{"id":35651,"date":"2019-11-22T10:26:56","date_gmt":"2019-11-22T10:26:56","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=35651"},"modified":"2019-11-25T08:52:41","modified_gmt":"2019-11-25T08:52:41","slug":"edp-utilises-security-ratings-for-security-performance-management","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/11\/22\/edp-utilises-security-ratings-for-security-performance-management\/","title":{"rendered":"EDP utilises BitSight platform for Security Performance Management"},"content":{"rendered":"\n<p><em>Information security is vital for operating in a secure environment, and as one of the largest energy companies in the world,<\/em> <em>Energias de Portugal (EDP) recognises this. It used a BitSight solution to improve its security performance and build confidence among its stakeholders.<\/em> <em>Paulo Moniz, CISO, EDP<\/em>, <em>explains how the solution has future-proofed operations. <\/em><\/p>\n\n\n\n<p>EDP is a\nglobal company, operating in 16 countries across four continents, specialising\nin energy generation, transport and distribution of electricity and gas. EDP has\n12,000 employees across Europe, United States, Canada, South America and Asia\nand serves 11 million clients. <\/p>\n\n\n\n<p>EDP recognises that information security is a vital part of its strategic objectives and is one of its key business requirements, representing a core commitment at the top management level. As a result, EDP\u2019s information security policy is approved at Board of Director-level. The policy establishes information security as a competitive differentiator, which generates confidence among EDP\u2019s stakeholders. Also, EDP recognises that it has a heavy responsibility in the societal context, as an operator of critical national infrastructure and manager of large volumes of personal data for clients and employees.<\/p>\n\n\n\n<p>As part of the EDP group\u2019s strategic information security vision, it established a three-year security master plan (2018 \u2013 2021) based on its end-to-end security principle consisting of these objectives:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Focus on people:<\/strong> Recognising people as a central element of security, not only as the organisation\u2019s first line of defence but also to create the capabilities to architect and implement the security solution to protect the organisation systems and to build a critical incident response and recover capacity<\/li><li><strong>Compliance:<\/strong> Following external laws and regulations imposed on the relevant sectors and generating trust<\/li><li><strong>Intelligence:<\/strong> Making security less intrusive, more efficient and empowering business, especially in Digital Transformation<\/li><li><strong>Resilience:<\/strong> Cyberattacks are ever more common, so the resulting security incidents must be handled by the organisation to assure business continuously deliver despite adverse cyber events<\/li><\/ul>\n\n\n\n<p><strong>Utilising\nBitSight Security Ratings<\/strong><\/p>\n\n\n\n<p>EDP was introduced to BitSight through its threat intelligence company. The BitSight Security Ratings platform provided the necessary external view of its networks that EDP required. Issuing daily ratings that are akin to a credit score for security, BitSight Security Performance Management helped EDP take a risk-based and outcome-driven approach to managing its performance. This included broad measurement tools, continuous monitoring and forecasting. EDP as an organisation values sustainability as one of its biggest corporate objectives, and ensuring cyber-resilience to protect customers and employees is a big part of this. The Security Performance Management tool enabled them to achieve this and reduce its cyber-risk.<\/p>\n\n\n\n<p>EDP\u2019s adoption of a metric based on the BitSight Security\nRating helped define the group\u2019s KPI around its overall security performance. The\nspecific metrics included checking aspects such as security of its own website,\naccess to its networks from dangerous locations or communications coming from\nmachines infected by criminal networks. The EDP group has achieved the proposed\nrating objectives for 2018 and 2019.<\/p>\n\n\n\n<p><strong>Fast and efficient information security<\/strong><\/p>\n\n\n\n<p>EDP\u2019s dedicated global cybersecurity incident response team\n(CSIRT) works 24 hours a day and participates in national and international\ncybersecurity exercises. The company tests its reaction to occurrences of\ndisruptive events, driving awareness and training among employees. This is\nwhere EDP saw value through its Security Performance Management tools as not\nonly a reporting tool around its own security posture, but also to credibly\ncommunicate to stakeholders and the market. This added value to the\norganisation\u2019s objectives around sustainability.<\/p>\n\n\n\n<p><em>Internal Assessment <\/em><\/p>\n\n\n\n<p>The<em> <\/em>CSIRT team utilises BitSight for Security Performance Management to monitor and receive real time infection alerts to help work on fast remediation within its own network. CSIRT also works closely with the BitSight team to ensure all relevant information, such as details of all risk vectors, are shared and continuous behaviours are monitored.<\/p>\n\n\n\n<p><em>Benchmarking<\/em><\/p>\n\n\n\n<p>BitSight\u2019s consistent and transparent rating system on all companies is an important feature that allows EDP to compare its performance to industry peers and identify wider security issues. The platform provides intelligence on compromised systems, security diligence and user behaviour risks that affect EDP and its industry peers. This provides EDP with the ability to see which infections are targeting peer companies for insight into industry-specific threats, as well as understand security diligence standards across its industry.<\/p>\n\n\n\n<p>Another value to EDP is communicating key indicators to the\nboard and demonstrate improvement over time as a result of the remediation\nactivities guided by its security rating performance.