TechKnowSurge
NIST CSF GV.PO-01 NIST 800-53 PM-1 ISC2 CC 1.3 NIST CSF GV.RM-01 NIST NICE K0798 NIST NICE K0799 DoD 8140 OG-WRL-005
VideoSecurityFree

Protection - The Need for A Cybersecurity Program

A cybersecurity program is a structured, ongoing function that assesses risk, enforces policy, and ensures company-wide accountability — and without one, organizations remain exposed no matter how strong their individual technical controls are.

Complete this video to capture a CTF flag worth 1 point.

About this video

Organizations are made up of people with different roles, skill levels, and assumptions about security — and that variety creates risk. An accounting professional who has never experienced a breach may underestimate social engineering threats. A developer who writes secure code may have no visibility into company-wide vulnerabilities. An IT technician may be too occupied with day-to-day operations to evaluate the broader security posture. Even a well-informed employee who dismisses policy as irrelevant to their role may unknowingly expose customer records or erode competitive advantage. Without a cybersecurity program that spans the entire organization, no single person or team can compensate for these blind spots, and one weak link is all it takes to compromise everything else. A cybersecurity program addresses this by operating at the organizational level rather than the individual one. It identifies and assesses risk, ensures alignment with regulatory and customer requirements, and translates those findings into enforceable policies, procedures, and controls. Equally important, it trains employees on those policies and maintains ongoing compliance monitoring with clear accountability for violations. Unlike a project, which has a defined start and end, a cybersecurity program is continuous — it evolves as threats, regulations, and the organization itself change over time. The ideal structure for a cybersecurity program is a dedicated department with its own budget and personnel, separate from IT. Placing cybersecurity under IT creates a separation-of-duties problem, where the same team responsible for implementing technology is also responsible for auditing and securing it. While resource and size constraints mean many organizations rely on their IT department to carry this function, the goal should be moving toward an independent cybersecurity function that can provide objective oversight and enforcement across the whole organization.

What you'll learn

What's covered

Cyber Security Program

Aligned to

NIST CSF
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders.
NIST 800-53
PM-1 Information Security Program Plan
ISC2 CC
1.3 Understand governance concepts
NIST NICE
K0798 Knowledge of program management principles and practices
K0799 Knowledge of project management principles and practices
DoD 8140
OG-WRL-005 Executive Cyber Leader

Key terms

Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Regulatory Compliance
The adherence to laws, government regulations, and industry standards that mandate how an organization must protect data and systems. Failure to meet regulatory requirements can result in fines, legal liability, and reputational damage.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Cybersecurity Program
An ongoing organizational function that encompasses risk assessment, policy development, regulatory compliance, employee training, and accountability to protect the organization continuously.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.

Topics

Cybersecurity Program Risk Assessment Security Policy Regulatory Compliance Cybersecurity

Transcript

Why there's a need for a cyber security program

There are a lot of people out there that feel like they do cyber security well. There are also a lot of companies that don't think that they're vulnerable. Yet people are being hacked on a daily basis, and companies are being hacked. So there's a disconnect there, and one of the problems is that companies don't have a security program.

A company is made up of people, and those people have a limit to their knowledge and how much time they have. So here are a few fictitious people at a fictitious company, to see what it looks like from a cyber security perspective.

This is Fiona, and she works in accounting. She thinks that she understands cyber security and how to be secure, but it's mainly because she's never been hacked before. This is really dangerous, because she doesn't think that that's going to happen to her, but she's in an important role. If somebody uses social engineering against her, she could be compromised — and same thing with the finances of the company, and then employees are not getting paid.

This is Rick, and Rick has a deep understanding of security, but only from the perspective of a programmer. When he's into the systems, he's making sure his code has a certain level of security involved, but he has no idea about the big picture around security of the company.

This is Shelly. Shelly works in IT, and she's in a lower level position in IT, so she doesn't really fully understand security just from her perspective as well. She understands IT security, but not security for the company. Not only that, but she's really busy doing IT work and doesn't really have time to look at the cyber security program as a whole for the company.

This is Whe, and he really understands cyber security and he knows what he's supposed to be doing, but he doesn't think that it really applies to him — that the policies and what is put out there is not something that's all that important, because he doesn't have access to sensitive information. Or so he thinks. But if you actually look at the information he has access to, it's customer records. If those were to get exposed to the outside, that would be problematic for a couple of reasons. Number one, then maybe you have to notify those customers, and that could be a damage to your company reputation. Not only that, but if a competitor gets a hold of that information, then that could be a loss of competitive advantage to the company.

And then we have some systems and processes that are really old, that people have just been doing, and technology that's just been serving the company over a period of time. A lot has changed over 15 years, and since that doesn't fall under anybody's umbrella, largely those security concerns around these systems and processes go unchecked.

So as you can see, if we don't have a cyber security program, we really can't enforce cyber security principles across the whole company and across all of the people of that company.

Let me put it a little differently as well. Let's say all of our resources within our network are locked up and really secure, and people have to input their credentials to get access to it. But it just takes one person to have bad credential hygiene, bad ways of them tracking their passwords, or really poor passwords, or whatever the case may be, to open up a vulnerability that exposes everything behind these walls. Well, that's what it's like with your employees, with the people of a company: one person practicing bad cyber security principles can open up the whole company for devastation.

Functions of a cyber security program

So what is a cyber security program, and what functions do cyber security programs have?

  • First of all, it's going to take a look at the risks. It's going to assess risks to the company so that way it can mitigate those risks.
  • Then it's also going to take a look at regulatory compliance. So, what are the government regulations, what are the customers demanding, what are the things that are demanding of the company that they fall in line with.
  • Then they're going to create policies, procedures, controls and guidelines. They're going to create things that are going to help mitigate against this risk and enforce this regulatory compliance.
  • From there they're going to have to train their employees on how to follow these policies, procedures and functions, and make sure that everybody is following that.
  • As part of that, to make sure that they're following it, they're going to work on compliance — making sure people are following it — and accountability. There's going to be some sort of repercussions if people are not following that.

A program, not a project

One thing that a cyber security program is not is a project. It is a program. So what is the difference between a project and a program? A project is time bound. That means it's got a start and it's got a finish to it, so there's a definitive time when the project is done and you have some sort of final product at that point in time, some sort of deliverable. A program is not that. A program is instead ongoing, where there's consistently checks and balances and you continue to develop it. I will tell you that when I'm setting up a security program, I launch it as a project to get it up and running, but then there's a maintenance part of it, because it's a program that continually operates after that.

What an ideal cyber security program looks like

What happens in a lot of companies is the cyber security program falls under IT, and this is not the ideal situation. It falls under IT because it's got the word cyber in it, and a lot of cyber security has to deal with the technology and things that IT would implement. But the real ideal is to have a whole separate department that's in charge of cyber security.

The problem with IT being in charge of cyber security is that it's not a separation of duties, which means that IT is both carrying out the functions of IT and also trying to implement security policy on IT, and that doesn't work very well from an accountability standpoint. So really, ideally, it would be a separate department with its own budget and with its own people. That's an ideal cyber security program.

Of course, that can't always happen because of resource funding and because of the size of the company, so for smaller companies that tends to be the setup. But ideally you'd be working towards a separate department for the cyber security program.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →