Building an effective cybersecurity program requires understanding what drives the need for one, who owns it organizationally, and how it gets structured across the business. This content covers the internal and external pressures that prompt security investment, the role of executive support, and the differences between centralized and decentralized program governance.
Security Program Development
Developing a comprehensive security program takes a lot of time, energy and money to do. It eats up a lot of resources, so we don't want to just do it to do it. There are certain reasons why we do it, but what are the driving forces?
I found that there's these certain drivers that keep coming up again and again to drive change when it comes to a cybersecurity program, and they can be categorized into two different categories here. One is just internal: internally we've decided this is a change that we need to do. Versus external: there are a lot of external factors that I find.
Number one is just customers are becoming more and more demanding around cybersecurity, and if you don't meet the customers' needs, they're going to cease to be customers. They're going to move to other companies. Or what I found is a lot of customers won't even become a customer of yours until you meet certain cybersecurity changes, until you implement certain cybersecurity policies, or until you implement certain controls. So that's one thing that's increased over time.
Another thing that's increased is the laws and regulations. They're getting a lot more stiff, and the bar is being set high with these. Same thing with cybersecurity insurance: in order to get insurance nowadays, it's becoming a lot more requirements to even get a quote for cybersecurity insurance with this.
The other thing that I find is a common driver, if it's internal, is that we've encountered some sort of pain point. That is, somebody hacked something, or there was a compromise, maybe there was a scam. Something's happened, and now we say, oh, that was really painful, so now we need to make some changes.
So really, most of the time that I find with cybersecurity is that we play a reactive role. That is, we make a change because, once again, we've experienced some sort of pain, or there's some sort of external influence that's making us make this change. But what we really need to do is get more on the proactive side, and it really makes a lot of sense to do that. Because the reason why the customers and the laws and regulations and cybersecurity insurance, the reason why the standard around these are growing, is because they're protecting customers, and we want to protect customers as well.
Not only do we want to protect customers, but we want to protect the business. If we find ourselves in a cybersecurity incident, 60% of small businesses, small and medium-sized businesses, go out of business within six months after a cyber attack. That's pretty staggering. So if we take that proactive stance, we actually create a much more stable, reduced amount of risk, reduce the amount of cost to the company, if it's done right.
Now, ultimately you're really not going to get very far unless you've got upper level support. What do I mean by that? Here's the corporate structure. At the top of a corporation, at least, you have a CEO, and then underneath there you have this group of execs you call the C-Suite. Then you've got the VPs, under there you've got the directors, managers, and then individual contributors. You need the support from the upper management in order to carry out a lot of the stuff that you need to carry out, because there is a lot of time and energy and resources that go into creating a cybersecurity program.
Although many see the CEO as being the top of the company, the CEO really reports to the board of directors, who elect the CEO, and the board of directors are elected by shareholders and company owners. So there's kind of a structure to this, and you need the support from all of this.
But who's actually in charge of approving the cybersecurity program and the policies, and what does that look like? This can look different depending on the company. For instance, if you're a larger company, you have somebody like a CISO, which is a chief information security officer, that operates at the C-Suite, who really is the driver to a lot of this.
What I've also seen is at smaller companies, like I was a director for a company, and as a director I would then create all the policies but then get sign-off from the upper execs to make sure that everybody was on board with it.
I've also seen things driven more from board of directors and CEOs more so than I ever have in the past, because cybersecurity has become a very hot topic. So now you see a lot, much more so than I ever seen before, you've seen a lot of requests coming now from the top.
Another way we could also do this is create a committee, a committee maybe of individual contributors, managers, directors, VPs, C-Suites, or really it could be any combination of any of these. So we might create a committee to either develop or approve of these policies. And some of them are policies that are just put on us from a legal perspective, that we're just required to implement.
The way we roll out a security program and the policies and the procedures might look different also from a centralized or decentralized. What does that mean? This could be centralized or decentralized based off maybe geographical locations, or departments. There's a lot of different ways we could roll this out, but I'm going to use geographical just because it gives us a nice visual.
Let's talk about decentralized first. Let's say the company has a headquarter office here in Seattle. We have a satellite campus over in Chicago. We've got several buildings over in the New York area, and then we've got a factory that's down in Texas. Decentralized just means that maybe we have some upper level policies, but for the most part all of these sites kind of is in charge of their own security. That is decentralized.
Versus a centralized system means that there's going to be a central control around security. So with a centralized system, let's use headquarters as an example here. Headquarters here sets the tone, sets the policies, the procedures and everything, and then it's a requirement for all of these other sites to follow that.
So a centralized system is maintained organization wide, versus decentralized is delegated: some of these tasks are delegated out to the individual offices, or individual departments, or whatever the case may be. Centralized gives us some level of consistency amongst the organization, versus decentralized allows us to be much more dynamic. And then generally the centralized works with larger companies, because they go from a growth state to more of a protection state, versus a decentralized is more for smaller companies, at least what I found, because they're more into being agile and being able to adapt and dynamically change.
Ultimately there's going to be a lot of different ways that we roll this out and how we structure this, but the big thing is that we need to adapt to the company, the size of the company, the industry it's in. And how we govern our security operations and our policies is really going to change depending on what the needs of that organization or that company are.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →