{"id":411911,"date":"2020-06-30T08:30:45","date_gmt":"2020-06-30T06:30:45","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=411911"},"modified":"2020-06-30T07:44:51","modified_gmt":"2020-06-30T05:44:51","slug":"8-questions-you-need-to-answer-to-become-cyber-resilient","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/industry-news\/411911\/8-questions-you-need-to-answer-to-become-cyber-resilient\/","title":{"rendered":"8 questions you need to answer to become cyber resilient"},"content":{"rendered":"<p>Over the past few years, a pattern has emerged in the type of events that organisations were consistently more worried about or interested in terms of networked-based detection and response technologies.<\/p>\n<p>\u201cInterestingly, it wasn\u2019t opening suspicious email attachments or web browser drive-bys that they were most concerned about. There are strong technological controls and processes in place to deal with the vast majority of threats in those vectors. Nearly all organisations have reached a risk-appropriate cyber maturity level from these well-known patterns of attack and feel comparatively resilient, as they have invested in multiple security technologies spanning the entire MITRE ATT&amp;CK chain. They can even confidently identify late stage techniques and tools that are \u2018living off the land\u2019,\u201d said Andre Kannemeyer, CTO at Duxbury Networking, distributors of the Armis agentless devices security platform.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/store.duxbury.co.za\/?utm_source=MyBroadband&amp;utm_medium=Article&amp;utm_campaign=30_June_2020\" target=\"_blank\" rel=\"noopener noreferrer\">Click here for more information from Duxbury Networking<\/a><\/strong><\/li>\n<\/ul>\n<p>\u201cInstead, the events that organisations were most interested in were almost always directly related to uncovering the \u2018land\u2019. These were the events that they feel less resilient to, as they represent a blind spot in the application of risk management. If you have a robust understanding of what the land looks like, you can mature a cyber capability to deal with threats that would attempt live off it. In simple risk terms, if you don\u2019t know the land, you can\u2019t manage what\u2019s in it,\u201d added Kannemeyer.<\/p>\n<p>In January 2020, the World Economic Forum released guidance designed to help organisations in the aviation sector advance their cyber resilience endeavours.<\/p>\n<p>The guidance actually transcends aviation and is appropriate to any industry sector and every type of organisation.<\/p>\n<h3 class=\"my-4\"><strong>8 questions to help you become cyber resilient<\/strong><\/h3>\n<p>The World Economic Forum\u2019s initiative poses eight questions that organisations should ask themselves to assess and advance their levels of cyber resilience:<\/p>\n<ol>\n<li>Does your organisation\u2019s approach to information, cyber, and IT risk management take full consideration of the risks posed by emerging technologies such as IIoT?<\/li>\n<li>Does your organisation understand the impact of emerging technologies on its attack surface \u2013 both outside and within the organisational and network perimeter?<\/li>\n<li>Does your organisation\u2019s cyber resilience strategy, risk scenarios and incident planning exercises take full account of system and data integrity risks, as well as confidentiality and availability?<\/li>\n<li>With ongoing changes in connectivity, technology, and business practices, how do your organisation\u2019s cyber and safety risks interconnect?<\/li>\n<li>Does your organisation have a clear understanding of the risk posed by its supply chain and partners across its ecosystem, including manufacturers, support partners, and infrastructure operators?<\/li>\n<li>How can your organisation develop and maintain effective baselines of cyber capability?<\/li>\n<li>How can your organisation continuously monitor cyber risks?<\/li>\n<li>How can your organisation build an industry database that enables minimum standards to be set, and industry-wide leveraging of best practice?<\/li>\n<\/ol>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Figure-1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-357985 size-large\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Figure-1-640x430.jpg\" alt=\"\" width=\"640\" height=\"430\" \/><\/a><\/p>\n<p>These eight questions progress an organisation\u2019s cyber resilience by challenging the three pillars upon which cyber resilience is built.<\/p>\n<p>The first two questions relate to visibility; how much of your organisation\u2019s critical infrastructure is visible. Can you fully see the extent of risk upon your attack surface?<\/p>\n<p>The second pillar of resilience is maturity and is tested in the next three questions (3-5). Do you truly have a 360\u00b0 view of risk and how it might manifest, from all of your digital surfaces, including third parties?<\/p>\n<p>The third pillar of resilience is capability. How rich is your ability to measure, detect, respond and learn, questions of capability are challenged in questions (6-8)?<\/p>\n<p>The World Economic Forum\u2019s cyber resilience initiative lays down guidance for best practice baselining and measurement of cyber resilience as a continuous and always-improving process via all three of the pillars.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Figure-2.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-357987 aligncenter\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Figure-2-640x430.jpg\" alt=\"\" width=\"640\" height=\"430\" \/><\/a><\/p>\n<p>It is initiatives like <em>Advancing Cyber Resilience<\/em> from the World Economic Forum that will promote a common risk criteria and encourage a robust understanding of what is valuable to resilience in cyber operation centres across every industry sector throughout 2020 and beyond.<\/p>\n<p>For more information contact Duxbury Networking, +27 (0) 11 351 9800, <strong><a href=\"mailto:info@duxnet.co.za\" target=\"_blank\" rel=\"noopener noreferrer\">info@duxnet.co.za<\/a><\/strong>, <strong><a href=\"https:\/\/store.duxbury.co.za\/?utm_source=MyBroadband&amp;utm_medium=Article&amp;utm_campaign=30_June_2020\" target=\"_blank\" rel=\"noopener noreferrer\">store.duxbury.co.za<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over the past few years a pattern has emerged in the type of events that organisations were consistently more worried about or interested in terms of networked-based detection and response technologies.<\/p>\n","protected":false},"author":57,"featured_media":223626,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10459],"tags":[14323],"class_list":["post-411911","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","tag-duxbury-networking"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/411911","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/57"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=411911"}],"version-history":[{"count":1,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/411911\/revisions"}],"predecessor-version":[{"id":411915,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/411911\/revisions\/411915"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/223626"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=411911"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=411911"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=411911"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}