cfotechoutlook

The Quintessential Technology Source for Corporate Financial Professionals

9January 2016and the like, companies are engaging specialized vendors to perform sophisticated compromise assessments. These assessments help gain visibility of the present state of dormant and active live threats within an IT environment.They can also result in newly detected data security incidents, some of which may be reportable. Although this might create a short-term financial and/or reputational challenge to a business, it is a responsible activity to undertake. In fact, all Blue Cross Blue Shield companies have recently gone through this type of assessment.CISOs are also engaging third-party experts to play the role of the adversaries targeting the organization and use their tactics and techniques to test defenses. These simulations expose vulnerabilities and capability gaps that can be improved upon to enhance the security posture against relevant threats. The cyber-threat landscape is quickly evolving, and the sophistication of attackers has increased significantly, with more and more reports of organized crime groups and nation-state involvement. A quick rundown of best practices in defending against these more advanced attacks includes:1. Protect all layers of technology associated with enabling what it takes to offer the "at- your-fingertips" information to your constituents, namely your computing perimeter, network, PC endpoints, applications, databases and core computing infrastructure.2. Protect your system administrative accounts and monitor their use; ensure that multi-factor authentication is required when using such accounts.3. Segregate your systems into networks based on the sensitivity of the data.4. Implement advanced security monitoring capabilities; preventive controls are not perfect, so a good detection program is required.5. Limit workstation-to-workstation communications.6. Document an incident response plan and continuously test it.7. Secure the physical facilities where data is stored.8. Drive cybersecurity awareness across the organization and test employees' willingness to click unknown links and open unfamiliar documents. Beyond these practices, a company should have sufficient funds reserved or insurance to address the economic loss that would accompany an incident.Protecting Personal DataA large portion of the U.S. population has, as a result of the recent breaches, been offered identity and credit protection and reparation services. While this has become common practice in response to a breach, last year Blue Cross Blue Shield companies agreed to offer such services to members prospectively, regardless of whether or not a breach had occurred. In addition to the obvious consumer benefits and peace of mind this delivers, such proactive offerings can help businesses avert losses up front, complementing early warning systems and thereby limiting potential damage and liability. That said, today many consumer programs are prohibited by regulatory agencies from receiving this service constraints that bear critical review in the name of consumer protection. These services are only one weapon in the arsenal of individual data protection. Equally, if not more important, are some basic habits that every individual should adopt to help avoid becoming a victim of identity theft and fraud. Closely monitoring our bank account and credit card activity are among these. As employers, it is important to educate employees on how to follow good cyber-hygiene practices, for instance, not attempting to access unauthorized websites and not opening suspicious email messages, but rather bringing them to the IT security team's attention. Cyber threats are a fact of modern life, today and going forward. They are also a dynamic threat, meaning they cannot be solved for so much as managed through equally dynamic risk mitigation. The actions outlined above are a good starting point, as is keeping current with the latest threats to help identify and direct future actions to protect one of your organization's most valuable assets, its data. $Companies large and small are beginning to ramp up the resources they devote to data securityRobert J. Kolodgy
< Page 8 | Page 10 >