How to Embed Cyber Risk Into Business Innovation

548 views
β€’
March 24, 2017
by
RSAC Cybersecurity
YouTube video player
How to Embed Cyber Risk Into Business Innovation

TL;DR

Cyber risk should be built into product strategy, application development, operations, and user experience from the beginning. Organizations can allocate scarce defenses more effectively by valuing data, reassessing that value as conditions change, clarifying cloud responsibilities, and treating secure code as an essential measure of product quality rather than a separate technical requirement.

Transcript

And good afternoon. It's Thursday of a long conference week, so we're gonna try to have some fun this afternoon. Um, we'll probably open it up for questions on the early side so that we can get some engagement from all of you, and any questions that you might have. Um, as mentioned, I'm Emily Mossburg. I'm a partner in Deloitte Cyber Risk Services ... Read More

Key Insights

  • Cyber risk is becoming a business concern because security events now disrupt individuals, customers, and organizations in visible ways. That experience changes cybersecurity discussions from narrowly technical exchanges into questions about business impact, customer impact, product decisions, and possible solutions.
  • A risk-oriented security model is necessary because organizations cannot mitigate every threat before it crosses the perimeter. Security teams must instead assess the value of data and decide where scarce resources can most effectively reduce exposure and protect important business assets.
  • Data valuation is dynamic because one dataset may become substantially more valuable while another becomes less valuable. A useful cyber-risk program therefore cannot treat protection priorities as permanent, since changes in data value may require resources and controls to be reassigned.
  • Cloud migration changes the risk profile by moving applications and data away from an organization's own data center. This raises questions about how much responsibility remains with the organization and how much is handled by the company operating the cloud environment.
  • Cloud services can reduce risk when providers offer security expertise that an organization cannot build internally. The FCC example presented in the discussion shows a CIO viewing cloud migration as safer because Amazon had hundreds more security engineers than the agency.
  • Cloud security has no single conclusion for every organization because the panel describes an unresolved debate over whether migration creates more or less risk. Different organizations may reach different conclusions after comparing provider expertise with their existing data-center capabilities and controls.
  • Secure user experience is not separate from cybersecurity because an experience cannot be considered good if using it exposes the customer to compromise. Product teams should connect every relevant design decision to both usability and the protection expected by the user.
  • Application security is a measure of code quality because vulnerabilities indicate weaknesses in the software being built. Treating security as part of good-quality code can integrate it into product development instead of leaving it as an additional category reviewed after implementation.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why should cyber risk be part of business innovation?

Cyber risk should be part of business innovation because new products, connected services, cloud workloads, and changing customer interactions can introduce new vulnerabilities and liabilities. Security considerations can influence whether an organization should proceed with an idea and how it should design the resulting service. Bringing cyber risk into early decisions also connects protection requirements with business impact and customer experience.

Q: How should organizations prioritize cybersecurity resources?

Organizations should prioritize cybersecurity resources by assessing the value of their data and directing scarce resources toward the assets where threats could matter most. This approach accepts that every threat cannot be stopped before reaching the internal environment. Priorities must also be revisited because the value of a dataset can increase or decrease substantially from one period to another.

Q: Why is valuing organizational data difficult?

Valuing organizational data is difficult because its importance is not fixed. One dataset may rise substantially in value while another becomes less valuable, changing the potential consequences of compromise. Since security resources are scarce, these changes can alter which assets deserve the strongest protection. A risk-based program must therefore reassess data value rather than rely on a permanent ranking.

Q: How does moving workloads to the cloud change cyber risk?

Moving workloads to the cloud changes cyber risk because applications and data are no longer managed entirely within the organization's own data center. Some operational responsibility may shift to the cloud provider, creating questions about who handles particular risks. The organization must compare its internal controls and expertise with the provider's capabilities before deciding whether its overall risk profile improves or worsens.

Q: Can cloud migration make an organization more secure?

Cloud migration can make an organization more secure when the provider offers expertise and staffing that the organization cannot build internally. The panel cites the FCC, whose CIO viewed moving all agency data to the cloud as a way to reduce risk because Amazon had hundreds more security engineers than the agency. The conclusion still depends on each organization's circumstances.

Q: Why is there no consensus on cloud security risk?

There is no consensus on cloud security risk because migration can both shift responsibility and provide access to greater security expertise. An organization may worry about losing centralized control when another company operates its applications and data. Alternatively, it may conclude that a cloud provider can protect those workloads better than its own data-center team. Different organizations therefore reach different judgments.

Q: How can companies balance user experience and security?

Companies can balance user experience and security by refusing to treat them as separate goals. A good experience should include protection against compromise, so security should influence the same decisions that shape how users interact with a product. Connecting security requirements to user outcomes helps teams treat protection as an inherent quality of the service rather than an added obstacle.

Q: Why should application security be treated as code quality?

Application security should be treated as code quality because vulnerabilities are defects in what the development process produces. Describing secure software as good-quality code brings protection into ordinary engineering expectations instead of placing it in a separate category. This framing can help product and security teams consider vulnerabilities throughout development and connect technical decisions with the user's experience.

Summary & Key Takeaways

  • Cybersecurity is moving beyond an isolated IT function because connected products, cloud adoption, successful attacks, and growing public awareness directly affect customers and business decisions. Organizations must evaluate cyber liabilities during innovation and product development, including whether a proposed service should proceed and what protections its design requires.

  • A risk-oriented security model recognizes that organizations cannot stop every threat at the perimeter. Leaders must identify valuable data and direct scarce resources toward protecting it, while recognizing that data value can change substantially over time. This dynamic valuation makes cyber-risk prioritization necessary, difficult, and subject to continual reassessment.

  • Cloud migration changes who operates systems and may shift portions of risk to service providers. Some organizations view cloud platforms as sources of security expertise they cannot build internally, while others remain uncertain whether their overall exposure improves. Effective decisions therefore require clear responsibility, organizational context, and careful risk comparison.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š