{"id":4115,"date":"2024-06-19T12:37:40","date_gmt":"2024-06-19T17:37:40","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-cybersecurity-can-steer-organizations-toward-sustainability"},"modified":"2024-06-19T12:37:40","modified_gmt":"2024-06-19T17:37:40","slug":"how-cybersecurity-can-steer-organizations-toward-sustainability","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/19\/how-cybersecurity-can-steer-organizations-toward-sustainability\/","title":{"rendered":"How Cybersecurity Can Steer Organizations Toward Sustainability"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte9c1ab2dc584bf7b\/666cd67ebcc34ac01e83203f\/workers-Aleksandr_Davydov-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Inadequate cybersecurity architecture can cause irreparable damage to an organization, which is why boards and C-suite executives are heeding recommendations to implement policies and procedures to mitigate risk. In addition, boardrooms are also paying attention to other hot topics, including diversity, equity, and inclusion (DEI) and sustainability. So it&#8217;s worth asking what cybersecurity personnel can do to support these initiatives.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security leaders are in a unique position to not only protect the organization, but also to help direct it toward a more sustainable future. There are several ways they can support the three pillars of ESG: environmental initiatives, social responsibility, and corporate governance.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cybersecurity &amp; Environmental Initiatives\">Cybersecurity &amp; Environmental Initiatives<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">By &#8220;environmental initiatives,&#8221; we&#8217;re talking about <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cybersecurity-talk-about-climate-change\" rel=\"noopener\">how organizations affect the environment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, such as carbon emissions, resource consumption, and waste output. Security personnel can make a palpable, positive impact on their organization&#8217;s environmental initiatives with a few key implementations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Endpoint management solutions. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the beginning of the hardware and software life cycle, cybersecurity personnel should make judicious purchases. Endpoint management software, for example, can be helpful, as such tools save energy by automatically installing patches and putting endpoints into sleep mode when devices are idle or threatened. [Editor&#8217;s note: The author&#8217;s company is one of many that sell endpoint management software.]<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">E-waste management. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity teams already monitor corporate devices to maintain compliance and robust network security; they should collaborate with IT personnel to prolong these devices&#8217; lifespans via patching and software updates. By reusing and refurbishing hardware, security personnel and IT folks can work together to lower operational costs and reduce their company&#8217;s environmental footprint.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Supply chain audits.<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> To reduce greenhouse gas emissions effectively, it is also necessary to conduct supply chain audits. Security personnel should periodically orchestrate environmental audits of all the vendors within their supply chain. This entails an assessment of vendors&#8217; energy consumption and waste management, among other things.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Energy-efficient data storage and processing. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security personnel should make data center cybersecurity a priority. Data centers use a ton of energy and often contain sensitive information. A <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cybercriminals-freely-share-millions-of-stolen-records-over-holiday-break\" rel=\"noopener\">successful cyberattack on a data center<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> would likely result in fines, loss of trust, and a rise in energy consumption to get operations back on track.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cybersecurity &amp; Social Responsibility\">Cybersecurity &amp; Social Responsibility<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This pillar is concerned with the relationships that one&#8217;s company has with various people and communities. In addition to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/making-diversity-the-how-and-not-the-what-of-cybersecurity-success\" rel=\"noopener\">diversity and inclusion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, we believe that companies should consider digital inclusion and the ability to contribute to economies in underdeveloped regions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Eco-friendly product procurement. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While procuring software and hardware, cybersecurity professionals are usually focused on robust security, compliance, and cost. However, they should also be cognizant of their potential vendors&#8217; sustainability practices. In addition to making sure that downstream vendors don&#8217;t introduce any cyber-risks, security teams should assess the overall environmental and social impacts of their third-party products.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s important to assess the average lifespan of third-party vendors&#8217; products, as well as any applicable energy efficiency ratings or environmental certifications. By choosing energy-efficient vendors that are committed to sustainable manufacturing practices, cyber personnel can bolster their own corporate reputation and attract environmentally conscious customers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For organizations that sell cybersecurity tools, it&#8217;s wise to consider <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/meet-the-new-public-interest-cybersecurity-technologist-\" rel=\"noopener\">digital inclusion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. A component of social responsibility, digital inclusion is the idea that people of all socioeconomic backgrounds should have access to technologies. By keeping cybersecurity software prices affordable, security companies can provide more tools to more people.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Effective data management. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity personnel are responsible for ensuring the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/researchers-map-ai-threat-landscape-risks\" rel=\"noopener\">confidentiality, integrity, and availability<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of their organization&#8217;s data. Without adequate cybersecurity tools, such as endpoint management solutions, identity and access management tools, and security information and event management software, organizations cannot protect their customers&#8217; data, which, of course, they have a social responsibility to do.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cybersecurity &amp; Governance\">Cybersecurity &amp; Governance<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Governance refers to an organization&#8217;s internal procedures, its ability to comply with laws, and how well the company is managed. When it comes to governance, cybersecurity professionals&#8217; knowledge and guidance is indispensable.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Materiality assessments and regulatory compliance. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Given that cybersecurity professionals are well-versed in dealing with compliance requirements, the executive branch should consult with them in their efforts to comply with regulations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides helping establish cybersecurity compliance and data-handling protocols, security professionals can also ensure that the organization is in compliance with environmental legislation across the globe. To do so, they should help with their organization&#8217;s ESG materiality assessments.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to assessing sustainability from a financial angle, ESG assessments list how operations affect society and the environment. Organizations need to have cyber personnel on their steering committees to bring a risk management lens to the conversation. By sitting on these committees, cybersecurity team members remind upper management just how invaluable they are to the organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Adherence to data privacy laws. <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Again, organizations have a social \u2014 and legal \u2014 responsibility to adhere to all <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/biden-administration-unveils-data-privacy-executive-order\" rel=\"noopener\">data privacy laws<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. By doing so, cybersecurity personnel help the organization properly manage customer data, while also mitigating threats from bad actors.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cybersecurity Is ESG\">Cybersecurity Is ESG<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the examples above show, corporate sustainability initiatives cannot be successful without the active participation of cybersecurity personnel. Whether we are talking about environmental initiatives, social responsibility issues, or governance, cybersecurity professionals need to take their seats at the table.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/how-cybersecurity-can-steer-organizations-toward-sustainability\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Inadequate cybersecurity architecture can cause irreparable damage to an<\/p>\n","protected":false},"author":12,"featured_media":4116,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4115","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/how-cybersecurity-can-steer-organizations-toward-sustainability.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4115"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4116"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}