A strong security program requires consistent policies, frameworks, and risk management practices to protect an organization from threats that individual employees often underestimate or overlook. This content covers how to build that program, select a security framework, and apply structured strategies to assess and respond to risk.
Security Program & Risk Management
Your networks are prone to a lot of risk, so how do we manage that?
My guess is that if you were to go and ask the employees of a business how likely they are to get hacked — how likely it is that their email is going to get hacked, how likely it is that their password will be compromised, how likely it is that they will fall for a phishing technique, how likely it is that somebody will leverage that employee to get into the business and hack the business — almost 100% of people are going to say, "No, that's not going to happen to me. That's unlikely to happen to me. My password is secure enough and I'm not going to fall for any phishing." Yet it happens all the time. The thing is that we have different experiences and we have different positions.
From a security program standpoint, I've got some people listed out here as part of a business. We've got HU, who has been in sales for 5 years selling products, and he's never got hacked before. Perhaps what he feels is that because he hasn't been hacked, he's in a comfortable position and he's thinking of everything correctly, when in fact his password might be terrible. He just might have got lucky and not have been hacked yet. Then you have Rick over here, who has some knowledge of security. He's a programmer, so he's security-minded, but he has this silo and he just does security for this position.
My point is that your security is only good to the point that these people are educated to, and they don't know any better. If you don't have a security program, you can never have consistency among these people to know what standard they need to be at. Another example that I have in here is a system, a process, that's 15 years old and very outdated, and it outdates all of these people. Maybe this system doesn't fall under anybody's umbrella, and it's a system that's out there and maybe has some security risk to it. That is a problem.
A security program identifies all of this and trains the people in what the expectation is. It does audits to make sure people are following through with what they need to be following through with. It captures these processes that are outside of other people's purview. A good security program is going to take a look at all of these different aspects and make sure that the whole company is coordinated with this.
Let me put it another way. This is somebody's network, and this network has a wall built around it for security purposes. But there are all of these doors to get into it. These doors, these gates, are individual employees' accounts, and these individuals will have a username and password to get into these gates. Supposedly this network is secure, but it just takes one person to leave the door open — a bad password that they have, or they've left it written on a message, or somebody has gotten a hold of this password — and now it doesn't just expose this little area, it exposes the whole network behind this. Once they're in there behind it, they can see everything, and it exposes everything.
A good security program makes sure that everybody is up to speed, that everybody understands they need to have these gates closed, that they need to have good passwords, and that they need to understand what phishing techniques are out there. Even with a good security program, I test the employees at the company I'm working for on a regular basis. Every couple of weeks they get phishing messages in their inbox, coming from a system that we manage, and it is testing them to see if they click on the links. And I have the same people that click on the same links over and over again.
So you have to watch out for this from a security program standpoint. You have to be monitoring this, you have to be educating people, and you have to be testing them. You have to have this full security program to really say that you are doing security, because without it you're all operating in these little different silos and operating at the experience that you have in the position that you have. It's not a true security program unless you dedicate resources towards security.
In its simplest form, it's really just about setting policies. Policies are expectations of how things are going to be, and you set those expectations. You make sure everybody agrees to those expectations, so everybody's on the same page. Then you set procedures and processes, and you implement changes that people are going to follow to make sure that they are being secure.
It also encompasses these things called controls. Controls are where you set aside a measurable standard, and then you hold people to those measurable standards. You hold those processes to those measurable standards. A security program has to have these elements of policies, procedures and controls to make sure that people are educated on what they're supposed to be doing, and that they are in fact doing what they should be doing.
Now, what should they be doing? What should you be doing? You need some sort of security framework, something that outlines what this looks like. I look at it as a blueprint. A security framework is a blueprint. There are many different security frameworks out there. You would select a security framework, and then you would build your security program off of this security framework. Some examples of this would be NIST 800-53, the NIST Cybersecurity Framework, COSO or COBIT, or ISO 2700. There are different frameworks out there that can be utilized to start building this security program around.
A good security program has risk management. Risk management is the process of taking and analyzing risk, figuring out what risks are going to be detrimental to the company, and figuring out how to mitigate those risks.
A couple of areas that this can be done in: first of all, the security risk assessment. Through a security risk assessment you look at what threats are out there and what threats you should be worried about. You look at vulnerabilities — what systems do you have out there, and what vulnerabilities do those systems have. You conduct something called penetration testing. Penetration testing, or pentesting, is a third party that comes in and starts testing out your network to see how they can penetrate it, where the vulnerabilities are, and how they can leverage the different systems. There's also posture assessment, which analyzes your whole security platform, your whole security program, to make sure that it is at a level that it needs to be for the size of business that you are.
There's also business risk assessment: assessing processes to make sure there are no gaps in the processes of the business. One of those is the vendor assessment as well. Make sure that the vendors are the appropriate vendors, and that there are no gaps with the agreements with the vendors and how the vendors operate. So there are some assessments that go into this to analyze the risk and see what the risk level is within each one of these different components.
Risk can actually be calculated. We can come up with quantitative data for risk, and this is helpful so we can compare different risks and prioritize different risks. What I mean by that is that risk is probability times impact, and that's how we calculate it. Probability is a percent, and the impact is a dollar amount, a monetary amount.
Let's give an example. We have a certain particular system that we're analyzing, and the probability that it would get hacked in the current state is 10%. If it got hacked, it would cost us $100,000 to fix — or maybe loss of productivity, or maybe loss of our reputation, or maybe some sort of impact like that. So the risk involved with this would be $10,000, 10% of $100,000. That would be the risk level, whatever's come out of the assessment.
So we can actually put calculated data, something that is solid information, with this. Once again, this helps if we have a lot of different risks. We can figure out the probability that each one of those would occur, figure out the impact that it would have on the business, and calculate what we figure the loss would be for this. Then we can prioritize based off of that.
With risk management, we assess the risk, we prioritize the risk, and then we take some sort of action against that risk. So what actions can we take against the risk? There are a few different options that we have.
These are some strategies for when we discover risk. What are we going to do? Are we going to avoid it? Are we going to reduce the impact? Are we going to transfer it, or are we going to accept it?
The first thing that we talked about is the security program and the need for a security program. It is so important, because otherwise you just have people doing whatever they think is secure, and that is not a form of security at all. We talked about different security frameworks, things that you can start building that foundation with and build the security program off of that foundation.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →