Information Security Blog

What do Utilities and Oscar Wilde have in common?

What do Utilities and Oscar Wilde have in common?

0 Flares

0 Flares


×

Wilde is widely known for his masterpiece “The Importance of being Earnest,” written in 1895 … but it’s something else he wrote that relates to utilities in 2012 …

 

Last week we blogged on a Carnegie Mellon study that cited utilities as being among the least-prepared sectors with respect to risk management and executive knowledge of IT issues.  Assuming that conclusion is accurate, it’s hard to argue that there is less Information Security Governance in the utility sector than there should be.  The net result of insufficient governance is a lack of accountability for putting the necessary controls in place to reduce information security risk to a level that (should have been deemed) acceptable by executive management.  More succinctly, there is still a long way to go before we can call our grid “secure”.

I think there are two logical questions to ask on this issue (the first is far easier to answer than the second):

1.   Why are the utilities so far behind regarding risk management and executive knowledge of IT issues?

2.   What needs to happen for them to catch up?

 

Why are the utilities so far behind regarding risk management and executive knowledge of IT issues?

Information Security Risk Management (ISRM) tends to lag behind Enterprise Risk Management (ERM).  On the financial side we have seen Information Security Risk Management significantly improve as an extension of an increasingly sophisticated Enterprise Risk Management capability. Utilities have typically trailed in this area. In fact, in a 2011 study by Accenture the utilities industry was cited as having one of the lowest proportions of companies with an enterprise risk management program. Logically this makes sense: banks have been prime targets of physical attacks for hundreds of years and cyber security attacks for years while utilities are only just now realizing the growing threat of these risks.

 

What needs to happen for them to catch up?

The glass-half-full side of me thinks that the combination of increasing government regulation and growing recognition of the risk at the lower levels of the organization will bubble up to the CXO Suite – and ISRM will get the attention it deserves. The glass-half-empty side of me says that it will take a significant successful cyber-attack causing a massive outage weeks (or more) long to close the current ISRM gap.

 

 

Oscar Wilde once said, “The basis of optimism is sheer terror.” I could not have said it better.

 

0


Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

About the Author:

John Verry (CISA, 27001 Certified Lead Auditor, CCSE, CRISC) is Pivot Point's resident "Security Sherpa". He is lucky enough to spend most of his day helping clients develop a road map to address security, compliance, and attestation requirements.

Add a Comment

0 Flares Twitter 0 Facebook 0 Google+ 0 Pin It Share 0 LinkedIn 0 Reddit 0 StumbleUpon 0 Email 0 Email to a friend 0 Flares ×