London Summit set to focus on “lack of quantification” in sphere of cyber security

Is no news good news when it comes to cyber security in your business? What are the hallmarks of excellence in this field? Phil Cracknell, Chief Information Security Officer (CISO) at Homeserve, is speaking alongside senior public and private sector figures at the Cyber Security Summit and Expo in London on Thursday 16 November, shining a spotlight on the current challenges facing cyber security practitioners.

Cracknell is keen to focus on the lack of quantification in cyber security, pointing out that: “What good looks like is becoming increasingly important” and, as such, the ability to define what construes “good” cyber security takes priority.

Cracknell has achieved much in developing co-operation between CISOs with a number of purposes, one of which is the quantification of cyber security standards. Initially focusing on “anonymous surveys of CISOs to fill the void of information regarding breaches”, this work has since evolved into The Metrics Project.

The Metrics Project focuses on defining the mechanisms and language used to measure the effectiveness of information security, with over 50 UK CISOs involved. As the collective work of over 350 CISOs across its current lifespan and purposely avoiding vendors and analysts thus far, The Metrics Project focuses on developing something that will deliver true value to the businesses of those involved: “By the CISO, for the CISO” as Phil Cracknell observes.

Measuring and validating

Cracknell emphasises the role of metrics as “very much the key to our future” in measuring and validating the effectiveness of cyber security. “Businesses are waking up to the fact that they need metrics and risk indicators that our Board members, audit committees and non-executive directors are able to understand.”

Promoting a “report what you should, not what you can” mindset from organisations, Cracknell suggests metrics have the ability to affect business practice in a number of ways. They can demonstrate effectiveness, measure exposure and agility, test an organisation’s culture, pinpoint responsibilities and highlight levels of investment, all of which provide a great insight into a sector and tangible as well as measurable indicators of cyber security suitability.

Having been working in the cyber security arena for over 20 years now, its quirks and trends are not a mystery to Cracknell. Looking forward, he’s able to offer an insight on not only the current state of the industry, but also in terms of where this fast-paced and largely unpredictable sector may be heading.

Soft skills also crucial

Suggesting the current focus by security providers on product and technology may not be the optimum strategy going forward, Cracknell draws attention to the softer skills involved in effective cyber security. “Security leaders are still procuring solutions that don’t address their top issues or risks. Good risk management will avoid this. A solution for a risk doesn’t always have to involve buying hardware, software or a service at all.”

Instead, Cracknell advocates an introspective business model complete with the continual training of staff and improved process management.

Looking to the future, Cracknell has addressed the rising trend in both work and society of BYOD and the risks associated with it. “Given that our corporate perimeters are expanding and even disappearing entirely, coupled with the prevalence of personally-owned devices in working environments, businesses should concentrate on protecting the contents, not the containers, and identify critical data.”

*Phil Cracknell will talk as part of the Cyber Security Summit at 3.30 pm on Thursday 16 November under the subject heading Measuring Success: Metrics for Cyber Security Strategy. Cracknell is taking part alongside senior public and private sector figures, among them Mark Sayers (deputy director of cyber and Government security at the Cabinet Office) and Chris Ulliott (CISO at the Royal Bank of Scotland)

About the Author
Brian Sims BA (Hons) Hon FSyI, Editor, Risk UK (Pro-Activ Publications) Beginning his career in professional journalism at The Builder Group in March 1992, Brian was appointed Editor of Security Management Today in November 2000 having spent eight years in engineering journalism across two titles: Building Services Journal and Light & Lighting. In 2005, Brian received the BSIA Chairman’s Award for Promoting The Security Industry and, a year later, the Skills for Security Special Award for an Outstanding Contribution to the Security Business Sector. In 2008, Brian was The Security Institute’s nomination for the Association of Security Consultants’ highly prestigious Imbert Prize and, in 2013, was a nominated finalist for the Institute's George van Schalkwyk Award. An Honorary Fellow of The Security Institute, Brian serves as a Judge for the BSIA’s Security Personnel of the Year Awards and the Securitas Good Customer Award. Between 2008 and 2014, Brian pioneered the use of digital media across the security sector, including webinars and Audio Shows. Brian’s actively involved in 50-plus security groups on LinkedIn and hosts the popular Risk UK Twitter site. Brian is a frequent speaker on the conference circuit. He has organised and chaired conference programmes for both IFSEC International and ASIS International and has been published in the national media. Brian was appointed Editor of Risk UK at Pro-Activ Publications in July 2014 and as Editor of The Paper (Pro-Activ Publications' dedicated business newspaper for security professionals) in September 2015. Brian was appointed Editor of Risk Xtra at Pro-Activ Publications in May 2018.

Related Posts