The conclusion is almost uniform when you ask any seasoned cyber security executive, analyst, lawyer, or engineer: there is no such thing as a foolproof plan.
One way or another, organisations must operate under the assumption that a bad guy will get in at one point. This does not have to mean calamity though, with preparation and planning for the worst to occur serving as the best form of risk mitigation.
Implementing Continuous Monitoring and Minimising Attack Surfaces
Ultimately, a successful cyber plan will be in place when three key areas are included and an organisation is clear on how it should be executed. These three areas are: the completeness of security coverage to include all applications, services, supply chain links, and employees; the consolidation of danger points down to the lowest possible number by decommissioning unused systems, destroying unneeded data, and limiting the number of external vendors used; and assurance, where an organisation knows the status of its operations at all times, including what is happening in its gaps or weak spots. Continuous monitoring is key to telling a confident story when the media or regulators come knocking, as it is generally the communications after a breach that gets someone fired or forgiven.
“Every ASX-listed company, every private company in the top 1,000, every government agency has had a security review done by this point. Very few large or even mid-size organisations don’t have some idea of what they need to do. The problem is not being able to do it. Continuous monitoring is key to telling a confident story when the media or regulators come knocking. It is generally the communications after a breach that gets someone fired or forgiven.”
Nick EllsmoreCyber Security Lead | Mantel