04.06.2024
Blog
Cyber Security

Six points for effective cyber security management

Geopolitically motivated cyberattacks are increasingly taking place not only between nations. Public and private organisations are also frequently targeted, as confirmed by the 2023 ENISA Threat Landscape (ETL) Report. Businesses and public authorities are called upon to bring their cyber security management up to scratch in order to withstand these attacks.

Philipp Kleinmanns
Senior Vice President Cross-Market Services Consulting

According to the European Union Agency for Cybersecurity (ENISA), almost a fifth of incidents alone affected public administration. A further 13 per cent targeted digital infrastructure and digital services. Small public authorities or businesses (SMEs) are not necessarily the primary target. However, they can serve as gateways for attackers to gain access to large corporations or states, for example if these SMEs are their suppliers.

Vulnerabilities can arise, for example, in the software products used or with external service providers. To identify such interconnections, politically motivated attackers carry out thorough market research in order to reach their target, even via circuitous routes.

Data centres and IT service providers are also in the spotlight. These are attractive targets because they have access to a wide range of public institutions and businesses. Geopolitically motivated attackers are not necessarily after money. According to ENISA, they often seek to obtain information, sensitive data and trade secrets, or even to cause disruption or damage.

How well organisations can defend themselves against such threats or manage a security incident does not depend primarily on their size. What matters most is the priority given to cyber security and the resources made available:

  • Chief Information Security Officer (CISO): Cybersecurity is no longer a matter that can be dealt with as an afterthought. Ideally, there should be one person who is fully responsible for IT security.
  • The CISO’s position: Cyber risks can become an existential threat to a company. Cyber security should therefore be closely interwoven with business strategy. Consequently, the CISO and their team should not be assigned to the IT department, but should report directly to senior management and the board.
  • Willingness to change processes: Security is a cross-functional aspect that affects many processes within an organisation. Whether it be HR processes, procurement and finance processes, or asset and access management: security should be integrated throughout.
  • Budget for security tools: The CISO should have sufficient budget at their disposal to procure, customise to specific requirements and operate the necessary security technology, which should also be capable of automatically detecting suspicious activity on the company network.
  • Human resources: In addition to the technical aspects, an organisation needs a well-resourced cyber security department. On the one hand, protection against cyber-attacks is a broad field that requires a wide range of skills. On the other hand, cyber security is very time-consuming, as attackers do not adhere to business hours and attack methods are becoming increasingly complex.
  • Resilient process chains: Even if cyber security is well established, a security incident may still occur. In such cases, it is important to have a plan in place for how to proceed should the worst happen. The processes should span all areas: from the business side through to the technical side, right through to third parties such as service providers or customers. Planning should include, amongst other things, who informs whom in an emergency, who has what decision-making powers, and how to respond to an incident in time-critical situations. Establishing a Business Continuity Management System addresses these challenges in a structured and sustainable manner.

Developing a cyber security strategy is often a demanding task. Firstly, awareness of the threat landscape must be raised across the entire organisation so that IT security is given the importance it deserves. Internal resistance should not be underestimated, so it is important to involve all staff at every level. It can be helpful to seek external support for the design and day-to-day operation, for example from a Managed Security Service Provider (MSSP). The technology must be regularly reviewed and updated, and specialist staff must also be kept informed of the latest attack methods and security risks. It may make sense to outsource entire sub-areas – including human resources, security technology and (sub-)processes – to a service provider and utilise a SOC-as-a-Service, either as a cloud-based or on-premises operating model, depending on requirements. In this way, security technology and expertise remain up to date, and the company can focus on its core business.

Philipp Kleinmanns
Senior Vice President Cross-Market Services Consulting

Philipp Kleinmanns ist Senior Vice President Cross-Market Services Consulting bei Materna. Sein Verantwortungsbereich umfasst die kundenorientierte Optimierung von Service-Prozessen, die Entwicklung moderner Cloud-Infrastrukturen und das Thema Cyber Security.