{"id":4522,"date":"2021-03-11T09:24:51","date_gmt":"2021-03-11T09:24:51","guid":{"rendered":"https:\/\/www.intelligentcio.com\/apac\/?p=4522"},"modified":"2021-03-11T09:24:52","modified_gmt":"2021-03-11T09:24:52","slug":"culture-is-key-how-cios-can-build-cyber-resilience","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/apac\/2021\/03\/11\/culture-is-key-how-cios-can-build-cyber-resilience\/","title":{"rendered":"Culture is key: How CIOs can build cyber-resilience"},"content":{"rendered":"\n<p><strong><em>Nick Emanuel, Senior Director of Product, Webroot and Carbonite, stresses the importance of training to build up an organization\u2019s cyber-resilience.<\/em><\/strong><\/p>\n\n\n\n<p>Given the widespread technology transformations, shifts and disruptions over the past year, businesses of all sizes have been faced with re-evaluating their ability to face \u2018unprecedented\u2019 threats, or simply manage new hazards in preventing a ransomware attack.<\/p>\n\n\n\n<p>While some CIOs sought new technologies to eliminate risk and protect the business, others recognized the illuminating opportunity the pandemic presented to take the time and investment to evaluate and strengthen each layer of security.<\/p>\n\n\n\n<p>When reviewing the latter\u2019s changes, one element was visible time and time again: the company\u2019s end-users. Where we\u2019ve found company security culture, with IT leaders at the forefront of it, playing a big role in increasing an organization\u2019s overall cyberawareness, we saw far fewer attacks reaching the endpoint. We saw this for what it is: a real-world example of \u2018cyber-resilience\u2019 in effect.<\/p>\n\n\n\n<p><strong>What is <\/strong><strong>cyber-resilience<\/strong><strong><\/strong><\/p>\n\n\n\n<p>Being cyber-resilient means being able to withstand and quickly recover from cyberattacks and accidental data loss. Because data loss or malicious attacks can easily derail a business, layered security approaches and a commitment to both data security and protection have emerged essential for today\u2019s CIOs and CISOs.<\/p>\n\n\n\n<p>Businesses know the limitations of traditional security defenses and that cyber-resilience can\u2019t be achieved through technology and process alone but can find it hard to champion or build a viable business program or process around it. True resilience calls upon entire organizations to be educated and aware of the threats at hand and to actively participate to minimize the risks posed.<\/p>\n\n\n\n<p><strong>Taking ownership of <\/strong><strong>cyber-resilience<\/strong><strong> across the whole organization<\/strong><\/p>\n\n\n\n<p>For employees of all backgrounds, it\u2019s reassuring to know of on-going investment in new technologies and detection methods to help meet a variety of cybersecurity challenges, from blocking threats by mal-actors or nation states to hiring enough security staff to safeguard employees and businesses online.<\/p>\n\n\n\n<p>However, it has never been more crucial that every employee takes ownership of their online behaviors. This is because the most common threat, phishing attacks, are at record highs given the disruption and opportunity that the on-going pandemic presents, and the employee is often the direct target.<\/p>\n\n\n\n<p>In fact, research conducted during the pandemic detailing online behaviors and clicks habits found that in Australia and New Zealand, one in five people reported receiving phishing emails specifically related to COVID-19. 76% of respondents also admitted to opening emails from unknown senders, with over half (59%) blaming it on the fact that phishing emails look more realistic than ever.<\/p>\n\n\n\n<p>It takes time to reach a healthy level of cyberawareness but getting started has been made much simpler by awareness training toolsets or programs. The effects are cumulative and can be measured from day one.<\/p>\n\n\n\n<p>Fostering suspicion into day-to-day online business routines, as well as simple steps such as using unique and strong passwords for all logins, disabling macros from a document and removing admin access from devices can keep end-users safe from a range of common threats. Efforts in building the right employee awareness and behavior should be spearheaded by the CIO and CISO and senior leadership needs to buy in to encourage lasting change. Employees should receive routine updates on cyber-resilience initiatives and progress to communicate priority and importance to the greater organization.<\/p>\n\n\n\n<p><strong>Education and awareness are everything<\/strong><\/p>\n\n\n\n<p>Simply put, if employees are not educated about cyberthreats, they can\u2019t be expected to completely defend against them. Which is why many businesses are now turning to training and education services specifically geared toward helping employees improve their cybersecurity postures.<\/p>\n\n\n\n<p>Cybersecurity awareness training varies in length and curriculum, but elements can include phishing simulations, courses on security best practices and data protection and compliance training for important regulations like the Privacy Act 1988 (Cth), Privacy Act 2020, GDPR, HIPAA, CCPA, etc.<\/p>\n\n\n\n<p>Training is of course important at onboarding, but regular on-going simulations, engaging content and gamification will create and sustain true culture. To reinforce a cyber-resilient culture, IT leaders should report on successes (like number of attacks blocked) and communicate the latest risks\/threats and tips to staff about cybersecurity trends and best practices through internal newsletters, emails and remote check-ins.<\/p>\n\n\n\n<p>Business leaders should incorporate reminders and updates about cybersecurity into team meetings and other important company updates to underscore the importance and purpose of investing in cyber-resilience.<\/p>\n\n\n\n<p>By leading the implementation of appropriate practices and considerations into company culture, CIOs, CISOs and their peers have the power to reduce the risks posed by cyber-criminals by significant margins.<\/p>\n\n\n\n<p>By ensuring staff understand they play a critical role in ensuring security, companies are empowered to protect data and operations and ultimately uphold the trust place in them by customers, employees and stakeholders.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nick Emanuel, Senior Director of Product, Webroot and Carbonite, stresses the importance of training to build up an organization\u2019s cyber-resilience. Given the widespread technology transformations, shifts and disruptions over the past year, businesses of all sizes have been faced with re-evaluating their ability to face \u2018unprecedented\u2019 threats, or simply manage new hazards in preventing a [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":4524,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4,18,1576,55,43,44],"tags":[1708,191,174,343,1707],"class_list":["post-4522","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-enterprise-security","category-analysis-insights","category-oceania","category-thought-leadership","category-top-stories","tag-carbonite","tag-cios","tag-cybersecurity","tag-ransomware","tag-webroot"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/4522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/comments?post=4522"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/4522\/revisions"}],"predecessor-version":[{"id":4527,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/posts\/4522\/revisions\/4527"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media\/4524"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/media?parent=4522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/categories?post=4522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/apac\/wp-json\/wp\/v2\/tags?post=4522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}