Cyber resilience becomes a key focus for companies as attacks accelerate

Alex Burnham, Director and Head of IT Audit and Security consulting was recently featured in an article from the Business Post by Penny Gray.

True cyber resilience extends beyond traditional security measures. Security by design has shifted from best practice to business necessity, with organisations expected to show regulators, customers and insurers that security has been integral from the start rather than added later.

The speed and scale of cyber-attacks is increasing, with artificial intelligence giving attackers new ways to identify vulnerabilities across organisations and their third-party environments.

“Whilst the cyber threat landscape to all organisations has remained significant over the last 12–18 months, we have seen one of the key areas of change in relation to the speed and scale of attacks,” said Alex Burnham, head of IT audit and security at Forvis Mazars. “Indications are the utilisation of AI is having an increased impact on the identification and exploitation of vulnerabilities across both internal and third-party environments.

“Improved and timely security vulnerability management processes are now critical. All organisations must implement threat intelligence processes to ensure that they are kept up to date with the latest vulnerabilities.”

The growing dependence on external providers is also creating additional exposure.

“Last year saw an increase in the number of high-profile supply chain and third-party attacks. Organisations need to engage both MSPs and SaaS providers to acquire the required skills, improve efficiencies and ultimately cut costs. Exploitation of such providers’ environments has significantly impacted operations, with Marks & Spencer and Jaguar Land Rover being good examples.

“Whilst at this point most organisations have third party risk management processes in place, in our experience with a diverse portfolio of clients, some organisations are still in the process of updating their third-party risk management processes with an aim to ensure that an adequate level of oversight is maintained across all third-party support providers throughout the lifecycle of the contract.

“Improvement to third party risk management processes includes: the maintenance of a centralised inventory of all third parties and their services that they provide, vendor risk classification based on their criticality to business operations, strong due diligence and risk assessment prior to engagement, clear definition of cyber security and regulatory compliance requirements, ongoing monitoring throughout the contract, business continuity and resilience with clearly defined recovery objective, and exit and termination management preparing for possibility that the vendor relationship end unexpectedly.”

As well as requesting cyber security gap analysis and compliance reviews against internationally recognised standards such as ISO 27001 and NIST CSF 2.O and Cyber Fundamentals (Cyfun) frameworks, Forvis Mazars clients are now asking how resilient and prepared they are to react to the cyber incidents ensuring the critical business processes are kept running or can be recovered within an adequate timeframe.

Resilience demonstrates that the organisation can continue operating when those controls are challenged or fail.

“For an organisation to gain enhanced confidence over its resilience and ability to continue operations or recover within an adequate timescale, organisations need to fully understand their environments, critical business processes and key risks and threats to those processes.”

“Having identified these key areas, they then need to develop and implement processes and technology to adequately protect the key business processes. These processes must be assessed on an ongoing basis to confirm their adequacy, with any gaps remediated. It is essential that senior management maintain oversight of the organisation’s resilience.”

In response to this, the Forvis Mazars cyber security team has been conducting risk-based simulation tests for many its clients. These tests are conducted to validate resilience and whether an organisation’s controls, processes and people can effectively manage the risks that pose the greatest threat to business objectives. Such tests do not only concentrate on incident response and technical recovery but also test how the business and senior management respond an incident.

“Organisations are coming to terms that cyber incidents will happen and changing their focus on not only preventing a cyber-attack, but also how they will respond in the event that they have a cyber incident,” said Burnham.

“The focus needs to move away from what technology will be affected by an incident onto what impact will this have on the business operations, determining which business services would be most affected by a specific cyber threat and ensuring that resilience plans are in place and have been adequately tested.

“Whilst prevention controls are important, ensuring the organisation has an adequate level of resilience in place is equally as essential. Therefore, the board must receive adequate training and frequent updates on the current threat landscape and how it impacts them and the effectiveness of response and recovery processes.”

Read the original article on the Business Plus website.

Contact