Have you ever been asked difficult questions from your leadership teams that you couldn’t answer? How do you intelligently and succinctly respond to the following questions and have the supporting data to back up your metrics and business outcomes?
- Are we secure?
- When was our last security incident, how did we respond and will it happen again?
- Are our critical assets and data protected? If not, what will it take to add protective measures?
- We’re still compliant with all of our regulatory requirements, right?
Regardless of your role in compliance, risk management or information security, these questions can potentially trigger a mild case of anxiety or even a full on panic attack, depending on your organization’s level of control maturity. The way I see it, we have three choices:
- We can avoid questions like these all together by cowering under our desks or running the other way down the hall (virtual or physical hallway, that is)
- For all remote workforce members, please note that the mute button and webcam cover only hide you for about 5-10 seconds, tops, not that I’m speaking from personal experience, of course
- Piece together a response from a multitude of spreadsheets, meetings, emails, disparate SIEM tool reporting and vulnerability scanning data
- Face the questions with confidence and ease, armed with accurate supporting data and using minimal effort.
Obviously, option #3 is ideal and option #1 is not really an option, so we don’t recommend you try it! All joking aside, wouldn’t it be much more effective not only to have the answers to the tough questions, but also to automate the process of getting to those answers?
What if we took a more proactive approach instead of simply reacting and responding to emerging threats and incidents?