Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Practical Risk Management – Beyond Certification
Articles Risk Management Security Training & Education

Practical Risk Management – Beyond Certification

Alok.TripathiBy Alok.TripathiJanuary 10, 2023Updated:July 30, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Organisations regularly invest in their information security management systems (ISMS). These investments are a cost-of-business and cover the basics of fulfilling regulatory, compliance and certification requirements.

However, most organisations implement ISMS based on the ISO framework, creating policies and documentation that are static and unwieldy – this creates a challenging situation. Documents can be open to interpretation and lose any real value envisioned by the ISO framework.

The whole audit exercise becomes time-consuming, costly and cumbersome.

As we see cyber security move from a simple operational topic to a business requirement, ISO certification costs (which, on average, are €200k to €250k per annum for a medium-to-large company) should be converted to an investment better aligned with business needs.

  1. Security is more than certification

It’s one thing to have security certifications displayed on your website, but they become meaningless without taking action.

Companies need to honestly assess if they are getting true value from security certifications or if those certifications are just being used as tick-box exercises to reassure customers and increase sales.

Security certifications need to help organisations mitigate real threats, or they have no real value. So, verifying that a certification like ISO27000 is being implemented is vital.

  • Corporate security doesn’t stop at the IT or security team

It’s easy to forget about IT security and trust that the team responsible for securing the organisation’s infrastructure will do their jobs well, leaving other teams to do theirs.

But, with over 80% of cybersecurity breaches involving people, that mindset leaves organisations vulnerable to attack.

Everyone in the organisation should be responsible for security. That may require a culture change, but it’s a change that has to be made. 

Organisations also need to take a more refined approach to security training. We’ve identified four kinds of approaches that employees have to risk:

  • Risk-Takers – people who are open to taking risks but usually evaluate that risk first. 
  • Risk-Breakers – these people are responsible but a bit too detail-oriented. They’ll prefer to follow detailed instructions regarding IT security, but they could fall victim to more creative phishing attempts, like vishing. 
  • Risk-Makers – these employees tend to be more creative and innovative but may also see rules more like guidelines. 
  • Risk-Shakers – these people tend to learn through their own experiences. They’re curious and self-directed but won’t take risks unless they assess the risk as very low.

The best IT security training considers an employee’s approach to risk when training them. For example, an overly detailed set of rules is likely to alienate someone who shuns too much direction, whereas that same list of rules might give other employees a false sense of security.  

  • Be prepared to face new and emerging threats

As well as personalising security training, organisations that want to stay on top of security threats will ensure their training is updated regularly.

Cyberattacks are constantly evolving, as are points of vulnerability – from connected devices to vulnerabilities introduced with increased virtual working.

Cyber-criminals are always looking at ways to manipulate employees through social engineering (they may even use ‘whaling’ – targeting phishing attacks at senior executives or vishing to mimic the same executives’ voices to get more junior employees to do what they ask).

Organisations also face an increasing number of automated attacks from many areas and need to efficiently integrate their internal and external threat vectors to mitigate this threat.

Of course, this is easier said than done. It means daily, automated threat-hunting exercises and using level 2 or 3 security operation centre experts to review external threat intel and correlate it to vulnerabilities the organisation has already identified. Businesses also need to develop new threat-hunting tests and exercises to work on the findings – this is a continuous process.

  • Invest in recovery, threat protection, detection and response

As more organisations invest in good Security Information and Event Management (SIEM) platforms, they realise these platforms’ inbuilt tools aren’t necessarily tailored to their needs. Existing teams often take a long time (around six months on average) to get these platforms up to the required specifications.

The best way for organisations to hit the ground running when it comes to threat protection is to prioritise and be agile with their investments in improving the platforms they use. For example, while the SIEM platform is being implemented, invest in updating, automating and teach the system to spot real threats and reduce background noise. Use the findings of previous penetration testing, vulnerability scans, red teaming, etc., to prioritise use case implementation.

Organisations can improve the effectiveness, efficiency and return on investment of their cybersecurity by working with a partner that implements machine learning, artificial intelligence and other digital solutions that help improve the overall security of the business.

Alok.Tripathi

Principal Consultant and Cyber Security Specialist

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}