23 Jul The language of risk
Ivan Milenkovic, Vice President Risk Technology EMEA at Qualys, says it is time for the C-suite to be fluent in risk moving beyond surface-level awareness to chart the real depths of business risk.
We often hear that our scientific community knows more about the depths of space than about the depths of our own oceans. This is underpinned by the relatively small amount of submarine environment we have mapped when compared to the night sky. The same could be said of our software. The vulnerabilities that are most successfully exploited are those that have yet to be discovered due to lack of visibility, already forgotten, or lost in the sea of new ones. And for businesses, risks most commonly stem from an inability of technical staff to communicate the dangers clearly, and in ways that are relatable for business executives.
The ideal way to deliver software vulnerability reports to non-technical audiences is through business-related terminology. Transparent metrics can more easily be weighed against risk appetite so leaders can balance agility and competitiveness against legal and technical safety. When we consider the extremes of risk-free operations and security-free operations, neither is sustainable. The former is prohibitively expensive, and the latter is unlikely to be profitable over the long term. Balance is a must.
Sailing on the specific
The eventual goal is targeted investment: the right budget devoted to the right resources and the right actions. To that end, risk appetite should not be used as a phrase to explain away underinvestment in cybersecurity. CISOs must quantify consequences and present them as business impacts. This means risk appetite itself must be quantified.
The practices of issuing high-level declarations on unmeasured acceptable levels of risk must change. Organisations need to use more specific metrics that track risk levels over time and compare them against clearly stated tolerances, such as a maximum of four hours per quarter of unplanned downtime for a core system. Risk thresholds must also be established to trigger critical actions. For example, if downtime exceeds agreed-upon limits, notify the CIO. If it exceeds them by more than an hour, the CIO should notify the board.
All stakeholders must agree to declare war on ambiguity. Where possible, teams should measure risks, impacts and outcomes in monetary terms. This leads to the formation of a common language for discussing risk and risk management. General discussions of comfort levels are replaced with specific questions like, “can we absorb an AED 5 million loss from a 24-hour downtime period?” Questions like this will emerge naturally from a risk audit, where the business and its most critical issues come under the microscope. Of course, some risks will be harder to convert into dirhams than others. By attempting to operationalise risk management, however, we take an important step towards guided action. As time goes on, we will improve accuracy as we gain more real-world experience.
See the ROC
As with all changes in business culture, it is advisable to form a single, central entity with the authority to promote new, data-based conversations. Just as the Security Operations Centre (SOC) did this for IT intrusions, the Risk Operations Centre (ROC) will gather risk signals and present them in a common monetary language so that the best possible decisions can be made. The SOC performed a largely forensic role, identifying the sources of errors that led to damage. The ROC takes a data-led approach to prevent catastrophic incidents from occurring. Doing side-by-side comparisons of monetary data and risk tolerance, the ROC is equipped to make meaningful recommendations when changes in risk levels are detected and exceed formally stated thresholds.
Data dominates
Data is critical. It must be used to provide a unified risk view that the board can easily use for strategic oversight. The three most important metrics are risk arrival, risk departure and risk survival.
Risk arrival rate measures the volume of new material risks entering the environment over a given period. It exposes the effectiveness of preventive controls alongside business growth factors. Risk departure rate, or burndown velocity, is the volume of risks your team successfully closes or accepts over that same period. Crucially, departure is a rate of volume, not a measure of time. If your arrival rate consistently outpaces your departure rate, your risk debt is compounding. Finally, risk survival is the persistence time of a specific risk; the lifespan from discovery to departure. Survival measures the actual efficacy and capacity of your remediation engine. If risks survive longer than your agreed business tolerance, you are operating outside your risk appetite.
If presented visually, accompanied by incident costs, the board will be able to see if the organisation is making real progress on risk. Where investments have been made, decision-makers will be able to visualise if they are bringing adequate returns. They will see if the remediation engine can deal with the volume of new arrivals and if critical issues are being addressed in a timely manner. Stakeholders will be able to participate constructively in the risk conversation. They will be able to make suggestions about the prioritisation of critical issues that may stand in the way of revenue generation. They may direct the security team to concentrate on those issues and allow lower-risk threats to be addressed by automation.
Je parle risk
The currency of risk is money. If the CISO can craft a narrative around profitability, impact, downtime, costs and benefits, they will attract more decision-makers to their corner. Managing risk is orders of magnitude more effective than managing technology in the current threat landscape. The security function must evolve to become a risk function; one that makes better decisions, faster decisions and decisions that can be readily defended. In an expat heavy region, it is not uncommon for people to want to learn a foreign language. Why don’t we all learn to speak risk? Let Cyber Risk Quantification be your Babel Fish.
Sorry, the comment form is closed at this time.