Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - 3 Reasons Why Cybersecurity Is Not A Technical Problem
Articles

3 Reasons Why Cybersecurity Is Not A Technical Problem

ISBuzz TeamBy ISBuzz TeamMay 29, 2020Updated:March 15, 20236 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When the storm over a cybersecurity event settles, it’s easy to look back on a seemingly obvious technical deficiency like an unsecured elastic search server or missing patch and point fingers. Most of the time, security leaders will voluntarily or involuntarily take the fall, and soon thereafter the organization will start a fresh security journey, with a newly installed security leader and blank check to “get it right” this time.     

It’s sad to see these technical post-ops continue to be the norm, when evolving to a business and risk approach to cybersecurity can produce a much better outcome, even if a cybersecurity event happens. Imagine instead of the foregoing, the aftermath of a cybersecurity event produces a narrative along the lines of “We’re disclosing a cybersecurity event that we knew was possible, that we were able to effectively minimize thanks to appropriate focusing resources, and that we’ll be able to recover from thanks to appropriate planning, reserve funds and sufficient insurance.” That’s successful cybersecurity risk management in action.   

The world unfolding in real time thanks to COVID 19 may be the spark that finally causes organizations to evolve beyond a predominantly technical approach to cybersecurity. As we’re seeing in real time, years of advancements in technology and medicine can’t definitely prevent something really bad from happening. Organizational leaders have to accept that reality and prepare accordingly. Further, and more immediately impactful, the days of the security leader’s blank check are over. It’s unlikely that security spending will be as susceptible to other budget areas, but it certainly won’t avoid the same level of scrutiny, with every dollar spent under the microscope for as far as the eye can see.   

In preparation for this shift, it’s time for all stakeholders to learn how to play together nicely, and to prepare for this changing world post Covid19. There are more connected devices than ever, more of us will be working off-site, and the risks will only become more complex. Cyber risk is getting worse, but understanding and managing it needs to get better immediately. Below are the top three reasons why cybersecurity should no longer be just viewed as a technical problem.  

Reason 1: The Technical Language Limits a Secure Understanding    

The security industry speaks in a language only they understand, a limiting vocabulary for specific problems that they would like to communicate with and solve with their own internal community. We recently met with a CISO of a large healthcare organization. Like every good healthcare CISO, he was focusing on patient health information as the top priority. It surely made sense if you looked at things from a data perspective. Personal health records are the most valuable on the dark web. And given all the recent healthcare breaches and financial consequences, it’s on the top of every healthcare CISO’s mind we’ve spoken with. So all their security efforts were geared towards HIPAA compliance and the various HIPAA components in regard to safeguarding patient information. That was the language they were fluent in, cyberspeak, healthcare regulation and compliance dialect.    

But after installing an evolved approach and solution, we quickly discovered a cyber risk that was completely off the radar. They were completely blind to the fact that they had manufacturing facilities producing a large supply of a critical blood testing compound, which could be impacted by a cyber event against the control systems. And they didn’t even have a firewall around the technology running these facilities. They never thought to look there because those operations didn’t use any protected health information.  

Reason 2: The Technical Dollars Don’t Ensure Financial Sensibility   

An important question security leaders often do not have the answer to is: “What does cybersecurity mean to us as a business?” Often they are focused on the technical solutions.  

But in our uncertain times, it’s critical for the scope of impact to be examined from all sides of the business, and all risks to be considered and analyzed. There are cyber risks that go beyond a technical security mechanism that need to be accounted for, particularly if they can create a liability for the company that needs to be mitigated.   

Imagine a CISO of a large petrochemical refinery, quite capable in understanding how to protect his perimeter. But regardless of security know-how, one of his biggest risks was an explosion caused by a cyber-attack that over-pressurizes valves at the facility.  This CISO was completely blind to the fact that the company’s property insurance policy had an exclusion for cyber attacks. This is something we recently witnessed, and if an event like this would actually happen, it would cause billions in damages that could not be recouped from the insurance program. The voice of the dollar echoes far and wide, beyond the pure technology solutions and the CISO.   

Reason 3: The Technical Reports Don’t Measure Quantitatively  

Security leaders often measure success qualitatively, displaying colors in the shade of a traffic light to stratify risks and priorities. This will begin to change as budgets will be scrutinized more carefully by the CFO and other executives. And fiduciary responsibility will be heightened for board members, as more stakeholders will demand to know if the dollars are making an impact, and if the money for security is being allocated most cost-effectively.   

The current state of a cybersecurity program will no longer be just a technology inventory or a gap analysis. It will be defined quantitatively as far as spending an appropriate amount to maintain the requisite technical maturity needed to protect against risk that an organization would otherwise face. Recognizing also that cyber risk scenarios are not created equally. Why should a CISO be allowed to spend $1 million dollars to only marginally decrease the probability that they would get hit with a $10 million-dollar event when concurrently they could spend the same $1 million dollars to more greatly reduce the risk of a $50 million event.  

Cybersecurity is a business problem that requires a business solution. Stakeholders outside the security organization will never be tech gurus. But they can read financial statements and be able to quantify cyber risk from a cause and effect perspective. Our world may never be the same, but the framework to communicate cybersecurity is already in place. There are many tools to provide clear visibility into business impact and ensure both unity and security for the enterprise for many years to come.  

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}