Darren’s guide to project managing your cyber security

I’ve helped many of our clients make cyber security part of their business as usual and trust me, it’s easier (and more cost effective) to implement cyber security as a proactive task rather than a reactive one. And to do that well, it needs to be treated like a project…

With any project, you begin with your desired outcome (or goal), considering what it looks like and how you might get there.  When planning a company-wide cyber security programme, you also need to make sure this is all aligned with the company’s overall strategic direction to prevent waste and maximise the efficiency and impact. 

Overview

In this article I am going to share my key learnings under the headings of:

  1. Initiation – where and how to start
  2. Implementation – why a holistic approach is best
  3. Monitoring – and how to avoid standing still
  4. Communication and feedback – the oil in your machine
  5. Top tips

I hope it will help you on your cyber security journey…

Initiation – where (and how) to start 

Declaring that “we take the security of your information seriously” in your privacy policies or on your website isn’t enough;  at some point, you will be asked to prove it.

First, you should know:

  • What is important to you (what do you want to protect?)
  • Where do you want to be (align to standards, implementing best practice and/or gain certifications)
  • What is your current security posture? (what’s good and where are the gaps?)

Build your business case to explain why this is beneficial, and have the evidence to back this up with an audit. Audits are often overlooked, viewed as a task at the end of implementation to check, but as a gap analysis, they are a most important step to direct efforts, reduce waste and prevent mission creep.

Although the times may be changing, business motivation is still vastly influenced by finance – not the good intention of cyber security around client or staff data.  The quickest barrier to any project buy-in is cost: “so… what’s the cost of this implementation?”. 

As a project manager, you can change this attitude from overhead to investment by considering the positive reputational impact, which will in turn provide a competitive edge for contracts that previously may have been unachievable. And that’s not to mention building resilience and prevention of financial loss from inefficient processes, which may lead to a costly breach.  Case studies of fines from the ICO or similar, are distributed frequently for industry markets to help identify potential security gaps and savings for your company.

Implementation – why a holistic approach is best

One of the most cost-effective defences in cyber security is creating a human firewall, by implementing a regular training and awareness program.  Your staff are the most important asset and line of defence… But they can also be the weakest link in the security chain through no fault of their own.  The balance can be tipped in your favour by encouraging an interest in security and the strategic direction of your business, of which they are a key part.  This can be as simple as frequent internal sessions in which your team is updated with current threats, new working practices or familiarisation of what is already in place.

There will always be preferred standards and accreditation for your business that you will want to prioritise.  As a project, the crossover and duplication must be minimised to be effective in control and resource management – both to implement and to manage cyber security.  

Identify the compliance required by law and regulatory bodies, timeline milestones from your current framework and renewals into a combined schedule.  You will be surprised how many compliance framework tasks cross over into HR, HS or the technical that you are already practising and can be combined into a single management system.

Let’s use payment card compliance (PCI DSS) as an example. This is an annual submission, however it will involve some must-dos – such as quarterly internal & external scanning, or penetration tests and awareness training. It will be important to merge any new compliance requirements into your current way of working.   Standards or requirements for accreditation are not secret and are easily obtainable, so using these as the product to extrapolate the tasks will show where compliance duplicates effort, whether this is in the technical, HR or policy-making areas.

Ensuring it is realistic and sustainable is key to long-term success, which means ensuring leadership buy-in at the very top.   This is the authority to act for any one person working toward the strategic goal, regardless of seniority.  Importantly, leadership buy-in should also provide appropriate resource.  As this is not a one-person job, it relies on delegation of tasks to staff that are competent to carry them out, and a project team with the understanding and influence within your business to manage compliance via delegation.  Having a team also means the single point of failure risk is reduced.  

Monitoring – and how to avoid standing still

Controlling the project to deliver and enable outcomes involves monitoring.  For project management, this is key throughout implementation and your business-as-usual work practice. Known in ISO as the Plan, Do, Check, Act process, you need to know the intended outcome and risk before acting, and ensure through quality control to ensure that your plans are effective and working.  If not, lessons are to be learned and change is to be controlled.

Promote any change to working practices from implementing cyber security & compliance as a tool for improvement rather than a badge to display.  If things are not working as expected, the first identification will usually be at the coal face, which needs to be communicated.  Removing blame culture by having an understood process in your workforce to communicate issues (that must reach the project team) provides a key area of input for continuous improvement and change control.  This prevents prolonged risk or introduction of new risk from workarounds by helpful staff.

Check and test proactively via auditing and hold people to account.  The results of auditing are a second key area of input to continuous improvement, but is only effective if owners are assigned (and aware) of responsibilities within your cyber security programme.  If something is not working, find out why by completing a root cause analysis, the results of which may be relevant to other areas of business that previously were unaware.  Monitor your KPIs, risks and identified problems from these incidents or scheduled tasks to highlight patterns. This should focus your planned efforts in the future.

Conduct due diligence before engaging with interested parties, especially if your information is shared or your reputation will be influenced by a new relationship.  Be confident enough in your cyber security to be the one that asks “prove it” as your cyber security may involve reliance on a 3rd party process.   

Communication and feedback – the oil in your machine

For any cyber security programme to work, it requires centralised control and communication up and down the chain to raise general awareness and provide the validity for change.  As with any project, the initial product needs to be assessed for completion and in cyber security, this will be a continuous process at management review from your previous planning.  Gaining certification for example, may be a point in time assessment but there should be the assurance you continue to meet the standard you hold yourself to.

Security threats and best practice, especially in the cyber environment rapidly shifts.  By regular review of your current security posture as a team, taking into consideration any internal or external influence change (new suppliers, changes to compliance, new process) allows effective planning and management of tasks, this includes identification of gaps in resource, technical ability, or staff training which should be addressed prior to the risk increasing. 

Top tips

  • Start small – Awareness training and OS/software patching.  
  • Keep up to date – Sign up to regulatory body and industry news. 
  • What we do and how we do it – Create and distribute company policy and procedures (20 is plenty) 
  • Frequently audit – Check its working and if it is not, find out why.  Address the problem with a planned approach.
  • Communicate – Promote cyber security and continuous improvement (team effort)
  • Achieve industry accreditation – Itemise standards into achievable tasks and goals as part of your cyber security schedule.
  • Do not ignore it – If you need it, if you can’t do it, find someone that can help.

Final thoughts

Not everyone or every business has grasped this yet, but cyber security can’t just be bolted on to your organisation: it has to be planned, integrated and updated along with everything else you do. Once you accept that, everything will start to click and make sense. My hope with this guide, which based solely on my own experience, is that it will help you see the bigger picture and avoid some of the pitfalls along the way.

If you have any questions or feel I have missed anything important, please feel free to get in touch.

P_darren_1_Securious_Exeter_Devon_Cyber_Security

Written by Darren

Darren is our Operations Director. He facilitates the smooth delivery of our client services, making sure everything is done right and on time. Darren is Prince 2 qualified and a BSI qualified ISO 27001 implementer.

Follow us on LinkedIn

See the latest from the Securious team on LinkedIn