In the vCISO services line at risk3sixty, we see early on in engagements that many of our clients have caught themselves in a break/fix cycle, which reminded me of an old
SNL skit. If you’re unfamiliar with Saturday Night Live, it’s a sketch comedy show with a segment called “Weekend Update,” a satirical take on the nightly news. This particular segment featured the financial expert Oscar Rogers, who went on to describe how we could erase the nation’s debt and get government spending under control by following these simple steps:
“
Identify a problem… Fix It! Identify another problem… Fix It! Repeat as necessary until it’s all Fixed!”
– Oscar Rogers As ridiculous as Mr. Rogers’s advice may sound, I realized that we have all been lured into this trap while implementing and managing systems or building out governing security programs: we identify a problem, fix it, identify another problem, fix it. But, despite all our efforts, we find that we have not been able to ensure that it’s all fixed, and often we are fixing the same problem over and over again. So how do we regroup, mobilize, and implement a well-rounded and scalable security program that is built to last?
How We Help Fix It - The risk3sixty Way First, we take a step back and make sure that we have a holistic understanding of exactly what our clients’ business objectives are, and how we can leverage a well-rounded security program to drive these initiatives forward. In some cases, the appropriate technical solutions are already in place, but the organization hasn’t adopted them as expected, they’re not configured properly, or what’s truly important to the business has not been considered during the implementation process. With each of our vCISO engagements, we have a playbook we work from to assist in building out an effective and scalable information security program. The playbook involves independent workstreams including but not limited to the following:
“
Identify a problem… Fix It! Identify another problem… Fix It! Repeat as necessary until it’s all Fixed!”
– Oscar Rogers As ridiculous as Mr. Rogers’s advice may sound, I realized that we have all been lured into this trap while implementing and managing systems or building out governing security programs: we identify a problem, fix it, identify another problem, fix it. But, despite all our efforts, we find that we have not been able to ensure that it’s all fixed, and often we are fixing the same problem over and over again. So how do we regroup, mobilize, and implement a well-rounded and scalable security program that is built to last?
How We Help Fix It - The risk3sixty Way First, we take a step back and make sure that we have a holistic understanding of exactly what our clients’ business objectives are, and how we can leverage a well-rounded security program to drive these initiatives forward. In some cases, the appropriate technical solutions are already in place, but the organization hasn’t adopted them as expected, they’re not configured properly, or what’s truly important to the business has not been considered during the implementation process. With each of our vCISO engagements, we have a playbook we work from to assist in building out an effective and scalable information security program. The playbook involves independent workstreams including but not limited to the following:
- Information Security Baseline Assessment
- Information Security Training
- Logical and Physical Access Reviews
- Risk Management
- Incident Management
- Business Impact Assessment (BIA)
- Business Continuity Plan (BCP)
Making It Personal
We are intentional about learning and understanding your business, what’s important to it, what it excels at, what it struggles with, what risks it faces, and what its short—and long-term goals are. Once we have all the necessary context, we start to create a strategic plan that leverages these unique workstreams to help drive business objectives. So rather than identifying a problem, fixing it, and repeating the process repeatedly, we focus on building a program that helps facilitate growth and eliminate roadblocks for good.What’s Next?
If you want to learn more, check out this whitepaper on Single Framework Strategy.
Daniel Haumann
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)