02 Oct Risk-value control
Hadi Jaafarawi, Regional VP – Middle East & Africa at Qualys, makes the case for a Risk Operations Centre and the ability to finally control the relationship between value and risk management.
Risk is a way of life. As it is for individuals, so it is for businesses. Enterprises across the Middle East have in recent years had to deal, either directly or indirectly, with a series of global shocks — a health crisis, followed by a recession, followed by inflation, intermingled with shift after shift in consumer expectations. In response, the nation’s businesses have had to leverage whatever technical tools were available to satisfy consumers, regulators and investors.
Today, staying solvent and relevant requires a balancing act that inevitably leads to conversations about risk management. Business stakeholders want as little risk as possible, but in trying to formulate a real-world action list, it quickly becomes obvious that you can’t eliminate all risk. The Risk Operations Centre (ROC) has arisen to formally orchestrate this challenging process of managing risk at scale — helping businesses understand what risk they need to eliminate or mitigate, and what risk needs to be accepted or transferred.
Let’s start by defining our terms. We might think of risk as a way to describe an ecosystem of uncertainties where at least some of the outcomes are undesirable. Even in that limited view, the number of uncertainties and the severity of the outcomes are themselves subject to uncertainty. And what about the negative outcomes that result from unpredictable events? In practical terms, the organisation must seek to detect all possible scenarios and sources of harm, and to do so repeatedly, in the course of its risk management journey.
Facing the challenges
Our challenge is therefore to measure risk — to somehow quantify the likelihood of future setbacks. We need metrics that express a reduction in uncertainty given certain conditions and subsequent actions. As we try to do so, we must define what ‘elimination of risk’ means to us. What risk managers really need to do is to set boundaries of acceptability. In cyber insurance, for example, we find the concept of risk tolerance where verifiable levels of risk are compared to some preset limit that is contractually defined.
Besides just monitoring and measuring risk, the ROC is also a hub for continuously orchestrating the mitigation and remedying of risk to align with a predefined tolerance level. And since every modern business is a digital business, we are talking, in large part, about cyber risk. At this point, we should note the differences between the ROC and the Security Operations Centre (SOC). The SOC gathers and acts on security alerts while the ROC uses SOC data to provide all stakeholders, from the CFO to the lead compliance officer, with actionable information that allows them to manage risk collaboratively.
In my experience, the ROC is often established by the CISO, who will aggregate information on risk into a data lake. This requires building a comprehensive digital asset register and a full-stack vulnerability list and then integrating multiple threat-intelligence feeds. It also necessitates the invention of controls to compensate for risks that cannot be immediately fixed and coming up with ways to use the new stack to automate mitigation and remediation. This is no easy task. While it is difficult to gauge precise figures for the Middle East, a 2021 global estimate from Panaseer suggests the average organisation may be using as many as 76 security tools. Regional CISOs may find themselves in the ironic position of having to incorporate past security investments into their current risk profile.
The risk surface
As the CISO moves forward with their creation of an ROC, they will find that event-oriented data from the SOC can only act as a foundation for risk measurement. High-volume, rapidly accumulated SOC data lacks the requisite business context to be useful in its raw form to risk managers. The ROC’s job is to provide visually rich, context-sensitive information that supports sophisticated analysis of potential sources of harm and enables effective responses. Hence, the ROC is all about protecting value and minimising loss.
One of the unfortunate realities of business risk is that it tends to increase with success. Each enterprise has a ‘risk surface’ — or how much it stands to lose. The ROC is responsible for monitoring this surface and continually managing the business’ exposure to potential loss. We can already see enterprises embracing the ROC concept. In the fourth quarter of 2024, KPMG Lower Gulf launched what it calls a “risk hub” in the UAE, built around a Governance, Risk and Compliance (GRC) service. In the coming months, we are likely to see more moves like this across the nation, as ROCs become focal points for addressing challenges faced by the modern UAE business.
The right hands
Approaches to the construction of ROCs are still in their infancy, but if each company assesses its own realities against its goals and puts the right authority in the hands of the right teams, progress could be rapid. Collaboration between CISOs, CFOs and compliance officers will be of particular importance, as will partnerships with peers and vendors. As cybersecurity risk grows in intensity, quantification will be of great help in the mitigation battle. The ROC will be pivotal in bringing the right data and know-how together to shield the enterprise from the worst its adversaries can throw at it.
Sorry, the comment form is closed at this time.