In a recent article on TechRepublic, researchers at the University of Arizona’s Artificial Intelligence Laboratory described their ongoing study into the operations, interactions and communications of the hacker community. Specifically, researchers noted how organized they are, how tight-knit their community is and how they “always have and always will change things up.” Sound familiar?

Cybercriminals do not necessarily have a formally written framework under which they operate, but it may be surprising to learn that they are organized around some modus operandi. This is deeply cultural, social and unstructured, and it is effective in achieving their objectives.

Establishing a Modus Operandi for Security

As an IT or security leader with strong governance policies and increasing pressures thanks to compliance, business innovations and workforce behaviors, you cannot rely on fixed technology responses to navigate the security minefield. Simply throwing more security technology at a growing problem is like reaching for a simple ibuprofen for a migraine headache: It only provides temporary relief and doesn’t cure the underlying cause. In security, it is important to understand the context and critical interdependencies that put your organization at risk and then set your priorities and guiding principles accordingly.

Thinking about security from the perspective of modus operandi and working with a framework that delivers the guidance and principles behind decision-making helps leaders. Everyone in the organization is better equipped to navigate through the toughest of changes, growing business needs and, most of all, cyber dangers.

At IBM, we work with clients to adopt a framework called 10 Essential Security Practices in which we assess security capabilities, readiness and maturity. Then we develop a profile for security governance and processes, helping clients to establish long-term programs.

Essential Security Practices to Consider

The 10 essential security practices are designed to be the modus operandi for security and IT leaders. The framework encourages professionals to assess and develop appropriate strategies based on:

  1. A risk-aware culture;
  2. The establishment of intelligent security operations and rapid threat response;
  3. Secure collaboration in the social and mobile workplace;
  4. The development of security-rich products and applications by design;
  5. A hygienic approach to securing systems and infrastructure;
  6. The creation of a security-rich and resilient network;
  7. Best practices for addressing security complexities in the cloud and virtualization technologies;
  8. The careful management of third-party security compliance;
  9. Assuring data security and privacy; and
  10. How to manage the digital identity life cycle.

Conclusion

To operate cybersecurity as a true enterprise function, organizations need a framework within which to establish their security program, understand the context and critical interdependencies of initiatives and set priorities accordingly. Such a framework can also be used to identify gaps, monitor progress and achieve other strategic security objectives. This is all done while ensuring security programs are fully coordinated with an organization’s core business objectives and initiatives.

Are you ready to adopt a framework and prioritize a long-term plan for your security capabilities, readiness and maturity? Watch this video series about the 10 essential security practices to learn more.

More from CISO

Do You Really Need a CISO?

2 min read - Cybersecurity has never been more challenging or vital. Every organization needs strong leadership on cybersecurity policy, procurement and execution — such as a CISO, or chief information security officer. A CISO is a senior executive in charge of an organization’s information, cyber and technology security. CISOs need a complete understanding of cybersecurity as well as the business, the board, the C-suite and how to speak in the language of senior leadership. It’s a changing role in a changing world. But…

2 min read

What “Beginner” Skills do Security Leaders Need to Refresh?

4 min read - The chief information security officer (CISO) was once a highly technical role primarily focused on security. But now, the role is evolving. Modern security leaders must work across divisions to secure technology and help meet business objectives. To stay relevant, the CISO must have a broad range of skills to maintain adequate security and collaborate with teams of varying technical expertise. Learning is essential to simply keep pace in security. In a CISO Series podcast, Skillsoft CISO Okey Obudulu recently said,…

4 min read

The Needs of a Modernized SOC for Hybrid Cloud

5 min read - Cybersecurity has made a lot of progress over the last ten years. Improved standards (e.g., MITRE), threat intelligence, processes and technology have significantly helped improve visibility, automate information gathering (SOAR) and many manual tasks. Additionally, new analytics (UEBA/SIEM) and endpoint (EDR) technologies can detect and often stop entire classes of threats. Now we are seeing the emergence of technologies such as attack surface management (ASM), which are starting to help organisations get more proactive and focus their efforts for maximum…

5 min read

How the Talent Shortage Impacts Cybersecurity Leadership

4 min read - The lack of a skilled cybersecurity workforce stalls the effectiveness of any organization’s security program. Yes, automated tools and technologies like artificial intelligence (AI) and machine learning (ML) offer a layer of support, and bringing in a managed security service provider (MSSP) provides expertise that isn’t available in-house. But it isn’t enough, especially for the medium-sized businesses that would most benefit from an internal security team. However, the talent shortage doesn’t just impact present-day security concerns. The lack of a…

4 min read