{"id":5720,"date":"2024-10-10T12:00:00","date_gmt":"2024-10-10T17:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/walking-tightrope-innovation-risk"},"modified":"2024-10-10T12:00:00","modified_gmt":"2024-10-10T17:00:00","slug":"walking-the-tightrope-between-innovation-risk","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/10\/walking-the-tightrope-between-innovation-risk\/","title":{"rendered":"Walking the Tightrope Between Innovation &amp; Risk"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte18fd287f74816b7\/6707f74ebd349ed94a5c3400\/Risk%281800%29_lorenzo_rossi_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/crowdstrike-outage\" rel=\"noopener\">July&#8217;s CrowdStrike incident<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> serves as a stark reminder of the unintended consequences organizations face when innovating to enhance security and streamline operations. Using best-in-class technology is usually a safe bet for chief information security officers (CISOs) when selecting a security vendor, but it&#8217;s equally important to be cognizant of how that technology will be deployed and the amount of risk it can create. I&#8217;ve deployed CrowdStrike as one of my endpoint security tools, and standardizing on this solution allowed for my security operations to be automated, and created muscle memory among my security engineers. This resulted in a faster and more streamlined response to security alerts. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, the CrowdStrike incident served as a sobering lesson about the potential consequences of real-time misconfigured updates on critical business operations. This has opened my eyes to thinking about risk and innovation in a slightly different way. It&#8217;s not just about selecting a vendor with a strong security program, but also about considering the breadth of the implementation of the vendor product, as well as the way the product is updated across an environment. By understanding these different elements, enterprises can make more informed decisions to manage innovation against risk in a controlled manner.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Interestingly, some companies&#8217; reliance on older operational systems shielded them from the direct effects of the CrowdStrike incident. While their outdated technology was once viewed as a liability, it became a surprising advantage in this case. This scenario suggests that the trade-off between innovation and risk may be inevitable. However, both are achievable. So, how can CISOs strategically balance both to ensure secure, forward-thinking operations?&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Bridge the Barrier in the Boardroom&nbsp;\">Bridge the Barrier in the Boardroom&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs often face the misconception of being barriers to innovation within the boardroom. To dispel this, we must reframe the discussion from a &#8220;security versus innovation&#8221; perspective to one of &#8220;secure innovation.&#8221;&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security and innovation are not mutually exclusive, nor should they be. When security is integrated early in the development process, it ensures that innovations are both groundbreaking and secure. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-careers\/ciso-as-a-cto-when-and-why-it-makes-sense\" rel=\"noopener\">CISOs must proactively reach out to other leaders<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> across the organization, from the chief technology officer (CTO) to the chief financial officer (CFO), to ensure security is factored into strategic decisions from the beginning. It&#8217;s about building relationships, where security becomes as natural as brakes on a car \u2014 essential for control but enabling speed and progress.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Foster a Culture of Security\">Foster a Culture of Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One of the most important roles for a CISO is to be viewed as an enabler to innovation instead of a blocker. In reality, the role of a CISO extends far beyond protecting systems; it involves communicating risks at a business level and ensuring that security enables progress rather than stifles it. The key to achieving this lies in fostering a culture of security involving the entire organization, from leadership to employees in the field.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the first line of defense, employees are crucial to establishing a security-first culture. Daily interactions with third-party vendors and potentially malicious content expose them to risks that can compromise the entire organization.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A powerful way to engage employees in this mission is by making security personal. Phishing attacks, data breaches, and threats to personal banking information are tangible examples that resonate with employees. When people understand that their actions can directly affect their own security, as well as the company&#8217;s, they become more motivated to adopt secure practices. With a security-aware employee culture, defense strategies are baked into innovation efforts from the start.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"You're Secure, but Are Your Vendors?\">You&#8217;re Secure, but Are Your Vendors?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The sheer volume of the third-party relationships we manage keeps me on my toes. A single compromised user from any vendor could trigger a company-wide incident. After all, hackers only need one successful attack while security teams must be right every time.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For CISOs, this means that secure innovation doesn&#8217;t stop at internal processes \u2014 it must extend to the vendors that support their IT landscape. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cyber-insurance-strategy-requires-ciso-cfo-collaboration\" rel=\"noopener\">Collaborating with technology peers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to better understand and mitigate risks is key to fostering innovation without increasing the cyber-risk. Equally important is building strong, proactive partnerships with third-party vendors to verify they are prepared to respond at scale when disruptions occur.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To optimize this process, CISOs should focus on understanding which vendors are critical to the corporate infrastructure, particularly those involved in environments that require frequent updates. By ensuring these vendors follow rigorous testing protocols before rolling out changes, companies can better manage the trade-offs between innovation and operational stability.&nbsp;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Security-First Innovation\">Security-First Innovation<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISOs must lead the charge in integrating security-first practices into the heart of innovation, positioning themselves as trusted advisers who enhance the company&#8217;s overall objectives. By coming to the table with solutions rather than simply highlighting risks, we can shift the dialogue from &#8220;security will never approve&#8221; to &#8220;security can help make this better.&#8221; &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This cultural shift fosters collaboration with executives and third-party vendors, embedding security into every phase of the organization&#8217;s growth. When employees and leaders engage with CISOs early in innovation projects, security concerns are addressed proactively, building trust and ensuring that innovation and security coexist.&nbsp;&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/walking-tightrope-innovation-risk\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY July&#8217;s CrowdStrike incident serves as a stark reminder of<\/p>\n","protected":false},"author":12,"featured_media":5721,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5720","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/walking-the-tightrope-between-innovation-risk.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5720"}],"version-history":[{"count":1,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5720\/revisions"}],"predecessor-version":[{"id":5722,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5720\/revisions\/5722"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5721"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5720"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}