It may not be on the mind of every CEO, CIO or CTO but the rise of disruption is of major concern. Disruption itself has always been a part of business theory under Michael Porter’s five forces and classified as “the threat of new entrants”; but this threat has continued to evolve.
Barriers to entry in various markets have been in place to control competition. However, modern disruption can occur outside these barriers with the “disruptors” changing the very way the market sector operates thereby out manoeuvring and altogether eliminating existing big market players who could not anticipate this risk.
The difficulty in anticipating and mitigating disruptive risk is extreme since they may not actually exist at the moment but can exist in the future. Can your business survive after the disruption has happened? With the evidence of the impact of disruption all around, it should be evident that it is no longer a small issue, since the very survival of the enterprise may depend on it.
When Disruptions Occur
With this being the case, flexibility, speed and adaptability come to mind. However, many enterprises and their internal IT departments cannot offer those characteristics fast enough when disruption occurs, leaving the enterprise at a competitive disadvantage. This is because the “things always work this way” and “resistance to change” mentalities exist within all enterprises. By looking at the governance of enterprise IT (GEIT) and the importance of IT to support the enterprise, it may be wise to consider reinventing your IT.
By reinventing your IT you should consider the possibility of disruption as a major fact and readjust your current work models to offer some best case resistance/adaptability towards this. To take it a step further, you should streamline the enterprise to become the market disruptor itself, thereby giving your enterprise a head start against your current and potential competition.
One consistent view that remains is that security itself is of the uttermost importance and must be considered even though there is no single way to achieve the reinvention of your IT. We are in the age when digitization and connectivity play major roles for consumers. Customer demand and market conditions drive business strategy; however, reinvention can also be found in creating systems that change how business itself is done, to the benefit of customers, thereby driving habits and behaviors surrounding these.
Disruption should be discussed and considered as a new expectation rather than an impossibility. All strategy considers risk, but the question is: how does one prepare for the unforeseen disruptive risk that has not happened yet? Is your enterprise ready?
Ammett Williams CCIE, CGEIT, Telecommunication Team Leader, First Citizens TT
Capability is the backbone of an organization. The lack of organizational capability can lead to cost overruns, missed or close deadlines, poor morale, quality problems, customer complaints, and the inability to repeat previous success. But while organizational leaders recognize the need for capability improvement—according to a McKinsey & Company survey, executives view capability building as a top three strategic priority1—they often don’t know how to address their need.
CMMI Models
CMMI, or Capability Maturity Model Integration, provides a solution to increasing capability gaps. Proven effective in organizations and governments globally over the last 25 years, CMMI consists of collected best practices designed to promote the behaviors that lead to improved performance in any organization. CMMI’s pathway to capability improvement can be customized with 3 models for different environments:
CMMI for Development: Build capability when engineering or developing products and services.
CMMI for Acquisition: Build capability when acquiring products and services.
CMMI for Services: Build capability when providing services.
These models provide a framework for developing, improving and sustaining business performance in your environment. They enable you to determine if your current way of doing things is working, if you’re improving, and they lead you toward greater continuous improvement.
CMMI Maturity Levels
A key component to capability improvement is CMMI’s maturity levels. Maturity levels provide a rigorous benchmark rating method that enables you to compare your organization’s capability to its competitors, its industry and itself over time. CMMI provides 5 maturity levels that demonstrate a visible path for improvement: Initial, Managed, Defined, Quantitatively Managed and Optimizing.
As an organization advances its capabilities, it can expect to achieve a higher maturity level by identifying areas of improvement, working to correct these areas and integrating these solutions across its organization. High-maturity organizations have both lower risk and increased quality. The higher the organization’s maturity, the better its performance. By achieving a high CMMI maturity level, an organization demonstrates a deeper commitment to improving capabilities using statistical and other quantitative methods. A focus on continuous improvement means that high-maturity organizations are constantly evolving, adapting and growing to meet the needs of stakeholders and customers.
CMMI Around the World
Thousands of organizations have implemented CMMI; in 2015 alone, more than 1,900 high-performing organizations earned a CMMI maturity level rating. By implementing CMMI and communicating their maturity level to stakeholders, organizations highlight their capability and commitment to excellence.
CMMI has been implemented in 101 countries around the world, with 11 governments investing in CMMI to support economic development in their countries. For over 25 years, high-performing organizations in a variety of industries, including aerospace, finance, health care, software, defense, transportation and telecommunications, have earned a CMMI maturity level rating and proved they are capable business partners and suppliers.
In early 2016, ISACA acquired CMMI® Institute. ISACA and CMMI Institute share a vision for advancing organizational performance that centers on driving excellence in the IT, information systems governance, data management governance, software, and systems engineering functions in organizations across a spectrum of industries.
For a deeper dive, the CMMI Institute offers several training courses and certification options. Elect for onsite training or take the online introductory Fundamentals of CMMI Elearning course from the comfort of your own home or office. Learn more about your CMMI training and certification options: http://cmmiinstitute.com/grow-your-career.
About CMMI Institute
CMMI Institute is the global leader in the advancement of best practices in people, process and technology. The Institute provides the tools and support for organizations to benchmark their capabilities and build maturity by comparing their operations to best practices and identifying performance gaps. Learn more: http://cmmiinstitute.com/.
Editor’s note: ISACA will be hosting a free webinar on the topic, ISACA Presents: Building Capability with CMMI, Wednesday, 17 August 2016, 12PM (EDT) / 11AM (CDT) / 9AM (PDT) / 16:00 (UTC).
Every day, in every corner of the world, at every minute, small- and medium-sized enterprises (SMEs) are opening up stores, serving clients, delighting customers (or not). And while the classic SME picture may be the storefront, SME reality means constant commerce, updating web presences to buy, sell and service everything; work that begins before dawn and ends long after night has fallen.
While precise measurements are difficult due to differing definitions of SMEs, research by the World Bank has indicated that these vital enterprises employ more than half of all private sector workers globally, and can comprise more than 90% of all the world’s existing businesses. In the United States alone, the U.S. Small Business Administration has estimated that the number of SMEs currently operating in America exceeds 28 million firms.
These entrepreneurs and service sector employees share common characteristics—incredible dedication, a belief that what they do is valued by their communities, and the hope that their hard work will adequately provide for their families, and their families’ futures.
Regrettably, however, many SMEs have something else in common—minimal or nonexistent protection from cyber threats and attacks.
Effective cybersecurity is paramount to the success of any business, regardless of size, as it pursues growth and prosperity within a global and increasingly digital marketplace. According to global estimates released by security company Symantec, spear-phishing attacks against SMEs have more than doubled in only a few brief years, rising from 18% in 2011 to 43% in 2015.
For some SMEs, though, this digital economy brings with it some difficult choices. A number of SMEs around the world find themselves in the unwelcome situation of being forced to choose between incorporating adequate cybersecurity into the digital and wireless aspects of their business, or not doing so. All too often, due to business or personal factors, SMEs choose the latter.
This may not be possible in the future. As our digital economy evolves, a lack of cybersecurity for an SME poses increasing risk. Cyber insurance, available and in use by larger-scale organizations, should be more of an option for, and optimized by, SMEs. More direct impacts, such as breaches of an SME’s digital infrastructure leading to the release of financial or personal information, or attacks that create a back door into another company, will have consequences. Minimally, this hurts reputations and relationships, as customers and vendors think twice before patronizing the SME again. On the other side of the spectrum, the business does not recover, and is shuttered. None of this bodes well for SMEs that lack effective and robust cybersecurity.
There are efforts underway to address this. New Jersey’s recently appointed CTO, David Weinstein, is creating a resource for New Jersey’s SMEs to keep abreast of developments in both cybersecurity and the threat landscape, an effort that complements the ongoing cybersecurity education efforts of the U.S. Small Business Administration. We see an increasing number of Information Sharing and Analysis Centers (ISACs) in the United States making similar resources available to SMEs within their respective industries. In the European Union, ENISA is leading efforts to ensure that the knowledge gleaned from ISACs finds its way to the SME community as well. All of these efforts are commendable, for they provide SMEs with valuable tools to aid them in ensuring the cybersecurity of their digital businesses.
Yet, these efforts have not and will not reach every SME. Leaving one business or agency behind in the quest for greater cybersecurity for their digital enterprise efforts is unacceptable. The aforementioned efforts, already underway, must be built upon. Chambers of Commerce at the local, regional and national levels must begin to offer resources to secure the digital business of SMEs. More ISACs need to become involved. Governments, at all levels, need to find additional ways to create and support efforts that will aid in securing the digital futures of SMEs.
ISACA’s global community must do its part, as well. We know some ISACA chapters have begun outreach to local SMEs. This is excellent and to be commended—but efforts must grow. We urge all ISACA chapters reach out to local, regional and national SME-focused organizations, and to partner in efforts to increase and enhance cybersecurity within this crucial sector of the digital economy.
Likewise, we urge our colleagues within the NGO community to engage in similar efforts; and we pledge to help you with subject-matter expertise, tools and experience. Several NGOs have already taken steps to aid the SME community, all admirable efforts. Taken in sum, the NGO cybersecurity community has presences in nearly every nation in the world; our non-profit sector has an opportunity to effect global, positive change within the SME sector, as well as within the wider international digital marketplace.
It is incumbent, upon all of us within ISACA and with the wider NGO community, to share our expertise with the SME community. Enterprises of all sizes can and will benefit markedly from this interaction, and will be further empowered to realize the positive potential of technology, and reap the benefits of security in our evolving global digital economy.
Matthew S. Loeb, CGEIT, FASAE, CAE, Chief Executive Officer of ISACA
CISOs exploring career advancement opportunities have a new consideration, according to Gartner VP and Distinguished Analyst Paul Proctor. At a Gartner Security & Risk Management Summit presentation in June, Proctor talked about the evolution of a new enterprise role, which is a logical next step for some CISOs: Digital Risk Officer (DRO).
While few organizations have formally created the role, Gartner predicts that by 2020, 30 percent of large enterprises will have a DRO in place. Why? Because the increasing integration of digital technologies into business operations and products—the Internet of Things (IoT)—requires someone who can assess technology risk throughout the digital enterprise and provide executives with decisions that impact business processes. An example is assessing the physical system that gathers personally identifiable information from wearable technology. The DRO would look at how the data is used in marketing and sales operations, identify privacy issues, and look at the legality of monetizing the data as a source of revenue.
Proctor reports while CISOs may not have the title, many have gradually taken on some of the tasks associated with a DRO, such as:
Reviewing contract clauses for technology risk and security requirements
Developing policies to address the growing use of technology not controlled by IT
Addressing the privacy and security of data gathered by IoT devices
For CISOs interested in making the transition, here are the skills needed, according to several experts:
Fully comprehend how the business is run, recognize desired strategic outcomes and speak the language of executives in order to fully articulate digital risk factors in operational and financial terms.
Understand IT, IoT and operational technology (OT), and the overlap of technology and the physical world.
Have the ability to work in a bimodal organization, supporting Mode 2 projects.
Understand global privacy and e-commerce regulations.
Have a people-centric style to work across the organization in collaboration with businesses, legal, compliance, operations, and digital marketing and sales.
Essentially, the DRO’s role is to bridge the cultural divide between business and technology, says Nick Sanna, president of the Digital Risk Management (DRM) Institute. To do that requires building the organizational processes and best practices necessary to measure and manage digital business risk—including mapping important business processes, assessing exposure to threats and prioritizing risk mitigation initiatives. Sanna admits that building a DRM program will be a complex challenge for DROs, but also a great personal stretch opportunity.
Since I created the Security Culture Framework in 2012 and open sourced it in 2013, the interest in security culture has exploded worldwide. When I first started in the industry, security culture professionals were but a small group of specialists in the US and Europe, discussing how we, based on our experience, built functional security cultures in organizations around the world.
Today, only a few years later, the interest in security culture is truly global, with a large number of organizations applying the principles of the framework to build and improve their security culture.
In my opinion it is important to accept the fact that all organizations have a security culture—whether they acknowledge it or not. This means that a poor security culture may have a negative impact on your organization, opening the organization up to external and internal risk and data breaches. A security culture can (and should) be improved, thus making the improvement a potential benefit.
Security culture is defined as the ideas, customs and social behavior of a group (organization) that keeps it secure. To be secure is one clear benefit of a security culture. What being secure really boils down to are the risk assessment, risk acceptance and risk mitigation strategies of the organization. No two organizations are the same in this respect. A risk-focused approach to security culture is a very good idea, as it allows you to direct your efforts to where they will make most sense for the organization.
An organization with a high risk appetite may choose to focus less on security culture than an organization with a low appetite. As long as they understand the short- and long-term outcomes of such a strategy, I have no problem with such a choice being made. The challenge arises when an organization finds itself in the blind—believing they are doing the right things, while waking up brutally one morning with all their data records being leaked to the press, and then, upon closer inspection, discovering that their awareness training programs worked very well to check a box once a year, but did very little, if anything, to build and improve their security culture.
Making informed choices is part of a security culture. Understanding the threat landscape, the risk strategy, and then transforming this into a security culture program is the way to build and improve security culture.
I plan to write future blogs that will discuss the principles of the security culture framework and my experiences building security cultures around the world. I will also take questions and provide answers to your security culture questions.
What is your experience building and improving a security culture? Do you see any settings where an organization could accept a lesser security culture? If so, why?
Editor’s note: Roer’s latest book, Build a Security Culture, is available for purchase at ISACA’s Bookstore.
Kai Roer, Security Culture Coach/Author, The Roer Group