{"id":2579,"date":"2024-02-22T15:00:00","date_gmt":"2024-02-22T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/4-key-steps-to-reevaluate-your-cybersecurity-priorities"},"modified":"2024-02-22T15:00:00","modified_gmt":"2024-02-22T15:00:00","slug":"4-key-steps-to-reevaluate-your-cybersecurity-priorities","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/22\/4-key-steps-to-reevaluate-your-cybersecurity-priorities\/","title":{"rendered":"4 Key Steps to Reevaluate Your Cybersecurity Priorities"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte2fb6408066b8f36\/65d684d9a79b9d040aff69b5\/Priorites_seanbear_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyber extortion bolted to its highest level in early 2023 after a slight decline in 2022, according to&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/newsroom.orange.com\/cyberextortion\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">Orange Cyberdefense<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and didn&#8217;t slow down the rest of last year. This year will likely see more of the same.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyberattacks on business and industry are increasing in frequency, scale, and cost, especially against high-value targets, such as banks, hospitals, utilities, and universities, which hold the sensitive information most coveted in the dark marketplace.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Technology and cybercriminals&#8217; sophistication are evolving together quickly, yet many companies and organizations are not. Financially motivated cybercriminals are capitalizing on many victims&#8217; willingness to pay in hopes of quickly restoring network systems and reclaiming sensitive information.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In this environment, customers, investors, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/how-secs-rules-cybersecurity-incident-disclosure-are-exploited\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">regulators<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and the public will judge brands for more than the security of their networks. They also expect brands to respond to an incident transparently, comprehensively, and promptly.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While brands should continue devoting resources toward the latest defensive technologies, they face growing reputational risk if leadership fails to prioritize strategic incident preparation and response.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For many corporate leaders, it&#8217;s not a question of having the willingness to start but rather knowing where to begin. Here are four key steps brands should embrace to strengthen their cybersecurity strategy.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Elevate Cybersecurity to the C-suite and Board\">Elevate Cybersecurity to the C-suite and Board<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Far too many <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/apcoworldwide.com\/blog\/corporate-boards-should-drive-cybersecurity-strategy\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">corporate boards<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> relegate cybersecurity responsibilities to the chief information security officer (CISO) and IT department. Without leadership&#8217;s involvement, consequences range from incomplete layers of defense to incident responses that are more costly \u2014 both financially and reputationally.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Boards are wise to shift their views of cybersecurity and incident response, creating a culture where they are strategic priorities. Instead of just another IT expense, they&#8217;re viewed as essential investments to preserve your most valuable assets and protect your credibility with stakeholders.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Start by requiring <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-to-talk-about-infosec-to-your-board-of-directors\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">regular briefings<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for all directors detailing network security improvements, adherence to best practices, and the latest industry trends. Use this opportunity to discuss hard questions, such as how cyber threats are detected or what it would cost your company if it were fully offline for a week.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Boards should also have a cyber committee equivalent to their corporate governance, audit, or compensation committees. The cyber committee is charged with assessing your company&#8217;s risk profile, setting robust cybersecurity policy, and determining what resources, including staffing, are needed to reduce vulnerability.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Audit Sensitive Information&nbsp;\">Audit Sensitive Information&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Surprisingly, many organizations do not have a full line of sight on the sensitive information they have or where it&#8217;s held, much less how it could be compromised or exploited by cyber-threat actors.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Job one for the board&#8217;s new cyber committee is setting a consistent cadence of rigorous audits and assessments. For the same reason you check that all your doors are locked before turning in for the night, regular cyber audits help keep you safe. Knowing vulnerabilities, gaps, or weaknesses shows you how and where to add another layer of security.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Update (or Create) Your Incident Response Plan&nbsp;\">Update (or Create) Your Incident Response Plan&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An incident response plan is like insurance. You hope you never have to use it but, when you do, you&#8217;re thankful to have it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An incident response plan is a playbook or toolkit to guide you through the short- and long-term aftermath of an attack. It allows you to act swiftly and strategically, protecting your bottom line and reputation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While it&#8217;s best to customize your plan to your organization, all incident response plans have common elements: Decision-making protocols clearly define roles and responsibilities. Scenario planning articulates steps to take for various types of attacks. Stakeholder and media mapping identify key internal and external audiences, and holding statements enable communication with each one when deemed appropriate. Your plan should also identify potential third-party legal, forensics, and communication partners, spelling out each one&#8217;s expertise.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Revisit Cyber Hygiene Training&nbsp;\">Revisit Cyber Hygiene Training&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While data is difficult to track, some reports indicate insider threats account for as much as 60% of cyber incidents. Insider threats may emanate from a disgruntled employee with harmful intent, but it&#8217;s often the result of human error.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, many employees are in the habit of using free Wi-Fi at coffee shops, restaurants, and other public spaces while on a company laptop, tablet, or phone. Because it&#8217;s unsecured, public Wi-Fi is fertile ground for attackers. Hackers can lift passwords and other sensitive information or install malicious software on an unsuspecting employee&#8217;s device, which eventually makes its way to the main network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Leadership should revisit their company&#8217;s cyber-hygiene training programs frequently, ensuring they are up to date and address identified weaknesses.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Protect Your Brand Reputation and Assets\">Protect Your Brand Reputation and Assets<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If not handled well, cyber and ransomware attacks cost more than the potential loss of data or money. Embracing these steps can help avoid the loss of trust, credibility, and reputation, additional costs that can take months or years to recover.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/4-key-steps-to-reevaluate-your-cybersecurity-priorities\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Cyber extortion bolted to its highest level in early<\/p>\n","protected":false},"author":12,"featured_media":2580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=1800%2C1200&ssl=1",1800,1200,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=1800%2C1200&ssl=1",1800,1200,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/4-key-steps-to-reevaluate-your-cybersecurity-priorities.jpg?fit=1800%2C1200&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2579"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2580"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}