IBM Security today announced a new service to help companies analyze and quantify their security risk so that they can make better cybersecurity spending decisions.
Despite security and data breaches costing companies millions of dollars — IBM’s 2020 Cost of a Data Breach report puts the average total cost at $3.86 million — CISOs still have a tough time justifying security budgets to corporate boards of directors. In fact, only 27% of CISCOs are ultimately responsible for their organization’s security spending and policy decisions, according to that same IBM report.
IBM’s new Risk Quantification Services, offered in partnership with RiskLens, gives CISOs financial data to put dollar amounts on their company’s security risk and justify spending on new technologies and investments, said IBM’s Julian Meyrick, managing partner and VP of security strategy, risk, and compliance.
Why Risk Quantification Matters“That’s why risk quantification is so important,” he said. “IT security professionals for many years have been talking about the fact that security should be a board-level issue. But too often, we, as IT security professionals, have gone into the boardroom and talked in-house gobbledygook as opposed to talking in business language. That’s the challenge that risk quantification really helps us with — it talks in pounds, euros, dollars, which is ultimately the main business language. So now, we’re talking about the financial impact to business, and how we can reduce that by increasing cybersecurity. And that’s a very important conversation.”
The partnership essentially combines RiskLens’ quantitative cybersecurity risk management platform with IBM’s enterprise-scale security products, services, and threat hunters. “RiskLens gives us a partner with a [software-as-a-service] platform built on the FAIR methodology, which means we can deliver enterprise-scale risk quantification programs,” Meyrick said.
How IBM Uses FAIR MethodologyIBM Security applies the Factor Analysis of Information Risk (FAIR) methodology — an open, international standard for cyber risk modeling — to its customers in collaboration with RiskLens. This quantifies risk by calculating the probability of a security event occurring and the probable loss projection based on expected data loss, operational disruptions, and business context.
Additionally, IBM Security provides business context for its risk calculation models using its security portfolio, consulting services, and IBM X-Force Threat Intelligence. And, of course, the vendor then offers mitigation recommendations via its security services based on their costs and expected risk reduction.
The new service helps CISOs put a price tag on security risk for areas including cloud, mergers and acquisitions (M&A), and remote work, Meyrick added. For example, a risk quantification assessment could help organizations decide which workloads to move to the cloud while also recommending security controls to put in place based on a cost-benefit impact analysis.
Assessing M&A Cyber RiskWhen it comes to M&A transactions, security risk quantification helps organizations proactively mitigate risks before they turn into active threats, and it enables them to assess the risks that might impact the target company’s value.
“We can help CISOs proactively build security risk into the corporate mergers and acquisitions process and use risk quantification as part of that methodology,” Meyrick said. “I’ve also spoken to CISOs who have, within weeks of acquisitions, had to divert resources to deal with a security breach as a result of the acquisition coming on board.”
This service also gives companies an M&A negotiating tool, he added. “The corporation could go into the conversation with the merchant banker and say we understand the price that you’re asking, but we’re going to offer you $10 million less because of the associated security risks we have identified and quantified. And the good thing about FAIR is that you’ve got all the data underneath to say this is how we came to the conclusion of $10 million.”
Additionally, as companies move to remote work because of the COVID-19 pandemic with many employees using their personal devices to access corporate networks and data, a zero-trust approach to security becomes increasingly important. “But where do you start? What are the key initiatives that you need to think about? Risk quantification can help you prioritize the key steps that would reduce your risk as you move to a model of zero trust,” Meyrick said, because the service assesses security risks, calculates their business impact, and then prioritizes mitigation.
Comments