This article is based on an episode from the Cyber & AI Perspectives podcast. Prefer listening instead? Listen to the audio version below.
Today I’ll speak about one of the most common biases among cybersecurity professionals: the focus on implementing cybersecurity controls, while not really managing them.
Implementing security controls is only the first step. Real cybersecurity requires ongoing management through planning, monitoring, auditing, improvement, and review — an approach increasingly needed because of regulation, complexity, and evolving threats.
Cybersecurity implementation vs. management
For example, if you need to implement backup, you find the solution that is most compatible with your technology, has a reasonable price, and is provided by a reputable vendor. You purchase it, deploy it, adapt your operating procedures, and provide some training for your employees if needed. And that’s it. Things will operate fine.
But will they really?
Let’s consider the deployment. How often are you going to perform the backup? Will the frequency be the same for all of your systems, or will some data be backed up more frequently than others? You’ll probably have to assess risks and calculate your recovery point objective, or RPO — in other words, how much data you can afford to lose — to strike a good balance between backup that is not too costly and backup that will preserve enough of your data. This is all part of planning and setting objectives.
Then, let’s think about what will happen once the backup is in production. Are you going to let it run and check it once in a while, or should you have someone check it regularly to make sure it works as expected? This is part of monitoring.
Further, are you going to blindly trust that everyone will perform all the tasks related to backup — for example, that it is monitored regularly and tested periodically? Or should you perform an internal audit to make sure everyone is doing their jobs?
Once you find out what is going wrong, will you rely only on finding a fix for that problem, or will you try to prevent this kind of problem from happening again? This is part of continual improvement.
Finally, will you get your management involved and let them know if there are problems you can’t fix, if additional funding is needed, or if some rules need to be changed? This is part of management review.
The missing piece: Security management
These things I mentioned — planning, monitoring, audit, improvement, and review — are part of security management. This kind of management goes beyond pure implementation. Without it, you probably wouldn’t set things up properly, wouldn’t be aware when things go wrong, and wouldn’t fix those problems systematically.
I didn’t come up with all of these things myself. Basically, this is what ISO standards like ISO 27001, ISO 42001, and others are saying. I know that most people don’t like ISO, but nevertheless, I think this is probably the best part of them: They help you build a picture of how to manage your security.
Why will security management become even more important?
Why is this kind of management, with or without ISO standards, going to become more and more important in the future?
One reason is regulation. Laws and regulations like NIS2, DORA, and others require companies to implement some kind of management system. Another reason is complexity: Cybersecurity now has so many interrelated elements that it is becoming increasingly hard to balance everything without a systematic approach. Finally, when you look at why many incidents happen, it is because someone has forgotten about some detail or overlooked some trend, and introducing a managerial approach to security is basically about making sure you cover all the angles.
And if you’re not skeptical about ISO 27001, take a look at my article explaining what an Information Security Management System actually is. You’ll find the link in the show notes.
To learn about the ISMS, check out this article: What is an Information Security Management System?
Dejan Kosutic