How to create a transformational cybersecurity strategy: 3 paths

Enterprises must build a security strategy that is aligned with business needs.
Enterprises cybersecurity teams are in the midst of an intensifying storm: Technology challenges are growing more complex, and the speed of business continues to increase along with the number of cyber threats companies are facing, Andrew Rose, chief security officer of Vocalink, said in a Thursday session at RSA 2019.
“Security is being put under immense pressure to keep up, and if it doesn’t, we’re the ones to blame,” Rose said. “We need to keep up or we just get left out.”
We are also in the midst of the age of the customer, wherein customers care more about privacy and security than ever before—and if they aren’t happy with a company, they walk away, Jinan Budge, principal analyst at Forrester Research, said in the session.
However, this all opens up new opportunities as well as challenges when it comes to creating a transformative cybersecurity strategy, Budge said.
“There’s a fine line between the deeply technical, scientific part of cybersecurity, and the people part, which we spend less time talking about—the stuff that actually enables a sustainable transformation,” Budge said. “We’ve seen how one without the other can fail.”
A good strategy moves security from an IT issue to one of customer trust, Budge said. It also moves security from a technically-focused discipline to a holistic one, and gives business the freedom to achieve its digital aspirations, rather than acting as a blocking agent, she added.
Bad cybersecurity strategies are those that cause companies to miss the breaches they experience, that invest in the wrong areas, that require teams to spend their time responding tactically, and that struggle to attract and retain talent, Budge said.
No one silver bullet exists for creating a cybersecurity strategy; each is dependent upon the size of the organization, its cybersecurity maturity, and the level of support in the organization, Budge said.
Here are three different paths that enterprises can take in creating a cybersecurity strategy.
The benefits to this strategy include the fact that it is quick to put together, and can involve a one-year plan. It’s also comfortable for the CISO and security team to build.


