|
SMALL BUSINESS CYBERSECURITY Simple, Easy to Follow Help Certified Information Systems Security Professional |
| Home | Credentials | Coaching | Contact |
|
Clean Definitions What is CyberWhat is Risk What is a Threat What is a Framework What is the Cloud What is a CISO or BISO What is a decent Plan? What is AI? Resources
Measuring and Manageing Information Risk,
Authors: Jack Freund and Jack Jones
How to Measure Anything in Cybersecurity Risk
Authors: Douglas W. Hubbard and Richard Seiersen |
What is Risk? Defining risk can be a contentious subject, depending on who you talk to. Risk is a calculation of the potential financial impact of a threat, considering all factors, including the true likelihood of it recurring over a given period of time. Risk is not a feeling. It's the answer to an algebraic equation. It is like a statistic. Threat is not the same as risk, although some people incorrectly use them interchangebly. Threat is only a part of risk. Discussing risk Risk should be measured and discussed in monetary values. It should not be simply Low, Medium or High, unless those terms are referencing known monetary values, relevent to the business. Monetary values are used because they are a common unit of measure used by various businesses to measure things that are not so related, such as life, limb, fines, property, reputation, insurance, and so forth. Therefore, to relate information security risk to other risks, we should use the same, standard unit of measure. When thinking about risk, it is often good to have a comparable example to keep things grounded. A meteor strike to your house or town is far fetched, but the injury of a fellow employee by a car accident is not. Everyone knows that driving anywhere has threats of an accident. Every day, many people get into car accidents, and every day, someone dies from a car accident. However, employers request us to go to the office and we keep driving, even though there is some risk. This is because the actual risk value of an accident or death by driving in a car is far less than the risk to the business by us not collaborating so well. Perhaps this is why many businesses pay for a base level life insurance policy for their employees. Calculating a Risk Appetite How much risk can you swallow before you feel ill? How much financial loss can your business accept before you no longer have a business? I cannot calculate your business risk appetite until I really understand your business and exactly what worries you about it. I cannot calculate your risk until I fully understand all that goes into everything that you and your workers do. Calculating the risk appetite for your business is something that I can help with, using something close to the FAIR Institute's comparative approach. A rough approximation of calculating risk for business information is this: Consider the things that make money for your business. Those are the threat targets. Consider what might take those income streams away. Consider what it might take to recover them back into money makers if something were to happen to them. Look at paying all the people who need to be involved and any fines, lawsuits and reparing of reputational damage that might happen. That is your incident cost and recovery cost, or the total possible cost of the threat. You will also need to calculate what it would cost to protect the devices from those threats to keep from losing the money in the first place. We will use that number later on in the next paragraph, so save it. Looking at the total cost of the threat is only part of the risk value. You have to find the percentage likelihood that the threat even happens. You do this by looking at your company's or a similar company's statistics for that type of threat. Keep in mind that if you do things different than the other businesses (hopefully better), your likelihood or threat impact may be lower. Multiply the total possible loss of the event times the percentage likelihood in times per year, month or day, and that is the cost per year, month or day to handle the threat. You will now break up the cost of mitigation by the same period (year, month or day) and see if it is less expensive to mitigate than the cost of just letting the threat possibly happen to your money making activity for the same time period . When it costs less to mitigate a threat than the money the business acivity can bring in, that becomes part of the choice. You must also calculate whether the cost to mitigate the threats is less than the possible losses, amortized out over the year, month or day time period than if you choose to not mitigate. If it costs more per time period to mitigate than you may possibly lose if unmitigated, you may want to make some changes. You might also buy insurance for the threat impact, if an agency will sell you a policy. You may want to totally eliminate the possibility of the threat by stopping the particular business activity. You might also choose to accept the risk and do the activity anyway, crossing your fingers that it will all be okay. The choice you make is a reflection of your risk appetite for that particular threat type. Other theats to consider may be similar, so the next calculation will be easier. Here is the key: WRITE DOWN EXACTLY WHAT YOUR CHOICE IS FOR THE NEXT TIME AND WHY. This will help others to react the same for a similar problem later. It will also help you evaluate later if you need to change from what you thought was the correct way to handle it. We call this written document a standard. The policy would be to not accept too much risk to the business. The standard(s) tell everyone what is acceptable to comply with the policy. If you choose to just accept the risk, that becomes a risk acceptance and you should very carefully track those to make sure that a number of them don't eventually add up to much more than you think is wise to bear. Confused? If all that left you confused, think over this: How much does it cost to sell your goods and services today without any security? How much would it cost with the security? How much will you potentially lose without the security? How much will you potentially lose with the security. Adding the security costs up, over a series of five years should not take away more profits than flying totally wide open in the wind if you got hit by information security events over the same five years. If it costs more to protect than you may lose totally unprotected, you are wasting money. Your larger risk is in spending the money to protect yourself, instead of how it normally is with spending money allowing you to save more because you are secured from rogue losses. |
Testimonials
NULL at the moment. |
Please email ronald@weist.net to schedule an appointment to talk about your information (affectionately called cyber) security.