Have you ever been asked to white-wash a security risk?
There are gradations of white-washing. At it’s worst, it can be an almost career-ending more, and put your certifications at risk.
At it’s least, it be using compensating controls.
Security risk should never be white-washed. I have had disagreements on the impact of a risk if it get exploited, and then we start the serious discussion on severity and impact to the organization. In most cases we came to an agreement after we discussed the cost to the organization, the impact to he business, and the harm to reputational damage of the organization. We start the remediation process to mitigate the risk.
Content you might like
Important solution for today’s way of working52%
Interesting idea to explore for 202242%
Not necessary6%
Communication48%
Listening49%
Foresight31%
Courage31%
Crisis management23%
Personal accountability23%
Honesty36%
Consistency19%
Continuous learning14%
Humility20%
Initiative13%
Relationship management10%
Cooperation8%
Other (please specify)0%
Yeah. That's exactly the experience for me across the companies I've worked at. The thing we qualify and quantify in a security risk council, then get white-washed by the enterprise risk management committee. I think the part that's interesting about this is that you can have a really strong mechanism around quantification and have a lot of data driven approaches around how you quantify that risk, but at the end of the day a lot of this comes down to qualitative analysis. You have to determine, is this as important as investing in two more stores in the northeast? Are we really going to get a certain reward by reducing the risk? You have to figure out who's a friend, who's a foe. Who understands that by downplaying this there is an impact beyond technology. I think the best thing that I've been able to do is get the CIO to understand the different variables beyond security, availability, reliability, resilience..bring some of those other data points. Because he's obviously in more meetings than I am with the executive team where he can prevent whitewashing.
In some of my previous roles, I had the luxury of growing up on the finance side and I helped create the enterprise risk map. It was easy for me to plug into it, and then contextualize cyber risk into the enterprise risk map. Why? Because I helped construct the damn thing. If the CISO, CSO is not an equal participant in the construction of the enterprise risk map, it will always be watered down.