Metrics and Cyber-Security
Cyber-security is a topic that is constantly in the headlines, with information security, cyber-attacks, data breaches and malware all becoming buzzwords. However, cybersecurity isn’t just about protecting IT systems – it also involves building genuine security awareness throughout the whole organisation and making employees part of the defences. Companies that invest in crisis drills, that screen freelancers and suppliers for security practices, and that develop a real culture of security will be much better protected against all kinds of attacks.
Metrics are an essential element of all cyber-security programs and, on a broader level, of all risk management programs that feature a security component. A set of appropriate metrics helps to ensure that the status and trends of a company’s cyber-security are clearly understood by the C-suite and that any risks can be addressed early on.
The vast majority of respondents to this question agreed that it was necessary to have a robust scheme of regulation in place to protect consumers from insecure consumer connected products, such as smart speakers, smart TVs and connected doorbells. A number of respondents noted that the requirements should apply to desktop computers and laptops as well, although they recognise that PC hardware and software are not as separable as the components of a smartphone.
Many respondents anticipated that there would be some additional costs arising from the implementation of these new requirements, including the need to conduct product testing and/or additional supply chain reviews and for bringing together complex datasets. Other respondents noted that the benefits resulting from implementing these new requirements would be limited or nil.