SMALL BUSINESS CYBERSECURITY

Simple, Easy to Follow Help
For the Small Business

Certified Information Systems Security Professional
ISC2 CISSP #473513 Since 2013

Home Credentials Coaching Contact

Clean Definitions

What is Cyber

What is Risk

What is a Threat

What is a Framework

What is the Cloud

What is a CISO or BISO

What is a decent Plan?

What is AI?



Resources

Measuring and Manageing Information Risk,
a FAIR Approach
1st Edition

Authors: Jack Freund and Jack Jones
Published by: Butterworth-Heinemann, Oxford, UK
2015
ISBN: 978-0-12-420231-3 (Paperback)

How to Measure Anything in Cybersecurity Risk

Authors: Douglas W. Hubbard and Richard Seiersen
Published by: John Wiley and Sons, Inc., Hoboken, New Jersey, USA
2023
ISBN: 978-0-11-1989230-4 (Hardback)
ISBN: 978-0-11-1989232-8 (ePDF)
ISBN: 978-0-11-1989231-1 (ePub)

What is a CISO?

CISO stands for Chief Information Security Officer. As you look around the business world you will see a wide variety of them, each having different backgrounds, knowing differnt things, leading in different ways, all depending upon their business's appetite and tollerance for risk. CISO does begin with the work "Chief" and ends with "Officer" but not all of them are currently included in board or senior leadership meetings. Most CISOs still take their instructions from the Chief Operations Officer (COO) or the Chief Information Officer (CIO), and report results back up through them, but they may also work under the Chief Technology Officer, or Chief Legal Council, depending on where the business leaders feel they would best to serve business's interests.

Do you need a CISO?

In short, "Yes, every business does," but let me qualify that. Every business needs a person where full responsibility for everything lies, including information security. As the owner, principal or president of the business, you know everything about the business and have the highest vested interest in its success. It is best that you are the CISO, even if information security is not something you know much about. Do not worry about what you don't know. No CISO knows everything. They hire specialists to cover those details. What is most important is that you fully understand what makes your business thrive. In practice, once the choices for information security for the business are explained, and once there is a solid discussion about the effects of each solution on each potential information security area to cover, you will be the best person to make CISO level descisions.

My purpose and goal is to introduce you to the tenets of information security to help you understand how each can affect your businsss productivity and processes. I will also try to help you determine the costs to secure your information and the possible costs if you don't. Most importantly, I do not sell products. I do not represent any particular manufacturer or vendor, but I have my favorites which I will use as examples. I also do not want to become your engineer to make it all work and last, but I can if you choose. I'd much rather train your existing IT personnel to take on the job. My real interest is to help you understand so that you make informed decisions. What I don't want is for you to spend too much money on something that you only need a little of, or to buy things that will hurt your business. I will help you work through it all. It is up to you, as the CISO, to decide what is best for your business.

For awareness sake, I will address the concept of a vCISO (Virtual Chief Information Security Officer). In my opinion, if you don't have an organization or budget large enough to hire a separate person as a CISO whose work time you 100% own, you don't want a virtual one whose work time you don't own. You own the business. You have the very best, clear understanding of what happens in it, why it happens, whether or not it should happen, and also what happens if things don't happen. No virtual person is going to intimately understand it like you do. They are not qualaified to make the correct choices. You, as the owner, principal or leader, are the best person for that.

What's a BISO?

If a business or organizaiton is large enough to have a Chief Information Security Officer, they should also have Business Information Securty Officers. BISOs are folks that each understand and take special care for the different sections of the business, such as Finance, Operations, R&D, Marketing, Training, and so forth. They specialize in these spaces so that they can fully understand why each wishes to do things the way they do, which leaves them quite capable of accurately determining the real business risk that happens when they do what they do or not. A good BISO doesn't take marching orders from the CISO. They counsel with them. They interface between business needs, business processes and information security to make sure that good money is not thrown after bad. They help see that the proper amount of risk is consistently handled in the proper way to protect the viability and longevity of the business. All the BISOs tell the CISO what is needed and then the CISO deduces (because they are hopefully going to C-Suite meetings) if it all makes good sense, based upon what they are privy to from the upper business leaders vision and comments.

As a small business, you probably won't have BISOs, but you may still have separate functions in your business that are run by specialists. For the sake of consistency and to get their buy into any changes of programs that you want to implement, it would be wise to have them at least participate in planning so that they can note or mention any areas affected that you may miss. In my experience, a few more sets of eyes on change is always a good thing, but not too many.

What is Cybersecurity Again?

At this point, it's OK to ask that again. My services are for the newcomer to business information security. I come to help you. I am an Information Security Coach, here to help the small and medium businesses leaders who want to do the right things to protect their business, their employees and their customers from bad things that can happen to and with data. I will learn your business information security needs from you. I will research what the current conditions and possibilities are. I will help you produce a true risk number. I will help you determine what has worked in the past, and what may work in the future. I will give you enough information to make the wise choices. I will help you create the policies, standards and procedures so that what you decide with me is repeatable and governable. Call me an Information Security Counselor, of you wish. My role is to help you understand, decide and get going in the right direction. There is nothing virtual about that.

Testimonials

NULL at the moment.

Please email ronald@weist.net to schedule an appointment to talk about your data (or, cyber if you must) security.