Roz on why Monikal can help CEOs like her sleep better at night

As CEOs, we tend to have many things whirling around our heads at any one moment. From considering the wellbeing and the efficiency of our staff, to thinking of the future and how we can adapt to better serve our clients, to wondering how best to ensure the long and short-term success of our businesses. 

And it’s obvious that all of these things are important. But as leaders, we need to be focused, prioritising ruthlessly and driving our businesses forward. 

So I want to explain how a brand new product we have just launched at Securious can have a real impact on easing a CEO’s biggest fears, even if they wouldn’t normally expect to find solutions to their issues in the cyber security arena.

What keeps you awake at night? 

I think one of the best ways of distilling down what needs your attention most urgently, is to ask yourself what’s keeping you awake at night. For me, as a CEO, it’s the unknowns. The potential for something to happen that could impact the things I am custodian of. And if that was something I didn’t see coming, and I therefore had nothing in place to mitigate it… What a thought. 

For a lot of the people we speak to, thoughts of data breaches and cyber attacks keep them awake at night. And that’s not surprising – aside from a worldwide pandemic (and come on, how likely is that 😉 …), one of the things that is likely to have the biggest impact on your business across the board, whether on staff, clients, revenue or reputation, is a data or security breach. 

After all, it’s likely that the most important thing for us CEOs is our reputation. We can’t insure it for any amount of money. It takes a long time to build, but moments to come crashing down due to a breach, which could damage all those valuable relationships – whether internally with our staff, or externally with our customers and partners. All our hard work could effectively be unwound, and we’d find ourselves back at the beginning again. So cyber security might not currently be top of your concerns, but this is surely the stuff sleepless nights are made of?

So what can you do about it? 

1) Think ahead

In this day and age, we have to consider breaches as a given. Hopefully most of us will have incident response plans accessible and ready to go should the worst happen, and many of us will have insurance to help cover some of the costs incurred if it does. 

But if you’re really thinking about the impact a breach or attack could have on your business, you won’t want to just rely on your incident response plan or insurance. They aren’t enough.  

You might find it helpful drilling down another level, because security incidents come in all manner of shapes and sizes. Yes, there are ransomware attacks that could bring your business to its knees. Or big data breaches that would need reporting to the ICO and containing as a matter of urgency. But there are other security incidents that could really disrupt your business, but that you may not have covered in your incident response plan. 

Some examples of scenarios you might want to think about: 

  • An employee emailing the whole of your database to their private email address the day before they leave
  • The employee who followed your password policy to the minimum requirements but created a password that was easy to brute force
  • The targeted attacks on your firewall, and whether any of these have actually been successful or reconnaissance activities of our adversaries
  • The potential for a malicious actor to be sitting within your system exfiltrating valuable data
  • A client, or valuable partner telling you that you have had a breach
  • A breach occurring, and not having sufficient log data to be able to identify the scale of this
  • A port left open on your firewall by an upgrade that allowed access to malicious actors
  • Someone logging into your system via remote access from another country

2) Consider the potential costs of different kinds of breaches

It’s worth thinking through the end result of different breaches to help you decide which kinds of incidents would have the biggest impact on the success or even longevity of your business. Consider both the potential impact and the likelihood of it happening to help guide your priorities. 

To give you an idea of some potential costs: 

Fines and penalties 

The ICO issues fines to businesses that have not done enough to protect their data under the GDPR.  

According to statistics compiled by RPC, a City of London-based law firm, the average fine issued by the ICO trebled from £73,645 in 2016/17 to £216,000 in 2020.

Generally, the ICO has the power to levy maximum fines up to €20 million or 4% of global turnover – whichever is higher. So it’s certainly an end-result that should be avoided at all costs, with the implementation of robust technology, processes and systems to safeguard your data. 

Reputational impact

If you have a data breach and it becomes public knowledge, your reputation will suffer. Clients and prospects will lose trust in you and you’ll have to do a lot to make up for not looking after something as important as customer data. 

