A cybersecurity program is a structured, ongoing organizational function that identifies risk, enforces compliance, and establishes the policies and accountability measures needed to protect a company across every role and department. Without one, even a single employee's poor security habits can expose an entire organization to serious harm.
Cyber Security Program
There's a lot of people out there that feel like they do cyber security well, and there's also a lot of companies that don't think that they're vulnerable. Yet people are being hacked on a daily basis, and companies are being hacked. So there's a disconnect there, and one of the problems is that companies don't have a security program.
A company is made up of people, and those people have a limit to their knowledge and how much time that they have. So let's take a look at a few fictitious people at a fictitious company to see what it looks like from a cyber security perspective.
This is Fiona, and she works in accounting. She thinks that she understands cyber security and how to be secure, but it's mainly because she's never been hacked before. This is really dangerous, because she doesn't think that that's going to happen to her. But she's in an important role: if somebody uses social engineering against her, she could be compromised, and same thing with the finances of the company, and then employees are not getting paid.
This is Rick, and Rick really has a deep understanding of security, but only from the perspective of a programmer. When he's into the systems he's making sure his code has a certain level of security involved, but he has no idea about the big picture around security of the company.
This is Shelly, and Shelly works in IT. She's a lower level position in IT, and so she doesn't really fully understand security just from her perspective as well. She understands IT security, but not security from the company. Not only that, but she's really busy doing IT work and doesn't really have time to look at the cyber security program as a whole for the company.
This is whe, and he really understands cyber security and he knows what he's supposed to be doing, but he doesn't think that it really applies to him — that the policies and what is put out there is not something that's really all that important, because he doesn't have access to sensitive information. Or so he thinks. But if you actually look at the information he has access to, it's customer records. If those were to get exposed to the outside, that would be problematic for a couple of reasons. Number one is that then maybe you have to notify those customers, and that could be a damage to your company reputation. Not only that, but if a competitor gets a hold of that information, then that could be a loss of competitive advantage to the company.
And then we have some systems and processes that are really old, that people have just been doing, and technology that's just been serving the company over a period of time. A lot has changed over 15 years, and since that doesn't fall under anybody's umbrella largely, those security concerns around these systems and processes go unchecked.
So as you can see, if we don't have a cyber security program, we really can't enforce cyber security principles across the whole company and across all of the people of that company.
Let me put it a little differently as well. Let's say all of our resources within our network are locked up and really secure, and people have to input their credentials to get access to it. But it just takes one person to have bad credential hygiene — bad ways of them tracking their passwords, or really poor passwords, or whatever the case may be — to open up a vulnerability that exposes everything behind these walls. Well, that's what it's like with your employees, with the people of a company: one person practicing bad cyber security principles can open up the whole company for devastation.
So what is a cyber security program, and what functions do cyber security programs have? First of all, it's going to take a look at the risks — it's going to assess risks to the company so that way it can mitigate those risks. Then it's also going to take a look at regulatory compliance: what are government regulations, what are the customers demanding, what are the things that are demanding of the company that they fall in line with.
Then what's going to happen is they're going to create policies, procedures, controls and guidelines. They're going to create things that are going to help mitigate against this risk and enforce this regulatory compliance. From there they're going to have to train their employees on how to follow these policies, procedures and functions, and make sure that everybody is following that. As part of that, to make sure that they're following it, they're going to work on compliance — making sure people are following it — and accountability, where there's going to be some sort of repercussions if people are not following that.
One thing that a cyber security program is not is a project. It is a program. So what is the difference between a project and a program? A project is time bound, that means it's got a start and it's got a finish to it. There's a definitive time when the project is done, and you have some sort of final product at that point in time, some sort of deliverable. A program is not that. A program is instead ongoing, where there's consistently checks and balances and you continue to develop it.
I will tell you that when I'm setting up a security program, I launch it as a project to get it up and running, but then there's a maintenance part of it, because it's a program that continually operates after that.
What happens in a lot of companies is the cyber security program falls under IT, and this is not the ideal situation. It falls under IT because it's got the word cyber in it, and a lot of cyber security has to deal with the technology and things that IT would implement. But the real ideal is to have a whole separate department that's in charge of cyber security.
The problem with IT being in charge of cyber security is that it's not a separation of duties, which means that IT is both carrying out the functions of IT and also trying to implement security policy on IT, and that doesn't work very well from an accountability standpoint. So really, ideally it would be a separate department with its own budget and with its own people. That's an ideal cyber security program.
Of course, that can't always happen, because of resource funding and because of the size of the company. So smaller companies, that tends to be the setup, but ideally you'd be working towards a separate department for the cyber security program.
So as you can see, if you don't have a good cyber security program, then you probably don't have good cyber security, and you're opening up the company or the organization for some risk in the future. The functions of a cyber security program are really to look at the overall picture and start implementing policies and procedures and ways to mitigate against that risk. Ideally that's carried out by a separate department. A lot of companies will carry it out through their IT department, but ideally it would be a separate department.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →