Entering the Era of Insecurity (for politics and digital)

We all feel that we are entering in an “Era of Insecurity”.

The complex international geopolitical context, most countries focusing on their own protection and economy, closing many of their boundaries and reactivating visas, happens at the detriment of multiple alliances, associations, joint efforts, works, thinktanks and standards established between countries.

I recommend reading the following great article from IISS organization which summarizes it all :

https://www.iiss.org/publications/the-military-balance/2024/chapter-1-era-of-insecurity/

Whether this is natural and could have been expected or it’s a preliminary signal of extreme tough times to come, or both at the same time, there is a need for all of “us” to ensure “our” own protection and prepare for resilience.

When I say “us”, it could be Europe, France or other countries, one or several business verticals, and even at personal (and family) level.

I believe you all know this quote :

โ€œHard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.โ€

G. Michael Hopf (Those who remain)

Well, I very strongly believe in it. And what we currently observe in Europe is, I believe, resulting from the good times that all of us have welcomed.

A couple of years ago, I heard the Head of an Intelligence Service state the following :

“Happy times between the 2 wars, when we could travel, live, invest, work everywhere is now over. And I’m not talking about WW1 and WW2โ€ฆ”

This second article also describes the evolution of the European Cyber Defense, mainly through:

  • Sharing of intelligence data
  • Securing communications
  • Increasing investment in Signal Intelligence (SIGINT)
  • Increasing investment in electronic warfare

So, what does it mean for us, and particularly for Cyber warfare ?

It means that regulations at country and european levels will continue to evolve, drastically. It means that the established trust between countries and organizations will be even more at stake. It means that we must not consider that security is at no cost, that we must educate, train, test the level of prepareness of our kids, students, employees and partners.

It also means that it’s time to consider that all countries, all people, all verticals are concerned. Not just some of them that are involved in legacy warfare. We must be vigilant as if our country was already in the state of war. To avoid attacks and impacts.

Remaining alliances (even between countries) will need to agree on some common rules – and enforce them for real. Those alliances will require their members to trust each other, up to a point that has hardly been reached before. And avoid contradictory rules or inconsistent levels of controls / audits. Piling up different layers of “sovereignty” or trust will inevitably impact the performance at the worst possible time (the need for competition is extreme during tough timesโ€ฆ). To say it differently, living close to a powerful neighbour requires to have common interests, ideology, culture and fears.

I have the feeling that NIS2 and DORA are only the emerging parts of such upcoming regulations. However, the difficulty is that it defines both “a target” level of protection and a minimum one, leaving up to the various companies how to apply the so-called “proportionality principle” and how to harmonize the resulting policies and controls.

In such context, the introduction of Governance, Risk & Compliance (GRC) solutions will also become critical, for various reasons:

  • Document how organizations manage the various risks and what are the critical systems to consider
  • Ensure consistency within a vertical
  • Cover the entire supply chain, whatever the size and level of maturity of suppliers
  • Automate continuous monitoring to demonstrate that the controls described in the policies are effectively enforced
  • Break the silos between various departments, to ensure maximum efficiency and effectiveness
  • Publish, via a “Trust Center” the most tangible evidences that companies consider their protection and resilience with due care
  • Add other frameworks of compliance in the future, without having to rebuild everything from scratch and disrupt the ongoing strategies and tactics.

I have invested a lot of my time in studying those solutions, as well as how to transform companies’ cybersecurity mindset, decision-making processes. And I have the feeling that above all the technologies engaged, strong leadership, governance, prepareness and anticipation will remain at the heart of our effective resilience.

To conclude, I have the feeling that we are making decisions now that will strongly impact our future and hopefully our ability to return to “happy times” as soon as possible. Educating our children, with proper values and despite what we all hear at the news remains critical. I strongly adhere to the statement that we should start by caring for the mindset of the people that will leave in tomorrow’s world if we care for the world they’ll leave in.

In other words:

“Many will not understand, but we have to raise warriors”

Aaron McKie, John Chaney

We could also recap by saying :

“Prepare for the worst, hope for the best”

Maya Angelou

L’รฉvolution des Rรฉglementations de CyberSรฉcuritรฉ en Europe (incluant RGPD, CyberSecurity Act, NIS, DORA, etc.)

Contexte

Les Responsables de la Sรฉcuritรฉ des Systรจmes d’Information (RSSI) ont plusieurs contraintes ร  prendre en compte lorsqu’ils construisent leur feuille de route Cyber : entre les plans d’action suite aux audits, internes comme externes (incluant dรฉsormais les investigations des Cyber-Assurances), les actions correctrices suite aux incidents dรฉtectรฉs, et les actions nรฉcessaires aux conformitรฉs rรฉglementaires et contractuelles, la marge de manล“uvre des RSSI pour รฉtablir cette feuille de route est trรจs faible.


Disposer de mรฉtriques

Comprendre le niveau de protection rรฉel

Par ailleurs, et depuis plusieurs annรฉes, les Exรฉcutifs des diffรฉrentes sociรฉtรฉs s’enquiรจrent de leur niveau rรฉel de protection. Lorsqu’ils sont rassurรฉs par leurs รฉquipes, via une gouvernance et des tableaux de bord appropriรฉs, tout va bien. Si ce n’est pas le cas, ils cherchent des certifications, des validations “externes et objectives”. S’ils n’en trouvent pas, ils missionnent l’audit interne pour approfondir. Faute de rรฉsultat probant, ils finissent par missionner un audit externe, le plus souvent un “Red Team”, en informant, ou non, leurs รฉquipes opรฉrationnelles. Ce n’est d’ailleurs, pas la meilleure maniรจre de procรฉder, loin s’en faut : il serait prรฉfรฉrable d’entraรฎner les รฉquipes internes, via des Blue Teams, avant de simuler le comportement des pirates.

Reste que les partenaires et les clients, eux, ne se suffisent pas du rรฉsultat de ces audits. D’ailleurs le plus souvent, l’entreprise ne peut communiquer leurs rรฉsultats.


Les rรฉglementations de CyberSรฉcuritรฉ

L’รฉmergence des rรฉglementations

D’oรน l’intรฉrรชt d’avoir des rรฉglementations qui, elles, fixent le niveau de protection ร  atteindre, y compris jusqu’aux aspects les plus opรฉrationnels. Cela permet, d’une part, de fixer des rรจgles “homogรจnes” ร  l’ensemble d’un secteur d’activitรฉ, mais aussi de contraindre, par la loi, l’entreprise ร  s’y conformer.

Il y a plusieurs dizaines d’annรฉes, les rรฉglementations รฉtaient davantage destinรฉes ร  fixer les sanctions relatives ร  des activitรฉs prohibรฉes. C’รฉtait notamment le cas de la cรฉlรจbre Loi Godfrain du 5 janvier 1988.

Si la loi Informatique et Libertรฉs fixe quant ร  elle, dรจs 1978, un cadre lรฉgislatif relatif au traitement de donnรฉes personnelles, le RGPD (Rรจglement Gรฉnรฉral sur la Protection des Donnรฉes) adoptรฉ au Parlement Europรฉen le 27 avril 2016 marque un tournant pour plusieurs raisons :

  • D’une part il est beaucoup plus prรฉcis sur les aspects opรฉrationnels relatifs ร  la protection des donnรฉes ;
  • D’autre part il est รฉtabli ร  l’รฉchelle europรฉenne et non nationale ;
  • Enfin ses sanctions sont beaucoup plus lourdes pour les contrevenants : les amendes peuvent atteindre jusquโ€™ร  20 millions dโ€™euros ou 4 % du chiffre dโ€™affaires annuel mondial de lโ€™entreprise, le montant le plus รฉlevรฉ รฉtant retenu. Il prรฉvoit รฉgalement des sanctions pรฉnales pouvant รชtre appliquรฉes, incluant des amendes pouvant aller jusquโ€™ร  300 000 euros pour les personnes physiques et 1,5 million dโ€™euros pour les personnes morales, ainsi que des peines dโ€™emprisonnement pouvant aller jusquโ€™ร  5 ans.

L’importance de la Dรฉfense Nationale

De mรชme, en France, la Loi de Programmation Militaire promulguรฉe le 18 dรฉcembre 2013, a mis un accent particulier sur la cybersรฉcuritรฉ, reconnaissant lโ€™importance croissante des menaces numรฉriques. Cela incluait le renforcement des capacitรฉs en matiรจre de cyberdรฉfense. Elle concerne principalement les Organismes d’Importance Vitale (OIV) et fixe les orientations politiques de la Dรฉfense Nationale, mais elle prรฉvoit รฉgalement des ressources budgรฉtaires sur la pรฉriode 2014-2019. La LPM 2019-2025 qui lui a succรฉdรฉe, adoptรฉe en juillet 2018 a confirmรฉ l’importance de protรฉger le cyberespace contre les dรฉfis futurs et celle relative ร  la pรฉriode 2024-2030 รฉgalement.

A l’รฉchelle europรฉenne, la directive NIS V1 s’inspire directement de la LPM franรงaise et partage avec elle un objectif commun d’amรฉlioration de la CyberSรฉcuritรฉ, et de rรฉsilience des systรจmes critiques. Cependant, elle cible les Organismes de Service Essentiels (OSE) ร  travers l’ensemble de l’Europe. L’objectif sous-jacent est de protรฉger tout autant les grandes entreprises que leurs plus petits fournisseurs et sous-traitants, qui peuvent รชtre ร  l’origine des intrusions chez leurs partenaires et clients.


L’รฉvolution des rรฉglementations dans le temps

Depuis, les rรฉglementations relatives ร  la CyberSรฉcuritรฉ n’ont cessรฉ de se renforcer trรจs nettement. Plus d’exigences, plus prรฉcises et opรฉrationnelles, concernant plus d’entreprises, et assorties de contrรดles et de sanctions plus drastiques. C’est une vรฉritable tendance de fond, pas un effet de mode.

La directive NIS V2 succรจde ร  NIS V1 en 2022. Non seulement elle accroit considรฉrablement le nombre d’entreprises concernรฉes, mais elle distingue les Entreprises Essentielles des Entreprises Importantes pour ajuster les contraintes qui leur incombent. Ses mesures plus strictes sur la gestion des risques cyber en gรฉnรฉral mais aussi ceux liรฉs aux fournisseurs et sous-traitants, des incidents de cybersรฉcuritรฉ, de la sensibilisation et la formation des utilisateurs et de la rรฉsilience opรฉrationnelle dรฉmontrent le besoin de dรฉfendre davantage l’ensemble des entreprises contre les cybermenaces.

Elle met un cadre de gouvernance beaucoup plus structurรฉ, avec des autoritรฉs nationales renforcรฉes et une coopรฉration accrue entre les Etats membres.


DORA, lex specialis au secteur financier

La spรฉcialisation aux secteurs d’activitรฉs

La rรฉglementation DORA (Digital Operational Resilience Act) est une lex specialis de NIS V2. Il s’agit donc d’une spรฉcialisation de NIS V2 au secteur financier europรฉen. Toutefois, DORA met l’accent sur la rรฉsilience opรฉrationnelle face aux risques numรฉriques, la continuitรฉ des opรฉrations, la rรฉsistance aux perturbations.

Les sanctions applicables restent trรจs รฉlevรฉes. Par exemple, pour NIS V2, cela peut aller jusqu’ร  2% du chiffre d’affaires annuel mondial des entitรฉs essentielles et 10 millions d’euros (le montant le plus รฉlevรฉ s’appliquant).

A noter รฉgalement que la rรฉglementation NIS V2 prรฉvoit des injonctions de mise en conformitรฉ, la suspension temporaire des activitรฉs, et mรชme lโ€™interdiction pour les dirigeants dโ€™occuper des postes de direction en cas de non-conformitรฉ grave. DORA prรฉvoit mรชme la cessation temporaire ou dรฉfinitive de toute pratique ou conduite jugรฉe contraire ร  son contenu.

Si NIS V2 nรฉcessite, pour certains articles une transposition dans les lois nationales, ce n’est pas le cas de DORA, ce qui lui garantit une application uniforme ร  travers l’UE.


L’รฉvolution en Europe comme ร  l’International

Le CyberSecurity Act, entrรฉe en vigueur le 27 juin 2019 au sein de l’Union Europรฉenne, renforce quant ร  lui le rรดle de l’ENISA (Agence de l’Union Europรฉenne pour la CyberSรฉcuritรฉ), introduit un cadre de certification et des exigences europรฉennes sur les produits, services, et processus. Il permet donc aux entreprises de se doter de fournisseurs et technologies plus “sรฉcures”.

A l’รฉchelle Internationale, on constate รฉgalement un renforcement de l’ensemble des rรฉglementations relatives ร  la CyberSรฉcuritรฉ. On peut citer notamment :

  • La Loi sur la CyberSรฉcuritรฉ de la Rรฉpublique Populaire de Chine, entrรฉe en vigueur le 1er juin 2017,
  • La Loi pour la Protection des Donnรฉes Personnelles (PIPL) รฉgalement en Chine, entrรฉe en vigueur le 1er novembre 2021,
  • La California Consumer Privacy Act (CCPA) entrรฉe en vigueur le 1er janvier 2020 aux ร‰tats-Unis,
  • etc.

On voit bien que cette รฉvolution croissante et permanente des rรฉglementations de CyberSรฉcuritรฉ est donc un phรฉnomรจne mondial.


L’impact pour les entreprises

Mais toutes ces rรฉglementations introduisent donc autant de contraintes que de dรฉfis pour les entreprises europรฉennes (et mondiales) :

  • d’une part, le niveau ร  atteindre est de plus en plus รฉlevรฉ, il ne s’agit pas d’un “minimum nรฉcessaire” mais bien d’une cible,
  • les sanctions sont elles aussi de plus en plus lourdes,
  • mais les ressources (budgets, รฉquipes et savoir-faire) des entreprises en matiรจre de CyberSรฉcuritรฉ ne sont, elles, et bien qu’en augmentation, ni infinies ni en croissance exponentielle.

Dรฉfinir, revoir et maintenir une feuille de route

Conclusion : une Stratรฉgie reste nรฉcessaire

En parallรจle, les RSSI doivent donc gรฉrer toujours plus d’incidents, et toujours plus d’audits. Pour relever ce challenge, ils n’auront donc pas d’autre choix que de dรฉfinir, suivre et rรฉviser au moins une fois par an leur stratรฉgie de CyberSรฉcuritรฉ.

Celle-ci ne peut pas se rรฉduire ร  un “empilement” de technologies, ou au recrutement de tel ou tel talent, ni mรชme de quelques actions “a minima” (du genre dรฉfinition de rรจgles d’or). Il s’agit bien de trouver un “fil conducteur“, logique, raisonnable et pragmatique, pour convaincre le Management, et embarquer tous les mรฉtiers, internes comme externes, dans cette dรฉmarche. Evidemment, il faut pour cela un minimum de vision ร  long terme, pour ne pas repartir d’une feuille blanche chaque annรฉe.

C’est bien le seul moyen de donner au Management le niveau d’assurance nรฉcessaire que la CyberSรฉcuritรฉ est bien gรฉrรฉe, pour รฉviter des effets de bord aussi nรฉgatifs pour la carriรจre des RSSI que pour la protection du patrimoine de l’entreprise !

Over Secure = Under Protect

CyberSecurity is not about forbidding everything but rather a matter of risk posture and balancing do’s and don’ts

All CISOs are willing to reduce cybersecurity risks for their companies. To do so, they are asked to produce CyberSecurity policies that are listing do’s and don’ts. The temptation to forbid everything in order to keep systems “secure” is high. But it’s also the worst choice for them and their company. Let’s explore why.

Excessive policies discredit CISOs’ authority

Users’ perception

When users read policies stating that many things are forbidden, they believe that their CISO has simply ignored their business needs, has prohibited everything without assessing the risk, does not understand what is at stake. I’ve seen users tell their CISO : “you’ll succeed to make our Information System secure, but there will be no more business going on ; and at the end of the day, you’ll loose your job as well!”

CISOs must remain business partners

The biggest risk for CISOs is probably to be considered as isolated technical gurus and security extremists, rather than business partners. Such perception would prevent them from being involved in Execs discussions. And, in turn, it would severely impact their ability to drive the necessary digital transformation : their department would be considered as a cost center rather than a business enabler.

Users experience is shared

Users chat together, across companies. They share their experience, either past or present.

When they finally come to the conclusion that their CISO is excessively preventing them from using their IT systems, they stop complying with most corporate rules, including legitimate ones.

When users are left without option, they find a worse way to achieve their goal

I’ve met a military officer who once told me: “Be careful when your opponent has nothing to loose: he/she will think out of the box, and do anything necessary to survive. No matter the consequence, or even whether it’s ethic. You will be adversely surprised”.

Authentication tokens

If you force your users to authenticate using a physical smartcard (token) plugged into their laptop, they may end up by cutting their card in order to remove the extra piece left outside of their laptop outline, and finally leave the card permanently inside the laptop – but not easily visible. Why ? Because they are annoyed by the fact that they need to insert/remove the card all day long, because the card can be damaged if not removed prior to putting the laptop in a backpack, which would leave the user locked out – unable to open his session, etc. At the end of the day, no more 2-factor authentication at allโ€ฆ

Internet Navigation

Another example is related to restrictive proxy filtering. Restricting too much Internet navigation impacts user experience and performance as well. As a consequence, some users may acquire their own Internet access and hot spot (or even share their personal smartphone Internet connection, or spend their time at a coffee shop!) and use it much more than the corporate Internet access itself! For sure, modern cloud proxy solutions tend to prevent such behavior. But they are not yet deployed in all companies…

Complex passwords

Passwords are a famous headache for users. Deploying a password vault solution is a must *prior* to requesting users to use complex passwords (no personal info, no dictionary word) and renew them regularly. Otherwise they won’t remember it so they will write it down (either on a post-it note or in a cleartext file).

Shadow IT remains the biggest risk after all

IT Consumerization accelerates

Home office has tremendously increased over the last years – especially resulting from the COVID lockdown, but not only. It used to be called “IT consumerization”, which could be defined as “using personal IT for business purpose, due to the fact that personal IT is sometimes even more powerful and comfortable than corporate IT”. And personal IT has become so cheap that cost is not even an issue for users. But protecting data on systems that are not managed by the company without impacting user experience is very challenging. Hence, the more we provide “user-friendly” systems at work, the less we’ll have to care for shadow IT risks.

Move to cloud also remains a challenge

Today, shadow IT is also about subscribing to cloud services without approval from CyberSecurity/IT teams.

It’s extremely challenging for companies to protect on-prem systems, manage to migrate them to the cloud, consider using multiple cloud service providers as it requires a) to upskill their teams, b) to use multi-cloud compatible CyberSecurity solutions, and c) get necessary budget to do so. Adding all kinds of unsanctioned, private cloud consumption on top of that would drastically increase CyberSecurity risks for companies.

young man looking up from the cover of a wooden background.

Conclusion: a matter of mindset and user experience (UX)

Proper balance of CyberSecurity Dos & Don’ts is not easy but here is my 2-cent advice : every time you forbid something to your users, ask yourself what they could do to bypass your restriction, and whether such restriction would be acceptable on a daily basis for their job. And make sure that preventing IT usage remains the “last option”, not the first one.

Similarly, an interesting KPI is how much additional time a user spends in order to execute CyberSecurity operations (authentication, encryption, approval, etc.). Transparent hard disk encryption, passwordless authentication, SSO, always-on VPN are practical examples of how to secure Information Systems while avoiding impacts on user experience.

And for sure AI should drastically help in the near future to make it as transparent as possible or otherwise to alert IT Dept and users whenever necessary, avoiding false positives. It reminds me of an Exec who once told me : the best CyberSecurity is the one you never hear about – except when needed !

It must burn your handsโ€ฆ

Some people often ask “Why is it that you keep repeating some common recommendations again and again to your customers ? Don’t they understand them at first ?”, I sometimes wander what should be the right answer.

It’s true that technology has drastically evolved in the last decade. New fancy features, new sophisticated attacks and new even more sophisticated defense lines. Call it cat-and-mouse game or arms race, cops against thieves, whatever…


But aside from such sophistication, there are some simple / basic recommendations (I don’t dare to say “stupid” !) that are still not met. For instance, we could list the following possible 10 commitments :

  1. Managing inventories and obsolescence. You cannot protect systems for which there is no more R&D and for which nobody caresโ€ฆ And you can’t protect what you don’t even suspect to exist.
  2. Applying all patches on all systems. At least critical / cybersecurity patches. At least critical systems. That’s so-called “hygiene“.
  3. Changing default passwords *prior* to any system or application go-live. And enforcing a proper password policy of course.
  4. Implementing 2FA/MFA (2 or Multi Factor Authentication), as identifiers and passwords are not enough to protect you today. In fact, today, we even move towards passwordless applications.
  5. Filtering all network connections. At least at the edge of your networks. Forget about permissive rules : everything not explicitly permitted must be rejected. That’s it.
  6. Segregating guest networks from corporate ones, split your internal networks even deeper.
  7. Managing identities and access rights. No, you should not have 10 times more active user accounts than individuals in your company !
  8. Making sure you have a user policy, at least, not to mention an Information Systems Security Policy. Everything not written cannot be enforced. Also make sure that you deliver awareness programs on a yearly basis, at least…
  9. Making sure that you keep logs generated by your systems (which first means that such systems must generate logs…). You can’t and should not ignore what your systems try to tell you.
  10. Being ready to manage a crisis. If you’re not, then you’ll probably have to manage even more severe damages, and pretty sure that you won’t enjoy.

The above is not only meant to be observed in large organizations. Small and medium businesses can clearly afford it as well. I would even dare to say that most of the above can be done at home. Sometimes, it’s even easier for smaller organizations (faster decision processes, simpler inventories, etc.) to apply most of those rules. It’s not that complex nor expensive and it will not drastically impact your user experience.

And I strongly believe that the above is the strict minimum : you cannot just pick 2 or 3 of them, and consider that you’ve done your job and furthermore that you’re on the safe side.


Neither can AI and automation (the current buzz words) do it all for you. They are out there to ease your job, increase your workforce and therefore enable you to focus on your main objectives. But I don’t believe it will substitute to most of your tech guys. At least that’s not what I observed in the last years.

Same for Cloud Service Providers : many companies believe that being hosted at Google / Microsoft / Amazon is a passport to be safe. I consider that this is clearly wrong. It only means that you’re given the tools to secure your  systems, not that these tools are effectively and properly used.

Some “tech guys” who are not willing to evolve will surely have to think twice, consider upskilling (we can for sure work on it together !) orโ€ฆ find another job. Admins who still use “Password2024!” as privileged passwords should now have their hands burning.

I know the statement is strong. But it has to stop.

Same for those who use “admin / admin” as ID and password, those who write their passwords in a cleartext Excel file, those who carefully write “permit any any” within firewall rules…

Time has come to consider this as inacceptable.


To conclude, I often ask the Execs of my Customers which portion of the CyberSecurity strategy of the company they are aware of, how supportive they are. Most of the above commitments are far too technical for them. But it’s getting hard to communicate on any Executive statement or strategy while in fact your teams focus on above “basic” technical objectives. That gap between Executive expectations and technical basic operations prevents proper CyberSecurity efficiency.

And if those 10 commitments are not meant, it’s usually irrelevant to consider different initiatives to secure the company.

What’s a CISO “Time-To-Leave” (and how to retain them)?

We are often told that CyberSecurity staff is both hard to find and hard to retain.

I have the feeling that, regarding experienced CyberSecurity experts, such as CISOs, we have reached the time at which some of them:

  • are talented enough to define clear objectives for themselves and their teams,
  • as a corollary, are less and less willing to slow down the pace of their activities (due to the high level of threat). They chose their job to overcome its challenges, and now they know how to achieve their goals – and are paid to do so.

For most of them, the reputation of their company, the size of their teams, and even their level of compensation is not their primary motivation to stay, as opposed to how much they actually learn from their job on a daily basis and are confronted to new challenges.

Now how do we define “experienced CISOs”? Of course, it varies a lot from one individual to another. But for sure, when someone has been a CISO a) for various large companies b) for at least several years each, and c) have globally more than 10 years of experience in CyberSecurity, they pretty surely qualify

Still, some companies are willing to hire a CISO “to tick the box”. Unfortunately, some of them get involved into various social/political issues, loose more and more ability to influence the operational level of protection of his company, and hence get more and more afraid of getting involved into a CyberSecurity crisis someday…

Other companies may first hire a CISO to perform a quite practical primary objective, but, after several years, the same companies are embarrassed with the amount of change management that such a protection requires, resulting from the activity of their CISO.

I have the growing feeling that, at that point, experienced CISOs choose to resign and either:

a) move to another CISO job,

b) start their own company,

or c) switch to a complete different job (one of my friend switched from CISO to photographer…).

This is probably the best case scenario.

Worse cases would include real “burn-out” situations.

Various press articles have covered CyberSecurity staff involved in such burn-out.

But, tell me… How can CyberSecurity experts, which are so passionate about their job, end up in a burn-out? Simply because they don’t want to abandon their vessel, even though they are more and more convince that they don’t have the means to avoid the iceberg…

So they keep running faster and faster, though they are never satisfied about their job and achievements.

Now, the question is: how long does, in average, a positive relationship between an experienced CISO and his company last for? How long are such experienced CISOs enjoying to execute their job in large companies? According to my observations and as well to Heidrick & Struggles last survey, it seems that 4 years is a fair number.

Are there exceptions? Could experienced CISOs actually stay longer than 4 years in large companies, while still fully enjoying their job? I believe that CISOs either:

  • running an external activity related to their job (eg: leading a CyberSecurity association)
  • and/or are hired by a tech (software/hardware) company, in particular in the CyberSecurity field
  • and/or moving on a regular basis from one job/position to another within their company

…are likely to stay longer as CISO of their company. For others, I’m less optimistic.

Knowing this, what could we recommend to CISOs / companies to reduce CyberSecurity staff turnover? I would summarize it this way:

  • Keep supporting your CISO/CyberSecurity teams. Focus on and support their progress rather than on what they need to improve
  • Apply Steve Jobs’ recommendation: “It does not make sense to hire smart people and tell them what to do; we hire smart people so they can tell us what to do”.
  • Avoid mixing [too much] politics and CyberSecurity. Avoid changing CISOs objectives too often. It is hard enough to manage budget, skills and change management constraints to reach a proper level of protection. Keep in mind that CISOs enemies are (and must remain) hackers and malware. There’s no room to add others.
  • Instead, feed your CISO & CyberSecurity teams with challenges and training. Remember that what makes (and enables to retain) Great Employees is a mix of Trust, Talent, Tenacity and Training…

Still, I like this quote from Shawshank Redemption: “Some birds are not meant to be caged, that’s all”. Hence, companies should remain proud of the progression of their associates towards new positions, either internal or external. It usually means that they learned a lot through a fruitful multi-year experience!

Don’t pay the bloody ransom!

Several companies wander whether they should pay the ransom, in case of ransomware attack on their systems.

Unfortunately, multiple CISOs have faced such tough situation, not only from a pure technical point of view but also from a more deontological, social, political or even ethical point of view.

Some companies are strictly opposed to such “payment”, while others consider the difficulty to survive without the “lost” data (which is fully understandable), but some Execs also consider the “payment” as a “quick and easy way to solve the problem”.

Interestingly, while it’s sometimes quite hard for CISOs to get enough budget to perform their necessary projects, their management may take the decision to pay within a very short period of time (under the pressure of the incident). Well… I believe this is just the wrong way to address it.

Let’s study why.

First, you’re not sure to retrieve access to your data. Were you “trusting” the bad guys for that? Well you should rather trust your CISO, and his/her teams… Ransomware is not “a product”, it cannot be compared to ethical hacking, vulnerability disclosure programs, bug bounty and other useful commercial activity.

Second reason not to pay is that hackers would keep in mind that you’re a good customer.

That money is obviously not an issue for you.

That if you did it once, you may do it again.

Hence, they’ll come back. And unlike what you could do with your customers, there’s no “fidelity” program! Cost will not decrease over time.

So don’t put one more coin in the system, it’s not a piggy bank!

Last and not least, because giving money to those guys is just the same as funding cybercrime. The more money they get, the more weapons will be developed and sent out to all connected systems out there. And as you’re asked to pay in crypto-currency it’s gonna be hard/impossible to chase down criminals by “following the money”, just as law enforcement forces would have done decades ago. Forget it.

I’ve known one of my peers, a CISO who has been asked by his management (probably not enough aware…) to pay the ransom. When he informed the bad guys about it, there was another “surprise”: such criminals were suggesting to pay a little more, in order to download a “specific protection software” to avoid further attacks in the future!

Are you kidding? Do you believe it’s a “defense” or rather a “backdoor” to ease future attacks instead of preventing them? Well, his manager asked him again to pay for the addon. He did not, but rather resigned. Very brave, but sad, indeed. Keep your cybersecurity teams and install cybersecurity software, not malware.

With regards to the on-going discussions related to the reimbursement by insurance companies of the ransom (provided that victim companies declare the attack), I believe that we should not encourage companies to pay. That’s it.

For sure, companies that are about to bankrupt if they don’t retrieve access to the data could be forgiven for paying the ransom… But still: they encourage cybercrime and should rather invest in their protection to prevent cyber-attacks.

CyberSecurity Operations and the 3 Lines of Defense model

While the “3 Lines of Defense” model described by ISACA has demonstrated its efficiency, by splitting the responsibilities of governing and implementing CyberSecurity, on one hand, ensuring its compliance and proper impact on risk management, on the 2nd hand, and finally auditing proper execution of the first 2 functions on a 3rd hand, the need to ensure that CyberSecurity Operations are performed by and under the control of CyberSecurity professionals remains.

What I mean by CyberSecurity Operations is selecting, implementing, configuring, troubleshooting and updating CyberSecurity technologies that protect their organization.

In order to confirm this, I have interviewed various CISOs of large french companies belonging to very different verticals (banking and finance, insurance, luxury, cosmetics, health, retail, energy, communication, manufacturing, transportation). Here are the conclusions of this:

  • in terms of reporting line, CISOs mainly report to CIOs, but more and more to a COMEX member (which can be the CIO as well, but not only, eg: General Secretary, Risk Management and sometimes even CEO)
  • in almost all cases, CISOs are managing CyberSecurity Operations, at least on equipments that are dedicated to [advanced] pure CyberSecurity functions (eg: authentication, filtering, encrypting, data leak prevention, incident detection and response, etc.).
    • Network infrastructure equipments that are also involved in network segmentation may remain operated by infrastructure teams, provided that very clear rules are predefined to grant or reject network access rights, but that requires that infrastructure teams are aware, trained and fully accountable.
    • When such clear rules are defined, the objective and the trend are usually to automate (at least through a proper workflow) such management of network access rights, to optimize cost, agility, and risk management
    • In some cases, the infrastructure team staff in charge of managing such network segmentation is also reporting to the CyberSecurity team in dotted line
  • in terms of selection of CyberSec technologies, the CISO remains in charge of CyberSecurity market watch and selection of appropriate technologies, even if it’s often validated by the CIO and sometimes most of his direct reports as well (through a proper governance body). Of course, CISO is also consulted for the selection of other IT technologies as well
  • CISO also has the ability to perform audits by him/herself, provided that he/she finds/is given the necessary resources (people and budget) for that. Of course, it does not prevent many other controls or audits, to be performed by internal / external auditors, customers, insurance companies, certification bodies, and so on
  • similarly, incident response remains under the responsibility of CISO, both for triage, investigation, decision to respond, trigger a crisis, or close the incident
  • securing industrial systems (PLCs, HMIs, barcode readers, etc.) is also performed under the responsibility of CISOs, despite the fact that CIOs are not always in charge of managing the connection of such equipments to the network
  • when it comes to securing commercial products and services, CISO is often in charge of it, unless there is another dedicated VP who takes such responsibility. This does not prevent the CISO from being involved in analysis and risk management, ensuring the compliance to regulations, and having the ability to vet (or at least suggest to do so) improperly protected systems.

While the 3 Lines of Defense model focuses on the importance to split responsibilities (to avoid duplicated tasks, ensure Segregation of Duties and optimize cost), it does not describe at which level should arbitration / decision be performed.

For sure, CyberSecurity topic is more and more discussed by ExComm members but setting up arbitration / decision at that level would require that they have a deep understanding and experience on technological CyberSecurity topics. While this may be true for IT or CyberSecurity vendors, it’s usually not the case for other companies. As it is the same for global Security topics (securing people, premises, and information of all kind), gathering CSO, CISO, and EHS in a common team is also emerging but not yet quite adopted. Most of them collaborate a lot together, but are not [yet] reporting to the same individual in the organization.

With the emergence of several move-to-cloud projects, the need to recruit, upskill, and manage various CyberSecurity individuals, and the strong evolution of regulations, there is a growing need for all teams involved to be managed by CyberSecurity professionals who understand their daily job and the impact on the business. For such reason, I found interesting the idea that was given to me by one of the CISOs interviewed: “Let the CISO consolidate several Lines of Defense in his team, provided that each line is managed by a different direct report, while asking external auditors for an independant opinion on the efficiency of the protection of company’s assets, and how it benchmarks within his/her industry”.

To conclude, I would like hereby to thank all CISOs that have contributed to my survey, for their valuable inputs and thoughts on this crucial topic ๐Ÿ˜‰ !

The Rise of the Machines (my interview by CIO Institute)

I have recently been asked by CIO Institute to give my opinion on the emergence of automation, machine learning and artificial intelligence in multiple IT topics (including CyberSecurity).

Even though the objective was not to focus only on CyberSecurity, I found it interesting to try to define my vision on this topic. I keep thinking that you learn a lot when you step out of your “comfort zone”… ๐Ÿ™‚

Don’t hesitate to register on CIO-Institute website and read their articles, and of course attend their virtual events, as there are plenty of fruitful discussions and great things to learn!

Meantime, enjoy reading my article below, and feel free to send me your comments!

You may as well read it directly on CIO-Institute‘s website here.

NB: Thanks a lot to Stephanie!

The Rise of the Machines: Ensuring that the Human Element is Never Lost

The Global CIO Institute interviewed Olivier Daloy, VP of CIX-Aโ€™s on how firms can utilise the best of both worlds as people and technology develop. Read the interview below.

Published: Mar 16, 2022

Written by:

Stephanie Thilagalingam 

and Olivier Daloy

Q: As firms look to transform their businesses, what must firms do to ensure that they stay true to their people? 

OD: In my honest opinion, they must communicate regularly on what is at stake and what is the expected timing of the transformation. The biggest negative impact of communication comes from a lack of it. Firms must disclose their strategy and engage their people, avoid being shy or reserved to do so. They must clarify what are the expected gains, not only for the company, but also for each employee, both at corporate and personal level. Lastly, they must balance their ambition, adopt the right pace. Avoid going too fast as you will lose your employees but at the same time, avoid going too slow, as this will make you lose your competitive advantage.

Q: It was on the news recently that robots were running cafes at the Beijing Winter Olympics. Are we seeing a shift towards machines being trusted to carry out responsibilities that were once meant for humans? Would this shift mean that more jobs will become redundant in the coming years? 

OD: I donโ€™t think so, but rather that it simply means that every task that becomes commoditized will sooner or later be replaced by a more value added task. We must be prepared for that, not afraid. We must welcome innovation, but always measure and manage the risks. Itโ€™s a very common activity for CISOs. 

Q: In your opinion, do you think that firms would prefer to have their workforces completely automated as this then reduces the risks of human error? 

OD: Again, itโ€™s more a tradeoff between what can/should be commoditized versus what should remain under human responsibility. Not all workforces will be automated, but every โ€œprogrammaticโ€ task will definitely be. Keeping low value tasks is not only inducing financial losses, itโ€™s also a huge obstacle for recruitment and retainment of workforces.

Keeping innovation, creativity, social and even political skills is key for many companies. These are all examples of where human workforces may be relevant and bring a lot of value.

Q: Is the human-machine balance achievable? If so, how? 

OD: I believe it can, but itโ€™s a moving target. According to many criteria, such as what the available technology can do without making too many mistakes, but also considering ethics, and often the economy as well (not exhaustive). Proper arbitration, based on the risks, enables us to define what must remain a manual action versus what can and should be automated, taking the most benefit out of the added value of human actions.

Q: It is hard knowing what requires automation and what requires people skills. How can firms bridge that gap and be able to identify what truly works for their business? 

OD: I believe it usually comes from experimentation. Just like we do in IT, you define a minimum viable project/product (MVP) then you implement a pilot and based on its results you go for a larger rollout. But it should also care for what the users/customers/citizens require/are ready to accept โ€“ and of course, legal constraints.

There are various cases where companies thought they could automate much more than what their customers were ready to accept. In some cases, itโ€™s only a matter of taking the challenge at the right time. In others, itโ€™s just a matter of understanding whether there is a use case. Think about autonomous driving but also [Amazon] automated delivery: do you think itโ€™s going to remain a possible idea, an exception or will it be live some day? If you look at science fiction 15-20 years ago, there were a lot of ideas, some of which have come true, others are still not there. We use a lot of chatbots in IT, and we have SIRI and โ€œOK Googleโ€, but we still have keyboards โ€“ voice operated IT remains exceptional.

Q: How can we leverage emerging tech to boost productivity and performance and ultimately, allow people and tech to completely align and thrive? What are some ways firms can support this?

OD: Again, my opinion would be that we must start small and grow fast, fail fast but learn faster. This is probably the best way to integrate technology at the right level. We must focus on our pain points, find the right technology to power up our actions. I used to say that Iโ€™m not interested in a solution that looks for a problem, but rather for a solution to my problems. I also believe that we must develop the creativity of our people, give them time to think about disruptive ways of addressing their problems โ€“ and even incentivise their work/solution. Look at bug bounty: the best way to make people find new ways of hacking into IT assets is, in some way, by leveraging onto gamification/challenge/financial gain. There is no big interest in technical solutions that are not embedded into pragmatic problem solving.

Q: What are some potential risks firms must be on the lookout for when trying to build a harmonious relationship between people and technology? 

OD: I believe itโ€™s mostly a matter of trust. Trust from employees that technology is not going to steal their job, which they are afraid of. Also, trust that technology remains under control. For instance, I get questions from C-levels around; are we sure that when managing cybersecurity using machine learning and AI, we still know what we are able to protect against? And finally trust that, at the end of the day, the technology does not bring more risks than it helps to manage. For Amazon, it could be drones falling onto people, impacting their safety, for instance.

Olivier Daloy spoke at the CIO Institute DACH event which ran in February 2022. Daloy is a frequent speaker of the institute so sign up to the community today to interact with him and like-minded people. 

First lessons learnt related to Cyber Offensive actions led by Russia against Ukraine – How should you protect your assets?

Known recent cyberattacks originating from Russia include the following. Despite the fact that there is no magic way to increase in a very short period of time the level of Cyber Protection of a company, here are my (non-exhaustive) thoughts related to how you should protect against these threats or at least strengthen your cyber-posture.

  • Distributed Denial Of Service (DDoS) attacks,
    • Mainly observed against military, gov, media and banking critical services by Russia
    • To prevent or mitigate such threats, you should consider:
  • Website defacements
    • Mainly against gov sites
    • Probably coming from APT (Advanced Persistant Threat) UNC1151, with similar weapons than APT29 Russian state-sponsored group
    • To prevent or mitigate such threats, you should consider:
      • Ensuring that you have a full inventory of your websites (eg: Cycognito, Uncovery, Palo Alto Cortex Xpanse)
      • Checking that they don’t have any [critical] vulnerability (eg: using a vulnerability scanner such as Rapid7 Insight VM)
      • Filtering traffic at network level using regular or application firewalls – WAF (eg: Checkpoint, Palo Alto)
      • Fixing all such vulnerabilities or deactivating related services temporarily, otherwise consider virtual patch management solutions for limited periods of time (eg: TrendMicro)
      • Activating 2 (or multi) factor (2FA/MFA) authentication to prevent unauthorized accesses to your systems from Internet
      • Activating mechanisms to automatically ban sources that have failed to authenticate several times
  • Fraudulent messaging
    • SMS phishing (Smishing), typically pretending that there was a bank issue to trap target users
    • To prevent or mitigate such threats, you should consider:
      • Increasing the awareness programs of your users (eg: KnowBe4 service). Inform them in particular about attempts to steal their credentials using phishing websites or alike
      • Implementing or reviewing the configuration of your Anti SPAM systems (eg: CISCO IronPort, Barracuda Networks)
  • Malware attacks
    • Known code names are WhisperGate & Hermetic Wiper. Both aim at destroying files/filesystems, as opposed to ransomwares for which data access recovery is possible
    • Mainly against gov, communications, non profit organizations, e-services for citizens, IT organizations
    • To prevent or mitigate such threats, you should consider:
      • Implementing robust cloud proxy (in particular isolation techniques, such as Menlo Security) and Cloud Application Security Broker – CASB solutions (eg: NetSkope CASB, Microsoft CASB, etc.)
      • Implementing best in class Endpoint Detection & Response – EDR (eg: Cybereason, Mandiant) in a Managed Service mode (unless you’re lucky to have the proper internal ressources to manage it)
      • Making sure that such Managed Detection and Response – MDR or EDR and other CyberSecurity solutions are fed with all necessary Indices of Compromise (IoCs), that you either get from free (open) or commercial sources (eg: Recorded Future). To manage these IoCs, you may consider using a Threat Intelligence Platform (eg: Threat Quotient, Anomali), but I also strongly encourage you to contact us at CIX-A, to join our European Alliance of CISOs again hackers and other threats!
      • Contracting with a Rapid Reaction Force supplier to react to any major cyber-attack (eg: Cybereason Incident Response)
      • Generating off-line backups of your most critical systems and data and ensuring that you have properly documented how to restore them (or even already performed successful drills)
      • And of course updating your systems (cyber-hygiene) as often as possible, don’t forget to reboot them immediately when necessary

In addition to all of the above, you’ll need to :

  • closely collect, consolidate and monitor your logs (eg: Elastic Cloud, Rapid7 Insight IDR)
  • request your partners and suppliers to inform you immediately in case of detection of a proven cyber incident on their assets
  • and be ready to react to detected incidents, be them suspicious or proven.
    • To do so, numerous companies offer a Security Operation Center (SOC) service or Incident Response ressources that are worth considering. If you already contracted such service, consider increasing its level of vigilance on your known critical assets
    • You may also prepare to segment your network, to confine any detected attack. To do so, you’ll need a proper inventory of your business critical assets
    • Again, here, I also encourage you to join CIX-A, as we share technical critical and actionable information (including various cheat sheets, and IoCs) to respond to cyber-attacks!

Here are some interesting / relevant URLs that are worth mentioning:

Don’t write CyberSecurity Policies that nobody will ever read or even use!

When asked whether they have defined CyberSecurity policies, many CISOs answer: “Yes, of course! Even reviewed on a regular basis!…”

However, when asked whether all users know where to find them, how to search into them, and whether they always find what they were looking for in due time, it’s another story…

Many companies write policies only to comply with regulations or to pass certifications. This policy exists, check. That other has been reviewed, check. But nobody cares.

Worse is that, finally, no-one even knows what should be observed or complied with. Even worse, everyone prefers to ask the CISO or his/her team about it. It’s quicker than taking a couple of minutes (best case…) to search in the policy! Guess what? The more you answer, the more you’ll get questions!

Indeed, nothing prevents inconsistent answers from being given, either due to the turnover of CyberSec team members, their availability, skills, etc. And in any case, isn’t it a pure waste of time?

A good indicator is the number of times the CISO or his/her team has been able to use the written policies to avoid spending time writing accurate and exhaustive answers. Instead, they’re able to simply say : “please refer to such article from such policy, which should clarify everything, in a consistent and efficient way”.

OK, but… to do so, policies must be properly written. They must be short and straight to the point. They must be clear, accurate and exhaustive. They must include the mandatory rules, but also the recommendations and the allowances (that are not recommended, but only tolerated). They must be properly structured, but also be mapped over well-known reference documents (standards) available. And, of course they must be updated as soon as necessary. Not only once a year ๐Ÿ™‚ .

Writing different policies instead of a single one is quite old-fashioned. Rather than splitting policies into different documents, I would believe it’s a better idea to use Intranet search engines to make sure to find the right article as quickly as possible.

Of course, with such an objective, there are far less companies that may consider to manage CyberSecurity policies in a mature way.

But when they do, they benefit from the full power of efficient documentation, spend far less time to explain what businesses must comply with, and avoid a lot of frustration: indeed, CyberSecurity team is much more “predictable”, and its reputation is drastically reinforced!

Design a site like this with WordPress.com
Get started