{"id":31946,"date":"2018-05-17T12:21:11","date_gmt":"2018-05-17T04:21:11","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=31946"},"modified":"2018-05-17T12:21:11","modified_gmt":"2018-05-17T04:21:11","slug":"opinion-cybersecurity-for-the-fourth-industrial-revolution","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2018\/05\/17\/opinion-cybersecurity-for-the-fourth-industrial-revolution\/","title":{"rendered":"OPINION | Cybersecurity for the Fourth Industrial Revolution"},"content":{"rendered":"<div id=\"attachment_31947\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/05\/Alvin-Rodriguez.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-31947\" class=\"size-medium wp-image-31947\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/05\/Alvin-Rodriguez-300x263.jpg\" alt=\"\" width=\"300\" height=\"263\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/05\/Alvin-Rodriguez-300x263.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/05\/Alvin-Rodriguez-768x672.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2018\/05\/Alvin-Rodriguez.jpg 1024w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-31947\" class=\"wp-caption-text\"><strong><em>Alvin Rodrigues, Chief Security Strategist, Asia Pacific at Fortinet<\/em><\/strong><\/p><\/div>\n<p><strong><em>By Alvin Rodrigues, Chief Security Strategist, Asia Pacific at Fortinet<\/em><\/strong><\/p>\n<p>The\u00a0<a href=\"https:\/\/www.weforum.org\/agenda\/2016\/01\/the-fourth-industrial-revolution-what-it-means-and-how-to-respond\/\">World Economic Forum<\/a>\u00a0and other business analysts increasingly recognize that the world is currently undergoing its fourth industrial revolution. The first industrial revolution kicked off in the 18th\u00a0and 19th\u00a0centuries with the harnessing of steam and waterpower to replace human labor and mechanize transportation. In the second industrial revolution, assembly line and conveyor belt manufacturing methods enabled mass production, radically increasing the quantities and lowering the price of goods available in the marketplace. From the 1970s to the year 2000, the third industrial revolution\u2019s proliferation of computers and automation technologies revolutionized almost every economic process\u2014from manufacturing, to management, to mass media and entertainment.<\/p>\n<p>The fourth industrial revolution arrived with the advent of the 21st\u00a0century. Even as I write, it is transforming information technology into an artificially intelligent, pervasive, and autonomous source of economic value creation in its own right. In other words, information technology no longer\u00a0<i>supports<\/i>\u00a0the business, it\u00a0<i>is<\/i>\u00a0the business.<\/p>\n<p><b>Your Business Transformed, Ready or Not<\/b><\/p>\n<p>As with all previous industrial revolutions, no public or private organization will be immune from the fourth industrial revolution. Organizations that ignore it will end their existence, bewildered in bankruptcy court. If you don\u2019t radically transform your business, you will find yourself choking in the dust left behind by your competitors or completely unexpected market disruptor organizations (e.g., the Apples, Googles, Amazons, and Craigslists of the world.)<\/p>\n<p>Digital transformation is inevitable. Resistance is futile. The mindset of if it is not broken, do not fix it does not apply in this new era. Digital transformation is revamping and changing the way we do business, the way we operate, the way we engage with our customers, the way we deliver value, and in so many other ways and areas. Existing IT infrastructure and a legacy security mindset are heavily challenged as a business evolves.<\/p>\n<p>Existing companies are burdened with legacy infrastructure, and they must find a way to marry it as harmoniously as possible with new technologies, increasing the already complex environment that is integrated across every part of the business.<\/p>\n<p>Organizations face three main species of risk. The biggest risk involves not moving fast enough to seize new opportunities and adopt new, hyper-automated processes. The second risk involves making bad investment decisions regarding which technologies to acquire or develop, which people to hire, and which firms to establish ecosystem partnerships with. The third risk, and the one I will discuss in more depth in this blog post, revolves around cybersecurity.<\/p>\n<p><b>Dissecting Cybersecurity Risk Factors<\/b><\/p>\n<p>Cybersecurity business risks can take several forms:<\/p>\n<ul>\n<li>Operational Risk.\u00a0Exploits such as ransomware, denial-of-service (DDoS), data theft, site hijacking, and resource theft can seriously disrupt business operations. Some disruptions might only interfere with internal operations and processes. Others, such as DDoS attacks and site hijacking, can become sources of brand damaging public embarrassment.<\/li>\n<li>Reputation Risk.\u00a0Customers, investors, and partners will avoid doing business with any organization that exposes them to potential harm. Some incidents are directly visible to stakeholders when they interact with your organizations. And reputational damage can mushroom when incidents become public news events, either through journalistic reporting or regulation compliance-triggered public disclosure.<\/li>\n<li>Investment Risk.\u00a0This consists of overinvesting in security products that either do not work, don\u2019t integrate with other products in the environment, or protect assets and processes that really don\u2019t matter to the business. Remember, every dollar squandered on subsidizing inefficiencies or defending non-essential value generation factors is a dollar that could be invested more productively elsewhere.<\/li>\n<\/ul>\n<p>Not all security products are created equal. Companies must be aware of issues relevant to their new, extended and complex infrastructures, such most siloed products cannot communicate with other security devices, making collecting and correlating threat intelligence to detect advanced threats hiding in your extended attack surface difficult if not impossible. Likewise, poor documentation, lack of skilled resources, and limited budgets, combined with intense pressure from management to stay in step with business changes, often seduce technology professionals into taking shortcuts and not conducting proper evaluation on what products to retire and what products to extend.<\/p>\n<p><b>Strategic Focus on Vulnerabilities<\/b><\/p>\n<p>The first step in overcoming these risks is to realize that attempting to defend against every contingency is to defend against none of them. Effectively managing cybersecurity risks requires shrewd assessment of what\u2019s important to your business, determining how and where \u201ccrown jewels\u201d are vulnerable to attack, and what means should be deployed to protect them. Two sets of questions pertain to this process.<\/p>\n<ul>\n<li>Where is your enterprise vulnerable to cybersecurity disruption across its value chain?\u00a0By building up an inventory of vulnerabilities, enterprises gain a picture of what cybersecurity professionals call an \u201cattack surface.\u201d One of the interesting aspects of the attack surface concept is that it is really about how potential adversaries see your enterprise as a potential target, both in terms of what\u2019s worth misappropriating and how to get their hands on it.<\/li>\n<li>What are priorities for investment to shore up vulnerabilities against attack?\u00a0Setting priorities is a question of timing and involves questions such as, \u201cWhich vulnerabilities does one address first?\u201d Investment is a business decision revolving around what are the most cost-effective ways and means to address value chain-critical vulnerabilities.<\/li>\n<\/ul>\n<p>Prioritizing investments to address vulnerabilities hinges on developing a heat map depicting the probabilities of attack and potential impacts to the business. Vulnerabilities can manifest themselves in people, process, and technology. However, identifying where these vulnerabilities are located within the entire spectrum of business operation, ranging from very critical to non-critical, is just as critical, as this can serve as a guide for organizations in deciding what needs to be addressed first. Correlating vulnerabilities to a company&#8217;s attitudes towards risk provides additional clarity on priority setting. These sorts of exercises not only help organizations effectively factor security into their overall risk management strategy, but often also result in the realization that cybersecurity is not a technology discussion, but a business risk\/reward\/investment calculation.<\/p>\n<p><b>What to Do Now<\/b><\/p>\n<p>Whatever you do, do\u00a0NOT\u00a0skip ahead to ask, \u201cWhat should we buy to solve our problems?\u201d At this point, the question is, \u201cHow do we quickly and decisively come to grips with evaluating our organization\u2019s security posture and set course for needed changes?\u201d As every company is at a different stage in its security maturity, each needs to take a step back and evaluate what tools and processes are currently in place, what your business goals and strategies are, and then understand what are you protecting and why.<\/p>\n<p>At this point, I highly recommend taking a business-focused approach to cybersecurity by first understanding your company: how it is structured, what its business model is, and what its business operations include. From there, you can begin to identify the critical \u201ccrown jewels\u201d components and activities that deliver your company&#8217;s unique value proposition.<\/p>\n<p>These considerations will guide where to prioritize spending. In parallel with this business strategy exercise, examine what is going on in your company&#8217;s network. This should provide visibility into processes and workflows, and help you gain a sense of what constitutes normal behavior in your network. By identifying the normal, abnormalities are much easier to see, allowing organizations to discover potential new threats lurking in the network. Such measures enable an organization to build an effective and comprehensive security strategy and deploy appropriate solutions \u2013 designed around critical functions such as integration, collaboration, adaptability, and automation \u2013 that lead to effectively protecting those business processes essential to the success of the business.<\/p>\n<p>To begin the process of aligning cybersecurity investments with an enterprise\u2019s overall business strategies, I strongly recommend a couple of Fortinet-published whitepapers on strategic cybersecurity decision-making\u2014<a href=\"http:\/\/demand.fortinet.com\/LP=2684?source=Website&amp;sfdccampaignid=70134000001XvW4&amp;elqemail=4673&amp;elqtyp=1876&amp;elqlist=4015&amp;utm_medium=website\">A Security Leaders Guide to the Threat Landscape<\/a>\u00a0and\u00a0<a href=\"http:\/\/demand.fortinet.com\/LP=2827?source=Website&amp;sfdccampaignid=70134000001XvWJ&amp;elqemail=4898&amp;elqtyp=1876&amp;elqlist=4229&amp;utm_medium=website\">Rethinking Your Approach to Cybersecurity<\/a>.<\/p>\n<p><b>\u00a0<\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Alvin Rodrigues, Chief Security Strategist, Asia Pacific at Fortinet The\u00a0World Economic Forum\u00a0and other business analysts increasingly recognize that the world is currently undergoing its fourth industrial revolution. The first industrial revolution kicked off in the 18th\u00a0and 19th\u00a0centuries with the harnessing of steam and waterpower to replace human labor and mechanize transportation. In the second [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":31947,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[495,169,286,2474],"class_list":["post-31946","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-cybersecurity-and-cybercrime","tag-fortinet","tag-it-security","tag-opinion"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31946","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=31946"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/31946\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/31947"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=31946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=31946"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=31946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}