Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - A Spotlight On Critical Infrastructure: A Long Overdue Conversation About Risk
Articles

A Spotlight On Critical Infrastructure: A Long Overdue Conversation About Risk

Miles TappinBy Miles TappinAugust 5, 2021Updated:January 18, 20233 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A recent cyberattack targeting the world’s largest meat processor, JBS, points to a disturbing new reality: our nations’ critical infrastructures and supply chains are being targeted because they are not identifying the cyber risks that matter most to their operations.

Coming so soon after the ransomware attack against Colonial Pipeline where its perpetrators got away with $4 million in ransom money, it is becoming clearer by the day that there is an urgent need for critical infrastructure owners to adopt a risk-led cybersecurity programme. Despite the increase in these high-profile attacks, major firms are still not having the proper risk conversations between their cybersecurity experts and their business executives. 

Identify, Understand, Prioritise and Remediate

It is vital that the businesses that own and operate our nation’s critical supply chains start quantifying and prioritising their risks, leveraging threat intelligence, and automating and orchestrating their responses. And they must shift to this approach immediately.

One of the primary reasons critical infrastructure enterprises remain vulnerable is the lack of structure that has existed around enterprise cyber risk quantification. Last year’s release of an interagency report by the National Institute of Standards and Technology (NIST) titled, Integrating Cybersecurity and Enterprise Risk Management, identified significant shortfalls in enterprise cyber risk quantification efforts. “Most enterprises do not communicate their cybersecurity risk guidance or risk responses in consistent, repeatable ways,” the report states. “Methods such as quantifying cybersecurity risk in monetary terms and aggregating cybersecurity risks are largely ad hoc and are sometimes not performed with the same rigour as methods for quantifying other types of risk within the enterprise.”

The growing pace and sophistication of nation-state attacks, coupled with an ever-expanding attack surface, makes our ability to accurately quantify and prioritise cyber risks within the context of our individual businesses an urgent priority. But when business networks and systems can be compromised in a way that disrupts or halts industrial operations, that points to a clear failure to identify, understand, prioritise and remediate the most critical cyber risks facing one’s organisation.

The Risk – Threat – Response Paradigm

The Risk – Threat – Response paradigm enables business leaders to be better equipped in understanding and prioritising resource allocation. Keeping up with the threats and challenges that matter most to organisations requires a focus on cyber threat intelligence. By developing a cyber threat intelligence programme (CTI) organisations will be able to constantly reassess and process knowledge about cyber threat actors and will discover and understand the who, where, how and when of the challenges you face now and in the future.

Organisations today tend to be in a constant state of reacting to threats, vulnerabilities and incidents. Now is the time to become proactive, through a cyber threat intelligence programme that helps inform an organisation of its risk, aligning with the business as a whole to threats that matter most based on primary response and secondary loss – the damage that comes to the business as a result of the breach.

Bridging the gap between cybersecurity and business remains an aspirational goal for many who struggle to understand where to begin. We cannot allow this situation to continue in the critical infrastructure space. In a world of highly sophisticated cyber criminals, our critical infrastructures need to adopt a risk-led cybersecurity programme to help organisations not only prioritise and focus on the risks that matter most, but also will enable them to leverage threat intelligence to drive orchestrated response.

Miles Tappin

VP of EMEA

  • Miles Tappin
    Post-Pandemic Critical Infrastructure – What’s Next?
  • Miles Tappin
    Cyber Security is in Denial, That’s Why it Needs the Lean Six Sigma Approach
  • Miles Tappin
    The Brain Of Security
  • Miles Tappin
    5 Reasons CISOs Need Security Operations, Automation, And Orchestration (SOAR)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}