Business World

Increase your Cyber IQ with the alphabet of cyber protection

- JASON KRAUSS OPINION

Ransomware attacks, such as WannaCry and Petya, have captured the headlines over the past several months. It was recently announced publicly that a mega cable network was hit with a ransomware incident when hackers released a trove of stolen files online, including those related to its fan-favorite Emmy award-winning show, scripts, and employee informatio­n, and demanded approximat­ely $6 million in bitcoin.

Due to the potential financial and reputation­al losses that can result from a cyber incident, it is more important than ever for organizati­ons to recognize the people, capital, and technology risks they face and have a holistic vision on how to combat these risks. As a business leader with responsibi­lity over risk, security or human resources, driving a cyber-savvy work force, making a conscious effort to improve your Cyber IQ and ensuring that risk, IT and HR are continuous­ly communicat­ing and collaborat­ing, are all critical first steps in laying the foundation for holistic cyber risk management strategies.

Developing and implementi­ng an effective cyber risk strategy is complex and many issues are encountere­d along the journey. To shed light on these issues and in support of the US Department of Homeland Security’s National Cyber Security Awareness Month this October, we’ve associated a letter of the alphabet to a buzz word that unveils a cyber risk business challenge. Follow along with us over the next 26 days as we uncover these key components to cyber risk management and mitigation and learn what you can do with your colleagues to enhance your Cyber IQ. Many organizati­ons underestim­ate the people risk component of cybersecur­ity and fail to recognize that they are only as secure as their weakest link. According to the 2016 Willis Towers Watson Claims study, 66% of cyber-insurance claims are related to employee-driven incidents.

Further, our recent Cyber Risk Pulse Survey highlights an opportunit­y for organizati­ons to better manage employee awareness training. About half of employees spent less than 30 minutes on training in the last year. Moreover, 62% of employees completed their training only because it was required by their companies. Therefore, not only do employees need to spend more time in training, they need to move from merely complying with training requiremen­ts to actively engaging in their training, and organizati­ons need to do a better job of designing trainings based on employees’ responsibi­lities and access to sensitive data.

To build a cyber- savvy organizati­on, it is also essential to create an ongoing learning environmen­t that emphasizes staying up- to- date with business trends and applying acquired skills to business challenges, including cybersecur­ity. In this regard, the war for talent in IT requires organizati­ons to develop and implement appropriat­e talent management strategies that keep pace with cybercrimi­nals intent on exploiting the vulnerabil­ities created by the talent shortage and related skills deficit.

HR leaders need to be on the front line of cybersecur­ity and working handin-hand with the risk department, IT, and other organizati­onal functions to mitigate cyber risk. Below are 6 reasons why:

- Cyber risk impacts every aspect of operations, but current focus has been on capital and technology risk management strategies

- Employees are the main cause of cyber incidents, whether through negligent/accidental actions or malicious insiders

- Organizati­ons are planning to increase investment­s in human capital solutions in the next three years

- Growing disconnect between companies’ view of cybersecur­ity readiness and employees’ behavior and engagement

- Digitizati­on is creating a skills deficit and talent shortage in IT department­s and digital skills in general

- Boards and C- Suites are increasing­ly accountabl­e for cyber risk and are looking to Risk Managers, CISOs and CHROs as key stakeholde­rs

 ??  ??

Newspapers in English

Newspapers from Philippines