Cybersecurity Controls – All Are Not Created Equal

Cybersecurity Controls – All Are Not Created Equal

The last time I bought a new pair of ski boots was the late 90s. Just to give you some sense of how long ago that was, my mom paid for them.

But on my final day of the 2023 winter season, the top buckle buckled and broke off. So I cranked the strap as tight as I could and skied for half a day. It wasn’t the most comfortable, but it more or less worked.

Now, 25 short years later, the old pair needs replacing. (When I told my mom, she quipped, “I don’t think I still have the receipt to return them!”)

So last week, I went to Boston Ski + Tennis to find something new. The process was amazing; my 90-minute fitting session with a “ski boot specialist” led to the exact right boot for me. Throw in the custom inserts I opted for and the fit is super-comfortable.

Contrast this with my original buying experience all those years ago. I don’t remember it clearly, other than the fact that my aunt and uncle were there and they had to lie on the floor to help me get the boots on. Not exactly “high quality” customer service!

You won’t be surprised to learn that my two dissimilar ski boot experiences got me thinking about cybersecurity controls (I’m not embarrassed to admit most things do).?

Just as ski boots can differ significantly in both quality and associated customer experiences, cybersecurity is also both a product and a service. And there is a tremendous range of possibilities regarding where you may fall.?

Which means saying you have “cybersecurity controls” in place in your company is more or less the same as saying you “own a pair of ski boots.” Neither tells you a whole lot about your expected on-the-ground experience.

Take Multi-Factor Authentication (MFA), for example. Is it on one system, all key systems, every system? Is it optional, the default but still optional, required??

How about Managed Detection Response (MDR, often referred to as a Security Operations Center)? These solutions monitor the behavior of your environment (e.g., your EDR solution, your network, your cloud hosting platforms), notify you if something out of the ordinary is detected, and take steps to contain the problem.

But while your MDR may be technically first-rate, if the information is not presented clearly, questions are not answered promptly, and the MDR itself is not efficiently integrated into internal processes, it is not doing what it needs to do.

These are just two examples, but the concept applies across your operation: Metaphorically speaking, are your cybersecurity “boots” held together with an old, broken strap?

Simple Answers Are Not Enough

One-word answers to questions regarding cybersecurity (i.e., yes or no) are guaranteed to overlook what’s really going on. You need a deep evaluation of both tools and processes to know if your program is mature and fully implemented.

Keep in mind as well that when a new process is put in place, it typically requires multiple iterations to get where it needs to be. Cybersecurity is anything but plug-and-play.

The point is, “functioning” is not the same as functioning well. And unlike with a ski boot, signs that a cybersecurity program has deteriorated (or was never up to par in the first place) are rarely visible and obvious.?

Remember to swap out your jury-rigged, strapped security controls for something that will get the job done properly (cushy inserts optional).


Want to get great cybersecurity content delivered to your inbox??Click here?to sign up for our monthly newsletter, Tales from the Click.

This article originally appeared on the Fractional CISO blog.

Greg Kutzbach, CISSP

Enterprise Risk Management Expert

1 周

Excellent analogy and spot on. I’d like to add, that great controls from 5 years ago may become acceptable controls today. The security stick moves with time as business needs change and attacker methods adapt. Case in point, MFA. It used to be MFA was good enough. Now, phishing resistant MFA is where the bar is set. Subtle difference, but major change. As always, excellent article.

critical first step in the process. Know your exposures before implementing a plan!

Bruno Aburto

Cybersecurity Consultant | Enabling Clients to Focus on Growth by Solving Technology Challenges

2 周

I think separation of duties and access controls are ripe for this.

要查看或添加评论,请登录

Rob Black的更多文章

  • Cybersecurity Needs Your Attention

    Cybersecurity Needs Your Attention

    December. That magical time of year when so many conversations turn to… … the pick and roll, great team defense, smart…

    2 条评论
  • Cybersecurity’s Unanticipated Benefits

    Cybersecurity’s Unanticipated Benefits

    Longtime readers of this newsletter may assume that the only professionals I ever call to my house for assistance are…

    11 条评论
  • Why you need a Quantitative Cybersecurity Risk Assessment

    Why you need a Quantitative Cybersecurity Risk Assessment

    You are presented with two arguments about who is going to win the Super Bowl this weekend. Which sounds more…

    3 条评论
  • Top 5 Rob & Rob Videos of 2024!

    Top 5 Rob & Rob Videos of 2024!

    I am settling into my role as the principal member of the one-man short-video sketch comedy troupe Rob & Rob. This…

    8 条评论
  • Prepare for the Cybersecurity Championships!

    Prepare for the Cybersecurity Championships!

    The NBA season kicked off last night. This year, our beloved Boston Celtics are favored to win it all, again! I…

  • Let’s Get Physical

    Let’s Get Physical

    “Dad, the house alarm went off!” This is not great news at any time of day, but it’s especially unnerving when your…

    3 条评论
  • What’s Your “After Action” Plan?

    What’s Your “After Action” Plan?

    It shouldn’t have been a problem. After all, what could possibly go wrong helping a vacationing neighbor whose plants…

    7 条评论
  • Do You Have a Golden Cybersecurity Questionnaire?

    Do You Have a Golden Cybersecurity Questionnaire?

    It’s that time of year again – my two kids head off this month to overnight camp. They had a great time last summer:…

    12 条评论
  • Don’t Ignore the Warning Signs

    Don’t Ignore the Warning Signs

    Our house is only 18 months old. At this point, few things need repairing, painting, or upgrading.

    6 条评论
  • Hope for the Best; Plan for the Worst

    Hope for the Best; Plan for the Worst

    This past Saturday was a big day for the Black Family – my 13-year-old son had his Bar Mitzvah. He read from the Torah…

    5 条评论

社区洞察

其他会员也浏览了