<\/p>\n\n\n\n<p><em>Executive Reporting<\/em><\/p>\n\n\n\n<p>EDP\u2019s <em>Sustainability Report<\/em> provides the main trends in each of its sectors, the strategy adopted and the results achieved in relation to its sustainability goals. The report is a key channel through which the board shares its vision and values in innovation, sustainability and humanisation. The adoption of BitSight Security Ratings, defined as the group\u2019s KPI, highlights the external value to its third-party stakeholders and its importance to the company\u2019s internal mission statement. <\/p>\n\n\n\n<p><strong>Plans for the future<\/strong><\/p>\n\n\n\n<p>While the current focus for the organisation is on Security Performance Management, the next step will be the evolution towards third-party risk management, specifically vendor risk. This would include expanding EDP\u2019s current use of BitSight to apply ratings to specific vendors alongside its own monitoring solutions. This will help avoid \u2018blind spots\u2019 across its vendors and provide much needed visibility of security performance across its entire vendor lifecycle. Also, working with its vendors and BitSight to quickly and collectively reduce cyber-risk by sharing BitSight Security Ratings data will enable EDP to have intelligent, data-driven conversations with key stakeholders including vendors, board members and investors about its security risks.<\/p>\n\n\n\n<p><em>Intelligent CIO<\/em> <em>caught up with Paulo Moniz, Chief Information Security Officer, EDP, to find out more about the solution. <\/em><\/p>\n\n\n\n<p><strong>As an operator of\ncritical national infrastructure, how important is having a reliable security\nsolution?<\/strong><\/p>\n\n\n\n<p>EDP has established information security as a competitive factor, not only because we recognise that it generates confidence from stakeholders, but also because we have a critical responsibility in the social context. As a result, we have identified two major crown jewels: one resulting from managing large volumes of personal data of clients and employees; and the other because we operate critical infrastructures.<\/p>\n\n\n\n<p>In order to implement our\nstrategic vision for information security, we established end-to-end security\nas a guiding principle, which implies a holistic approach permeating the\norganisation. This avoids the need for a siloed approach, incorporating\nsecurity from the development of services and applications, to activities\ncarried out by service providers, within a logic of Security by Design.<\/p>\n\n\n\n<p>A reliable security solution\nsuch as the BitSight rating has the strong merit of uniting the entire\norganisation around a common objective, which is recognised by external\nentities. This is also a strong internal tool to mitigate cybersecurity risk,\nhelping to break the silos that have a negative impact on the organisation.<\/p>\n\n\n\n<p><strong>How does the solution\nimprove operability for the end-user?<\/strong><\/p>\n\n\n\n<p>The solution has a direct impact for cybersecurity teams &#8211; it provides us with objective security metrics that enable our security and operational teams to focus on clearly defined objectives. In turn, this enables us to decrease the global cybersecurity risk of the organisation. <\/p>\n\n\n\n<p>Being a common goal communicated to all within the company, BitSight\u2019s Security Ratings also establishes guidelines for those who aren&#8217;t within security teams, on what they are permitted to do with company IT resources, decreasing resistance and improving the overall security of IT resource usage.<\/p>\n\n\n\n<p><strong>How scalable is the\nsolution?<\/strong><\/p>\n\n\n\n<p>Taking advantage of the\nflexibility of BitSight\u2019s platform enables us to create our own customised\nasset groups and sub companies. This enables the company to grow its security\noperations horizontally, while bearing in mind the different operational\ncontexts, especially with regard to the clear boundaries between IT and OT\nenvironments. <\/p>\n\n\n\n<p>There are two major examples where we can escalate the solution easily with enormous value. The first is when EDP is evaluating the risk from a mergers and acquisition perspective. The second is when we want to create a vendor risk management program, since the supply chain is a critical aspect for EDP\u2019s overall cybersecurity posture. In both cases, the solution can be easily scaled to incorporate other companies in the digital footprint risk evaluation.<\/p>\n\n\n\n<p><strong>How far has it\nfuture-proofed operations?<\/strong><\/p>\n\n\n\n<p>Cybersecurity is a constantly-changing area with new threats emerging almost every day. No one with cybersecurity responsibilities can say with a completely clear conscience, that their company\u2019s operations, or the tools that support them, are completely future-proofed. <\/p>\n\n\n\n<p>However, we can say that by always keeping up to date with information security best practices and continuously improving detection and response mechanisms, BitSight has allowed EDP to keep tabs with newly-discovered vulnerabilities. This ensures that our security controls are keeping pace with ever-evolving threats. <\/p>\n\n\n\n<p>Aligning with the proposed recommendations by BitSight enables our security team to preview pain points and shifts when dealing with large-scale IT risk, maintaining a bird\u2019s-eye view without being lost in technical details that could potentially lead to us being blindsided by technological improvements. Nonetheless, it&#8217;s important to track these when designing and implementing long-term IT solutions for the company.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Information security is vital for operating in a secure environment, and as one of the largest energy companies in the world, Energias de Portugal (EDP) recognises this. It used a BitSight solution to improve its security performance and build confidence among its stakeholders. Paulo Moniz, CISO, EDP, explains how the solution has future-proofed operations. EDP [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":35658,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[205,51,33,57,18,93,24],"tags":[10996,13947,942,4216,13948],"class_list":["post-35651","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","category-case-study-newsletter","category-energy","category-enterprise-security","category-portugal","category-top-stories","category-used","tag-bitsight","tag-bitsight-security-ratings","tag-edp","tag-information-security","tag-security-performance-management"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=35651"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35651\/revisions"}],"predecessor-version":[{"id":35664,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/35651\/revisions\/35664"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/35658"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=35651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=35651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=35651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}