The
Gartner Security & Risk Management Summit, a 2-day event hosted in London end of September 2023, is an annual event that helps leaders in the field of security and risk management gain know-how on upcoming trends and threats in the field.
Gartner reinforced the tangible value that cyber security can, and should, generate for the enterprise while simultaneously challenging cyber security professionals to rethink outdated security principles and practices to enable transformation.
Gartner proposed a paradigm shift for cyber security professionals to rethink many of the current principles used for securing the enterprise and challenge us to reconsider the approach to cyber security across business engagement, technology, and talent. By having a ‘minimum effective mindset’, which is a ROI-driven approach, we can deliver maximum effect and debunk
four myths, namely:
Myth #1: More data equals better protection — Instead, cyber security should concentrate on obtaining the minimum amount of data necessary to address vulnerabilities effectively.
Myth #2: More technology leads to enhanced protection — This perspective can result in hasty or point technology acquisitions creating greater complexity and noise.
Myth #3: More cyber security professionals mean better protection — Scaling services to match enterprise pace necessitates a different approach than more people.
Myth #4: More controls yield better protection — Excessive controls often create employee ‘friction’, which encourages the wrong behaviors as employees seek to achieve their objectives, thus rendering this counterproductive.
The perpetual pursuit of maximum effort in cyber security operations takes its toll on CISOs, security leaders, and their teams. The reality for most organizations is that they simply cannot focus on perfecting all aspects — more data, more people, more controls, and more technology — given limited resources and budgetary constraints. The analogy here is if we consider four attributes of a car — chassis, suspension, brakes, and engine — then there has to be a balance of the investments and development, or we could end up with a very fast, great handling car that you cannot stop due to no investment in the brakes.
Swanson: “With a minimum effective mindset, the focus is shifted away from trying to be absolutely perfect at everything, but making sure your security meets the requirements of the organization, thus unlocking tangible, valuable outputs.”
Another take away from the summit was about what was important for CIOs and CEOs from a cyber security perspective and the implications for security and risk leaders. The view was that company boards are willing to increase risks but want tangible dividends from their digital investments. In other words, this means that they need their CISOs and their teams to ensure they are working on the key initiatives that offer the greatest business impact. This explains the
shift to more human-centric design practices in cyber security programs. What is then needed is not necessarily security for security’s sake, but rather security that is best aligned to what the business is trying to do and visibly so.