Compensation 

There is something else which is looming as an additional risk, and that is the increase in ‘no win-no fee’ data breach solicitors, now that they have exhausted PPI. The affected can claim for both damages and stress for ‘data protection negligence’, and will increasingly be encouraged to do so with online targeted ads and even phone calls: 

“Has your breach resulted in stress, anxiety of financial loss?”

And in terms of the scale of compensation – it would appear this is from £500 to £7,000 and more for breaches that caused the claimant depression or illness.

So what type of data breach could command what amount of claim?

A leak of an individual’s name, date of birth, home and email address is between £1,000 and £1,500, whilst a breach of medical records £2,000 to £5,000, Financial information is quoted as between £3,000 and £7,000. Depression and illness was quoted as up to approximately £40,000. The solicitors’ fees would be 25-30% of each claim.

This trend is all very worrying. For some of these things, we’ll be looking at insurance to help us cover costs but – and I’m not sure if anyone has noticed this – but these premiums are definitely on the up as insurance companies are starting to see the financial impacts increase.

3) Make sure you can see what’s going on in your environment

Once you’ve identified your biggest cyber security worries, and the scenarios that could have the biggest impact on your business, you’ll want to know that if any of them happen, you’ll be aware of it. That way, you can act quickly and protect your organisation, and in some cases have sufficient evidence if you need to take court action, or to defend your organisation. The way you respond will help determine the potential ICO fines you pay, how your customers feel about continuing to work with you, and potential financial impacts.

So what can we do to help make sure we have ‘eyes on’ the potential problems and issues that could have this sort of impact on our business? How do we know where our potential problems are coming from, and if and when things do go wrong, how can we make sure we get to the route of the problem quickly so we can act immediately?

Introducing Monikal (and how it can help improve a CEO’s sleep)

Having accurate, easily accessible information about your system and unusual events within it are crucial. 

Your systems are already generating the raw data constantly in the form of ‘logs’ – for example the number of failed login attempts which could indicate an automated ‘brute force attack’, new admin accounts being set up, and large files being exported. 

However, unless you know in advance what you are looking for, logs are effectively just large dumps of data rather than being of any practical use: scouring through reams of ‘logs’ and spotting any areas that trigger that alarm is a big job for your already-busy IT team. Then investigating the source of a breach could take weeks. Not great for you or your customers!

Imagine having to wait weeks before you could let your customers know what data was accessed, and them potentially being at risk for that length of time. Now add to that the fact that these logs are continually being overwritten, the data just might not still be there.

This is why we developed Monikal. 

Monikal helps mid-level organisations protect their critical information to reduce the financial, reputational and operational impact of data breach. Through a single dashboard, it provides increased visibility of technology and networks to highlight any vulnerabilities and enable a proactive response to threats and abnormalities.

In technical terms, Monikal is a SIEM solution (SIEM stands for Security Information and Event Management). A SIEM solution works by collecting logs from multiple devices across a network and amalgamating the data into a usable form. This includes identifying activity that is abnormal.

SIEM solutions have been available for some time in enterprise level organisations and governments, but our goal was to deliver an affordable option for CEOs of mid-level organisations who want to know where the next potential side swipe is coming from. Monikal collates and correlates data from across your whole network, at a price that makes this a ‘no-brainer’, starting from less than the 2020 UK average for a part time member of staff. 

If configured appropriately, it will, for example:

  • Tell you if an employee emails the whole of your customer database to their private email address the day before they leave
  • Tell you about brute force attacks – and which accounts are being targeted
  • Document any targeted attacks on your firewall, and whether any of these have actually been successful 
  • Highlight any potential for a malicious actor to be sitting within your system exfiltrating valuable data
  • Provide you with the log data you need to identify the source and scale of a breach, should the worst happen
  • Tell you if a port has been left open on your firewall by an upgrade that allowed access to malicious actors
  • Let you see if someone is logging into your system via remote access from another country

So that’s it. We’ve launched Monikal to help CEOs get a good night’s sleep; it’s as simple as that. I already wouldn’t be without it. If you are a CEO and would like to sleep better too, contact me and I’ll arrange for you to see for yourself how helpful it can be.