Please ensure Javascript is enabled for purposes of website accessibility

Risk assessments necessary for companies to protect systems, reputation

Risk assessments necessary for companies to protect systems, reputation

Listen to this article
Nelan

When Cheryl Nelan launched her business 10 years ago, cyber security was a side conversation for a business.  

“Today, it’s a primary conversation,” says Nelan, owner and president of CMIT Solutions of Monroe.  

Nelan and others agree that educating the C-level and board level about cyber risks and helping them take the best approach to protecting their assets is critical.  

There are so many risks facing companies that leaders may numb themselves to different the risks as a price of doing business, she says.  

The recent news of breaches at companies of all sizes in industries across the board, however, has opened the conversation.  

So has increased state and federal regulations and guideline on cyber security, such as New York’s Stop Hacks and Improve Electronic Data Security Act enacted in 2019 and the National Institute of Standards and Technology Cyber Security Framework, all aimed at helping companies manage and reduce cyber security risk.  

Not following these regulations could lead to fines or being turned down by cyber liability insurers if a breach occurs and the company did not have the steps in place to mitigate the risks, she says.  

“Companies are seeing the threat more and seeing it doesn’t just happen to big businesses,” she says. 

When speaking with a company’s leaders and board members, Nelan shares stories of what has happened to other companies similar to theirs.  

It’s important for business leaders to know where their company data is stored and how it is protected, she says, adding a focus is on showing them the risks and what they need to do to mitigate those risks. 

Ultimately, cyber security is a business decision, which involves a cost benefit analysis.  

“It’s about breaking the conversation down to different levels,” she says. “Our job is to help companies understand the costs and the risks so they can make informed decisions.” 

Mitigation efforts can range in price, depending on what needs to be protected and how much protection business leaders are seeking, Nelan says.  

Small- to mid-sized businesses now have more options to choose from when it comes to cyber security that are better and more affordable than was previously available, she adds.  

From a cost perspective, a company’s leaders can often wrap their arms around the losses incurred due to a breach.  

What can be more challenging is looking at more far-reaching consequences, such as what happens to a company’s customers if data is breached, which could result in a loss of trust from customers as well as negative press for the company. These impacts could be short-term or long-term.  

“It’s not just about mitigating risk,” she says. “It can also be the difference between a business growing and a business shutting down.”  

Montagliano

Michael Montagliano, chief of innovation at ProArch, says it is important to speak in business terms when talking with company leaders about cyber security. 

“You don’t walk into a board room with a highly technical presentation,” he says, adding there should be an emphasis on the financial impacts. “The bottom line for many businesses is ‘what is the cost?’”  

He also tailors his discussions based on who at the company he is speaking with, noting that a CEO may have different questions or views than a chief information officer or even a board member.  

Identifying and managing critical risks for a company is key, he says.  

“Cyber security isn’t a technology problem, it’s a risk and governance problem,” Montagliano says.  

He adds that internal audits and compliance are still primary drivers for business leaders when it comes to cyber security, but that is only the beginning of the discussion.  

Compliance regulations are usually asking companies to have the bare minimum safety controls in place, while audits want firms to show they have the controls, but not necessarily how well those controls protect them, Montagliano explains.  

“They need to stop thinking about simply ‘checking the boxes,’ and have good security hygiene in place to protect their most valuable assets,” he says.  

It is also important to talk to company leaders about the effect their firm may have on other companies, such as suppliers or vendors, especially if a breach occurs, because it may have a significant impact on them if their data was compromised as a result, he says.  

Fowler

Sitima Fowler, vice president of marketing at Iconic IT, says cyber security is part of a C-level executive’s duties to protect the company.  

Fowler says more firms are initiating conversations about cyber security and their options than ever before.  

Education is a critical part of the process, she adds, noting that many companies, especially small- to mid-sized businesses, have been overwhelmed with challenges during the pandemic.  

“It’s not that CEO’s or business owners are trying to be negligent, they just have so many compelling things coming at them at once,” Fowler says.  

She recommends companies first undergo a risk assessment, then implement a set of policies and procedures, followed by putting systems in place that align with those policies and procedures.  

Iconic IT has a one-page brochure it distributes explaining security practices businesses should at least have in place to protect from a cyber-attack, from firewalls and multifactor authentication, to security training for employees and a backup/continuity/disaster recovery plan.  

There are also new technologies being introduced which businesses can add to their cyber security toolboxes, she says. That includes antivirus software that uses artificial intelligence to identity and flag suspect internal and external correspondence.  

If a business does have a breach, the consequences can extend beyond the cost of paying the ransom, she says.  

Other areas that can be impacted include the time systems going down and a blow to a firm’s reputation, especially if customers’ data is affected and they find out the business did not have the appropriate risk mitigation factors in place.  

“A breach is horrific,” she says. “It’s not just a financial burden, but it’s also the loss of systems for a long period of time, which a company may never get back. It’s so much easier to plan ahead of time as part of the risk assessment.”  

Andrea Deckert is a Rochester-area freelance writer. 

l