{"id":3778,"date":"2024-05-28T15:26:16","date_gmt":"2024-05-28T20:26:16","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/making-the-case-for-reasonable-cybersecurity"},"modified":"2024-05-28T15:26:16","modified_gmt":"2024-05-28T20:26:16","slug":"making-the-case-for-reasonable-cybersecurity","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/28\/making-the-case-for-reasonable-cybersecurity\/","title":{"rendered":"Making the Case for &#8216;Reasonable&#8217; Cybersecurity"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8c9a87dc12741d38\/65f997fb6c9f9b040a4d58ca\/CISO_Kjetil_Kolbj%C3%B8rnsrud_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In litigation, specificity is crucial. &#8220;Beyond a reasonable doubt&#8221; is the standard of proof in criminal cases and prosecutors have to convince the jury that the evidence leaves no reasonable doubt about the defendant&#8217;s guilt. In civil cases, the standard is &#8220;preponderance of the evidence,&#8221; meaning the plaintiff must show that a fact is more likely than not true.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For regulators overseeing enterprise cybersecurity practices, the standard of proof is &#8220;reasonable cybersecurity,&#8221; or taking measures to protect data based on what a reasonably prudent person would do in similar circumstances. At the recent RSA Conference, the Center for Internet Security (CIS) released a detailed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisecurity.org\/insights\/white-papers\/reasonable-cybersecurity-guide\" rel=\"noopener\">white paper<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on reasonable cybersecurity and how the concept intersects with privacy laws.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Reasonable cybersecurity is intentionally ambiguous and depends heavily on context. A cyber insurance carrier will often use a a questionnaire asking about whether various security controls are in place, and underwriters might or might not approve a policy. But if a breach occurs later, the insurer might dispute the claim, as happened in 2022 where <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cyber-insurers-clamp-down-on-clients-self-attestation-of-security-controlshttps:\/www.darkreading.com\/cyber-risk\/cyber-insurers-clamp-down-on-clients-self-attestation-of-security-controls\" rel=\"noopener\">Travelers Insurance won a lawsuit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> against International Control Services over misrepresented security controls.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some standards, like the Payment Card Industry Data Security Standard (PCI DSS), are prescriptive, while others, like the European Union&#8217;s General Data Protection Regulation (GDPR), offer more flexibility. The EU law says an organization must make a &#8220;good faith effort to give people the means to control how their data is used and who has access to it. To accomplish this, you must transparently and openly provide them with the information they need to understand how their data is collected and used.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to the Cornell Law School website, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.law.cornell.edu\/wex\/reasonable\" rel=\"noopener\">legal definition<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of &#8220;reasonable&#8221; means, in part, &#8220;Just, rational, appropriate, ordinary, or usual in the circumstances.&#8221; In reality, reasonable can mean almost anything corporate management wants it to mean.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Quantifying Cyber Risk\">Quantifying Cyber Risk<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The board and the executive management define what makes sense from a cyber capability perspective for their organization in their business, says Charlie Lewis, partner at McKinsey. Lewis notes that quantifying cyber risk goes a long way to determining what is and is not reasonable, noting that Federal Reserve Vice Chairman for Supervision Michael Barr underscored the need to improve this nascent technology <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.federalreserve.gov\/newsevents\/speech\/barr20240117a.htm\" rel=\"noopener\">in remarks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to the Conference on Measuring Cyber Risk in the Financial Services Sector back in January.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Better data on cyber threats and vulnerabilities will enable us to identify and assess threats to banks and the financial system,&#8221; Barr said. &#8220;In addition, improved data on interconnectedness between financial institutions and service providers will help identify and measure the impact of an incident on the broader financial system.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When I talk about quantifying cyber risk, I can then set my risk tolerance in a way that lets me understand my control performance, and how well my capabilities are performing,&#8221; Lewis says. &#8220;That helps define <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">reasonable<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Along with the term reasonable, another word that Lewis says boards need to focus on is <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">materiality.<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> He notes the Securities and Exchange Commission&#8217;s recent rules changes help in defining materiality for disclosure purposes, adding that other regulatory requirements also identify specific required security. Knowing these required controls and how they are used in a corporate environment help develop a reasonable cybersecurity defense.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Enabling Security Controls\">Enabling Security Controls<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Curtis Dukes, executive vice president and general manager at CIS, agrees that balancing materiality with reasonableness is essential. In a recent 10K filing with the SEC, a company said its forensics investigation of a breach finds there was no material impact to earnings or operations. But while this statement met the regulatory requirement, it was said before the full impact of the breach could be determined. The initial results of a forensics investigation can be incomplete or simply wrong.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meeting the standard for reasonableness is &#8220;highly subjective,&#8221; says Dukes. &#8220;It&#8217;s typically up to a judge or to a jury to decide [and] assess fault in some type of litigation for that.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In order to eliminate much of the confusion, he says, security frameworks such as the NIST Cybersecurity Framework (CSF), CIS&#8217; own Critical Security Controls (CIS Controls), and other security frameworks provide enterprises with the controls they need to meet the reasonableness legal requirement, along with providing the necessary controls for meeting regulatory requirements. Organizations that implement the frameworks also generally meet cyber insurance requirements.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dukes adds that reasonable cybersecurity is a strong defense against artificial intelligence attacks as well. &#8220;If you have a good data, governance program prior principles in place, and you&#8217;re protecting data, using a set of cybersecurity best practices in the form of controls and underlying safeguard, then you&#8217;re largely mitigating the threat of artificial intelligence.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/making-the-case-for-reasonable-cybersecurity\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In litigation, specificity is crucial. &#8220;Beyond a reasonable doubt&#8221; is<\/p>\n","protected":false},"author":12,"featured_media":3779,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3778","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=1813%2C1107&ssl=1",1813,1107,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=300%2C183&ssl=1",300,183,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=640%2C391&ssl=1",640,391,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=640%2C391&ssl=1",640,391,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=1536%2C938&ssl=1",1536,938,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=1813%2C1107&ssl=1",1813,1107,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=1024%2C625&ssl=1",1024,625,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/making-the-case-for-reasonable-cybersecurity.jpg?fit=1813%2C1107&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3778"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3778\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3779"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}