Attacks/Breaches
9/8/2016
02:30 PM
Scott M. Kannry
Scott M. Kannry
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Avoiding The Blame Game For A Cyberattack

How organizations can develop a framework of acceptable care for cybersecurity risk.

CISO’s crave it, senior executives need it, and boards of directors demand it. What is it? Exculpability – being held free from blame. Why do they need it? Because in a world where perfection is impossible to achieve, exculpability is what will ultimately protect reputations in the wake of a serious cyber attack.

In legal terms, cybersecurity exculpability means that within an organization, management and security operation teams took responsible actions, despite the occurrence of an unfortunate event. These responsible actions, in turn, provide assurances to security leaders that their careers can sustain the test of a breach and provide a convincing argument to senior executives and boards that despite the potential peril, understanding, and active management of cyber risk is a far better course of action than pretending that risk does not exist.

The challenge becomes defining the duty of care that will absolve security managers and execs after a serious breach. Today, where the risk climate is rapidly and constantly evolving, technology and traditional controls alone will always be an imperfect defense. So how can an organization develop a framework of acceptable care for cyber? Let’s start by looking to other areas of society and business where duties of care are already recognized.

Everyday life: the reasonable person standard
The most logical place to start is everyday life where the concept is fairly straightforward: Individuals acting as reasonable persons should not be held liable for harm suffered by others. In effect, accidents can always happen but only when a person violates his or her duty to act reasonably should liability attach.

Unfortunately, there will always be legal nuance to consider when defining reasonable actions --including defining a standard of care for the situation in question. Worse, the sad reality is that lawsuits are usually inevitable regardless of perceived fault. Still, the entire concept is one of the longest standing responsibility barometers in society. Simply put, the reasonable person standard gives people the ability to avoid black marks when they did not do anything wrong.

Regulations, certifications & standards
The next place to look -- and one that often serves as a default duty of care -- is the arena of regulations, certifications, and standards. To be certain there are already plenty that impact the cyber world such as PCI-DSS, ISO 27001, HIPAA, SANS 20 and many more. Some, like PCI-DSS for credit and debit card processing entities, are mandatory, at least with respect to avoiding fines and penalties. Others are voluntary and show that an organization is following a known methodology to manage cyber risk.

The bad news is that by relying on this approach exclusively (including the reality that compliance often merely establishes a minimum threshold) such methods can be easily learned by adversaries. Even more important, the majority of standards and requirements are mere snapshots in time, therefore none can be an exclusive remedy to the problem.

Financial reporting
The last area to consider is very well known to senior executives and boards of directors of public and private companies of all industries and sizes: financial reporting. It’s the most trusted means of providing shareholders and stakeholders with a snapshot of how an organization is performing at any point in time. Yes, it’s an imperfect methodology and from time to time firms will commit fraud in producing balance sheets, income statements and statements of cash flows.

On the other hand, it’s tough to argue that modern financial reporting is not only what has given rise to functioning markets but it has allowed the system to stand the test of time for nearly a century. Simply put, financial reporting provides a constant barometer on responsibility and externally verifiable insight on how an organization’s leadership is continually managing affairs.

Defining a duty of care for cyber risk.
Borrowing most heavily from the three-part schema for financial reporting, let’s propose that a cyber duty of care has been met by security and organizational leaders who can confidently, continuously, and affirmatively answer the three most critical cyber-risk questions:

  1. Do we understand our cyber exposure? 
  2. Are we managing our cyber risk as effectively as possible? 
  3. Do we have the ability and financial resources to fully recover from a cyber event?

The first question can be answered by conducting and at least annually refreshing an impact or quantification analysis that contemplates the entire range of first- and third-party financial and tangible exposures.

The second question can be answered by utilizing and frequently refreshing an appropriate cyber program maturity framework, and by ensuring that the firm’s insurance portfolio is tuned to its cyber exposure.

The answer to the third question is a function of the first two in that it reflects both the maturity of the firm’s incident response capabilities and the sufficiency of financial reserves and insurance to cover the impact of an event.

Ultimately, these are the three most critical questions that shareholders should ask of their boards, boards of their executives, and executives of their security leaders. In turn, all of those organizational leaders should be at the ready with answers, especially in the aftermath of a cyber event, when the proof will be in the determination of whether security leaders took their cyber-risk management responsibilities seriously.

If in fact, the organization executes its ability to recover and has the resources and insurance to minimize the financial impact, exculpability should be rightly achieved.

Related Content:

 

Scott Kannry is the Chief Executive Officer of Axio. Axio is a cyber risk engineering firm that helps organizations implement more comprehensive cyber risk management based on an approach that harmonizes cybersecurity technology/controls and cyber risk transfer. He is the ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
9/14/2016 | 1:30:22 PM
Re: Exec insulation from liability
@Whoopty: That's because it was a government organization and a screwup at high levels.

Had this been a company in the private sector -- especially a major company -- heads would have rolled and sacrificial lambs would have been offered to appeal regulators.

Regulators, heal thyselves!
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
9/13/2016 | 7:55:16 AM
Re: Exec insulation from liability
Yea it's actually quite interesting. That's been a big revelation as part of the investigation into the hack of the OPM, where the CIO just had so little knowledge on how to combat the attack, downplayed how bad it was and wasn't even culpable. That's one big change that's coming. 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
9/8/2016 | 4:18:55 PM
Exec insulation from liability
For the past couple of years, this has been a burgeoning issue in negotiating executive employment agreements, actually -- insulation from liability.  Indemnification language, D&O insurance, and the like are all subjects that are on the table now in the wake of headline-grabbing mega breaches.
Security's #1 Problem: Economic Incentives
Dimitri Stiliadis, CEO of Aporeto,  9/25/2017
SMBs Paid $301 Million to Ransomware Attackers
Dark Reading Staff 9/21/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.