful in an organization, both risk and cybersecurity must work together
< Page 8 | Page 10 >