eBook | A CISO's Guide to Resilience | Check Point Software

A CISO's Guide to Resilience

Table of Contents

  1. Introduction
  2. Resilience Pillars
    1. Anticipate
    2. Withstand
    3. Recover
    4. Adapt
  3. Conclusion

Introduction

Imagine this: In the tech-savvy town of Techville, a company called SecureSystems was well-known for its software products and digital services. The company displaced competitors with top-tier offerings, impeccable customer service, and outstanding quarterly results. The company was so profitable and had such vast access to large customers that a group of hackers believed that they would profit from extracting company data and intellectual property. What initially appeared as a few minor and isolated cyber incidents began to turn into a full-scale cyber breach.
Adversaries seemed to have uncanny insider knowledge of SecureSystems’ vulnerabilities. The firm’s cybersecurity team sprung into action, but they had a daunting challenge ahead of them. Hackers exploited a number of vulnerabilities. They also installed multiple backdoors and compromised both phones and email systems. The length of time required to resolve the issues wasn’t readily apparent. As the days turned into weeks, the financial losses began to stack up. SecureSystem’s clients, concerned about the security of their data, started to back out of multi-year contracts. SecureSystems’ stock price plunged and layoffs became inevitable. The media covered the company’s downfall and created a grim narrative. As SecureSystem’s freefall continued, leaders and teams both realized that they hadn’t sufficiently prepared for a situation of this magnitude. The company had invested in extensive cyber security (after all, it was a tech firm). But that wasn’t enough. That’s where resilience enters the picture.
Failure to pursue cybersecurity and business resilience leaves enterprises vulnerable.

Definition

The National Institute of Standards and Technology (NIST) defines cyber resilience as the ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on systems that are used or enabled by cyber security resources. The goal of cyber resilience is to allow an organization to thrive amidst adverse conditions. Adversity may pertain to cybersecurity, as in the Techville narrative on the previous page, but it could also pertain to an environmental disaster, a pandemic, or financial volatility, among other things. In this eBook, discover how to build greater resilience into your businesses through cybersecurity and cyber resources. Find out about how to execute against a resilience framework and get cutting-edge real-world insights that can prepare you for whatever comes next. Enhance your risk management model. Get back to business-as-usual after an unanticipated incident—not in days or weeks, but in minutes.

Resilience Pillars

In striving for greater business resilience as enabled through cybersecurity and cybersecurity resources, NIST’s “pillars” can serve as a guideposts. According to NIST, resilience refers to the abilities to:

  1. Anticipate

    • Move away from a reaction-based crisis response and towards an outlook that anticipates adversity.
    • Incident Response Planning and Scenario-Based Planning: Leaders need to create and test versatile incident response plans that pertain to a wide spectrum of adversities, risks and high impact events.
    • Threat Intelligence and Monitoring: ESTablish robust threat intelligence programs and ensure corresponding tools can gather and analyze vast volumes of data.
    • Vulnerability Assessments and Penetration Tests: Lead efforts to identify weaknesses in the organization’s security posture.
  2. Withstand

    • Minimize business disruptions during adverse events. Implement redundancies for critical systems to ensure that failure in one area doesn’t lead to widespread disruptions.
    • Supply Chain Management: Keep lines of communication with suppliers open and establish channels to address supply chain issues.
    • Employee Preparedness: Foster a resilient workforce by promoting a culture of well-being and mental health support.
  3. Recover

    • Recovery planning can limit the effects of a cybersecurity event on a business, its customers, and on the market. Efficient detection and recovery strategies are key.
    • Implementing an incident response management plan will help organizations persevere amidst contested environments.
  4. Adapt

    • Ensure that an organization’s cybersecurity architecture evolves with the sophistication of threats. This includes implementing an agile means of managing risks and applying robust analytics monitoring.
    • Explore deception strategies such as honeypots to divert hackers’ attention if they access the network.

Conclusion

Resilience isn’t just about resisting shocks and staying the same. It’s really about becoming “antifragile,” as defined within Nassim Taleb’s book. Taking a proactive approach to the resiliency framework described in this eBook will not only assist your organization in resisting and recovering from adversity but will also transform your organization and enable your business to become more competitive, reliable, and well-regarded as a result. Building resilience is a continuous process that needs to evolve alongside your organization and the threat landscape.