Cyber security strategy: how to create a realistic plan

Having a cyber security strategy is a fundamental part of taking a proactive approach to cyber security. Otherwise, you’ll find yourself swamped, trying to react to every new threat that may emerge.

It should not matter if you have an outdated cyber security strategy in place or you are starting from the beginning – the following information will help you to start building an effective and strategic cyber security plan.

Task 1: Lay the foundations for a solid cyber security strategy

To have a strategy, you first need to know what you are going to protect.

You need to gain an understanding of the assets your company needs to protect. Assets come in many forms, but ultimately an asset is something that has value to your organisation. An asset extends beyond what most people would think of such as physical goods or hardware. Assets also include people, data, and your reputation.

While it may not be practicable to try and protect everything 100%, you should focus on what you absolutely need to protect first. To do this, start by reviewing your business processes and understanding how your revenue is generated, as well as what systems/information would have the ability to disrupt that by being unavailable or having the data stolen.

Identify what you are legally required to protect

While compliance and security are not the same thing, most organisations put the responsibility of maintaining compliance or security compliance frameworks on the CISO. Non-compliance can be costly and damaging to your business. Ensuring you design your strategic cyber security plan with required compliance frameworks in mind will help ensure your strategy prioritises legal and/or regulatory requirements.

Understand your organisation’s risk appetite

Before you can begin to develop a cyber security strategy, you should understand your organisation’s risk appetite, or the total risk your organisation is prepared to accept in pursuit of its strategic objectives. Risk appetites differ depending on your company’s financial strength, industry, objectives being pursued, and more. The cyber security strategic plan that works for a startup is unlikely to work for a large, established corporation. By understanding your company’s risk appetite, you can ensure you are not over- or under-protecting your business.

Task 2: Get to know the threat landscape

Once you know what assets you are going to protect, you need to analyse the threat landscape. To do that, you will need to first understand the environment in which your company operates. Who are your customers? What are you selling? Who would benefit from disrupting your business? The answers to these questions can help you become more familiar with the general environment. Every organisation’s threat landscape will be different, but all should include areas such as IT security updates etc. as a standard.

You will also want to look at what is happening with your competitors. What threats do they face? Has their security been breached in the past? The threats your competitors are facing are almost always the same threats that may impact your business, and looking at another organisation is often easier to visualise potential threats rather than being self-critical of your own organisation.

Finally, understand the types of threats that your business needs to protect itself against. What types of resources do potential attackers have? What are their motivations for shutting you down? Knowing these answers will give you the upper hand in defending your business against these threats.

There is no easy way to get this information, Google ‘cyber security threat report’ and you will get over 96 million results.

Task 3: Build your strategic cyber security plan

Pick a framework, identify the current state of your security environment, and establish a timeline. To build your plan, you need to pick a framework to use. Options include CIS Controls, NCSC 10 Steps and NIST.

It is important to choose a framework so you can effectively track progress while prioritising the most important steps. For instance, the CIS Controls provide you with a set of prioritised actions to protect your organisation and the order in which you should take these actions. This allows you to track progress so that you know where you are in the process and what actions are still outstanding.

Think about where you are, where you want to be, and by when

When you understand what needs to be protected from a processes and risk management perspective, you should evaluate the effectiveness of your current security measures. Confirm if you are protecting the right assets? Do you currently have the right processes in place for compliance?

You will also need to decide on a timeline, which will depend on the current state of your security. BE REALISTIC – if your cyber security posture is in its infancy, it is not realistic to expect huge changes in a relatively short period of time. Organisations that do try and do this may fail…  And usually end up spending more money, time and effort getting back to a good place than if they had set realistic timescales from the outset.

Do remember, things can and will change over time, requiring occasional updates to the timeline. However, it is important to have a target time frame in mind to get to what your organisation considers an acceptable level of risk. With a two or three year plan (which may seem a long time but it is a sensible time frame. However, it is also dependent on the size of your organisation and resource availability), you will usually need to spend the first year focused on IT hygiene while addressing the greatest or most likely to be exploited risks.

Evaluate your company’s cyber security maturity level

Using either in-house staff or an outside consultancy, evaluate your organisation’s cyber security maturity level. The concept of cyber security maturity refers to a company’s adherence to security best practices and processes; measuring it helps you identify gaps and areas for improvement. Whether you do this analysis yourself or hire a consultant, make sure the process is repeatable. That way, when you check your security maturity in the future, you will have a benchmark with which to compare the results.

Evaluate your technology stack

Look at the technology you have in place and identify tools you aren’t using to their full benefit. Underutilised software or other tools are only costing you money, time, and increasing your attack surface. Find out if the solutions you have identified here are fulfilling their original purposes, and if there is any way to get better use of them. If not, consider getting rid of it. You can also use the Cyber Defense Matrix (read more on the OWASP website) to identify any gaps you may have in security. There are a lot of cyber security solutions on the market. This means that ensuring that all aspects of your company are protected can be challenging. The Cyber Defense Matrix helps you understand what you need. So, when you start looking at security solutions, you can quickly determine what products solve what problems.

Identify foundational items and quick wins

Identify the foundational items, quick wins, and high-risk items that need to be addressed as a matter of urgency. Which steps are fundamental to the future of your plan? Prioritise these actions first. Quick wins are things that are easy to fix or require few resources. In the first year of implementation, make sure you have a combination of both foundational tasks and quick wins.

Task 4: Evaluate your organisation’s ability to execute the plan

The final step is assessing whether your organisation is able to do the necessary security work. You will need to look at your current IT and security teams to understand their skill sets and bandwidth. If you do not have the resources you need, you may need to plan to hire additional team members or outsource some of your security work to execute your strategic cyber security plan.

During this step, it is also important to think about what the future holds for your business or the IT team.

Does your company have any big product launches coming up, or a possible merger or acquisition on the horizon?

Will your IT team be handling any large scale, company-wide projects in the foreseeable future?

Keep these details in mind as you plan so you can prioritise and plan efficiently.

And if all this sounds like too much?

Check out our Cyber Security Strategy/CISO as a Service page to see how we can take all of this off your shoulders.