To comply with the Securities and Exchange Commission (SEC) rules on cyber risk management and incident reporting and navigate the current threat landscape, it’s time to integrate business intelligence into the managed detection and response (MDR) and security operations centers (SOC), argues Christopher Hetner, co-chair of cybersecurity and privacy at Nasdaq Center of Board Excellence.
The new SEC rules demand that public companies disclose “material” cybersecurity incidents within four business days, and elaborate on their processes for assessing, identifying and managing material risks from cybersecurity threats and their boards’ roles in the oversight, among other requirements.
“If you think about the security operation centers, they're mostly staffed with analysts that are in their mid-20s. So how do you expect these analysts to determine materiality based on a signal or anomaly on their network?” Hetner told SDxCentral during the HITRUST Collaborate Conference.
“We shouldn't be asking the CISO and their teams to figure out the financial impact, that's just absolute insanity,” he said, adding that’s why organizations should bring business intelligence into these domains.
Traditionally, MDR and SOC have been primarily focused on the technical aspects of threat detection and response. Now, some vendors see a shift in the industry to bring more business intelligence into their MDR platforms and other product suites to meet new cybersecurity requirements, Hetner noted.
One example is CrowdStrike, which recently expanded its MDR to offer managed extended detection and response (MXDR) services. The vendor announced the availability of X-Analytics from Secure Systems Innovation Corporation in the CrowdStrike Marketplace.
X-Analytics is designed to help identify business exposure to cyber risk, develop business-aligned cybersecurity strategy and communicate the technical complexity of cybersecurity risk in business terms to executive and board-level audiences.
“I think [CrowdStrike] sees this as an opportunity to bring further value in their product set, which is a good thing because we need to become more business-aligned in terms of how we think about cyber from a product standpoint,” Hetner said.
The necessity for CISOs to develop business competencyIn addition to bringing more business intelligence into cybersecurity services, Hetner also underscores the necessity for CISOs to develop business competency and introduce more business context, a shift that is crucial for effective participation in the boardroom.
Despite the increasing awareness of cybersecurity’s importance, he acknowledges that having security leaders on boards is not a common practice among public companies.
“The security community as a whole does not have the competency to be effective on a board. They have to have a full, wholesome view as to what the nature of the business is, understanding market dynamics,” Hetner said, suggesting that CFO or risk or audit committee chairs might be better positioned to drive discussions on business resiliency and investment strategies.
He noted the CISO transition from a technical to a strategic function requires a significant shift toward business competency, a transition that may not be realistic for the majority of CISOs who have risen through the technical ranks.
“Look at the total addressable market, there's 10,000 [publicly] listed companies. You can't realistically deploy 10,000 CISOs that have competency,” Hetner said. “I can list on maybe two hands the numbers of cybersecurity professionals that can be effective in a boardroom.”
“So instead of fighting that battle, which is not realistic, let's bring forward more business focus and context to the boardroom. So that now we speak in the language of the board and where to bring forward an area and specific topics that are understood and acceptable,” he added.
Comments