putilov_denis - stock.adobe.com
How CISOs can use risk assessments to drive security culture
A strong security culture requires that executives and rank-and-file users understand why controls exist. A risk assessment can be a powerful tool for winning hearts and minds.
Organizations that take cybersecurity seriously conduct risk assessments to determine policies, practices and controls. Often, however, security teams keep the actual assessments to themselves, with their findings failing to reach a broader audience.
"A lot of times things communicated downstream are mistranslated; they get proxied through multiple layers of the organization," said TJ Patterson, vice president and information security officer at STAR Financial Bank. "It's like the telephone game."
When stakeholders on the business side never learn why security policies and controls exist, they see them as barriers to getting work done and take them less seriously. The result is often compliance failures and distrust of the security function.
That adds up to a significant missed opportunity, according to Patterson, who uses risk assessments to inform, drive and maintain the cybersecurity culture in his CISO role. Success, he said, lies in effectively framing and communicating risk assessments, translating them into business language and metrics, and reinforcing security-aligned behavior over time.
"The controls within a risk assessment are what people feel," Patterson said. And their feelings, whether positive, negative or ambivalent, ultimately drive security outcomes.
How to use a risk assessment to drive cultural change
"Cybersecurity has historically been seen as a compliance, check-the-box exercise," said Lauren Craig, associate partner at McKinsey's Cyber and Technology practice. "That's created a culture where everyone thinks that security does its own thing in a silo, [when it's] very much a shared responsibility."
As a security executive, Patterson uses risk assessments to reframe cyber-risk as business risk and improve internal cybersecurity culture. To do this, he recommended CISOs consider the following best practices.
Take the security culture's temperature
To understand their organizations' baseline security cultures, CISOs and their teams must do some legwork. Get out and speak with people in different areas of the organization, Patterson said, whether in structured interviews or ad hoc chats.
Ideally, added Lance Spitzner, director of Workforce Cybersecurity Training at SANS Institute, security teams also periodically conduct formal, large-scale surveys to understand how the workforce thinks and feels about security at a macro level.
Sell business stakeholders on the risk assessment
Communicate to stakeholders how cyber-risks and mitigations directly affect their areas of responsibility and their ability to achieve their goals. Patterson suggested using real-world anecdotes to show why non-security professionals should care about security controls. "I will find examples where someone managed risk in a healthy way, and I will find examples where they didn't," he added.
CISOs should also keep key business leaders, such as the CIO and chief risk officer, in the loop during and after an assessment, according to Craig. "Transparency throughout is key [to maintaining leadership buy-in], so it's not, 'Hey, we did a lot of preparation and never heard the response,'" she said.
Tie cyber-risk messaging to business consequences
Cybersecurity jargon can alienate users and make the security team seem out of touch, Craig cautioned. Frame cyber-risk in terms of business consequences to show that "it's not just an assessment for the assessment's sake."
Similarly, she added, raw security metrics typically mean little to those on the business side who lack the context to interpret them. Say, for example, a risk assessment shows that an organization has 10,000 unpatched vulnerabilities. A sales executive likely doesn't know -- or care -- if that number is relatively low or high, inconsequential or catastrophic. What matters to business leaders is how those vulnerabilities could affect the bottom line.
"People do not understand the 'why.' If you can explain the why in their terms and how it benefits them, they are far more likely to buy in," Spitzner agreed. "Where possible, we want to make security as simple as possible. The more motivated people are, and the easier the security expectations are, the more likely change happens."
Repeat security messaging
Security leaders often establish guardrails based on risk assessments and then leave department managers to communicate them down the ranks. This is not enough to make behavioral changes stick. People need to hear messaging repeatedly and in a productive, positive way.
Patterson, for example, hosts periodic lunch-and-learn sessions and other internal presentations that build on what managers have told their teams. "Then the dots start to connect," he said. "Now they're hearing a message reinforced by me that they may have heard from a proxy before. It's a lot of rinse and repeat from the leadership perspective, trying to push the [cybersecurity] culture."
Be accessible, approachable and adaptable
Patterson said he makes a point of regularly getting out and talking to people beyond his immediate department. "They see the human behind all this security. They start to recognize it's more than just technology," he said. "There are humans actually trying to solve and manage this risk."
Patterson said informal banter and relationship-building with employees has led them to alert him to suspicious cyberactivity. "That wouldn't have been possible had I not gone out into the organization and talked with folks," he added.
Treat guardrail failures as a business problem, not a people problem
Don't automatically punish employees for improper responses to controls. Instead, use those incidents as learning opportunities for both end users and the security team, referring back to the risk assessment.
If possible, uncover failures preemptively and drive home business impacts through regular simulations. "Related to risk assessments are things like tabletop simulation exercises that help to make the risk real," Craig said. Include key business stakeholders who heavily influence organizational culture.
Reward positive security behavior
Phishing controls are the most visible to rank-and-file users and therefore the most likely to create widespread positive or negative feelings toward cybersecurity, according to Patterson. With that in mind, he pays particular attention to them in risk assessments.
"I may find ways to enhance them so employees have a better experience [when they see the controls]," he said. For example, he might ensure users who report a potential phishing email receive a thank-you message from the security team. Conversely, failing to respond to users who properly report suspicious activities can discourage them from doing so again.
In addition to acknowledging individual contributions, celebrate security wins with the entire organization. Show how risk decreases as security culture improves by linking key metrics -- e.g., higher reporting rates and lower incident rates, attacker dwell times and policy violations -- directly to business outcomes.
Challenges to establishing a cybersecurity culture
Effective risk assessments and follow-on efforts to gain organizational buy-in always start at the executive level. If management and the board don't fully support the effort, it will be harder to get other stakeholders to take security seriously.
A CISO might get pushback because the organization has cyber insurance or has never had a breach -- creating the perception of minimal cyber-risk. In that case, the CISO must explain that past performance is not an indicator of future resilience. "I've never been in a car accident, but I still wear a seatbelt," Craig said.
At the employee and management level, CISOs will always have to grapple with people who, for whatever reason, don't want to adhere to security controls or policies. Patterson said he addresses these issues at the individual level but sometimes enlists help.
"I'll hear people complain about [a control], and that's where I'll find folks in their teams," he added. "If I can build a rapport with one person, that's usually enough to get the buy-in I need."
A security team's internal attitudes and culture can also pose a challenge if practitioners lose sight of the forest for the trees. "Sometimes cybersecurity professionals get caught up in 'don't click on this' or 'you need this piece of software to protect your environment,'" Patterson said. "It's very important for cybersecurity leaders to remember that we are in the risk management business and the people business, not just these individual technologies."
Perhaps the biggest challenge to establishing a cybersecurity culture is time, Spitzner said. "To influence and build a strong security culture takes years as you are changing the shared attitudes, perceptions and beliefs of your organization globally," he said. "The biggest influencers of your culture include leadership, your security team, your security policies and your security training. All of these have to work together to help influence that change."