Cyber threats like ransomware, which made its very first appearance in 1989 and has been on security teams’ and law enforcement’s radar for the past 7 or 8 years, are not fads. It’s not going away. In fact, the cash-rich ransomware industry is flourishing. As a result, organizations are moving from the era of possibility to the era of probability of a successful cyber breach. It’s not hyperbole to say that it’s no longer a question of if an organization will face a cyberattack but rather when.
Protecting against ransomware is a top priority for most organizations as they look to protect themselves against lost productivity, lost brand equity or trust, and lost revenue. Protection against ransomware should be a 2-pronged approach with a focus on security and resiliency:
In the past, business continuity was comprised of 3 protection practices. We now have a 4th protection practice. I will start by reviewing the 3 well-established protection practices and then talk about where cyber resiliency fits in.
Thankfully, the US National Institute of Standards and Technology (NIST) has published a “Cybersecurity Framework” for safeguarding critical infrastructure. The framework integrates industry standards and best practices to help organizations develop or improve their cyber protection measures.
The NIST Framework is made up of 5 functions. You can think of these functions as steps, but notice that they are in a loop, signaling that there’s an expectation of continuous updates and improvements over time. Keep in mind that cyber resiliency is all about planning and preparing before a breach occurs. Not surprisingly, the first 4 functions — identify, protect, detect and respond — focus on planning and preparation to ensure a successful recovery.
Anyone can download and use the NIST Framework (link resides outside ibm.com) and corresponding white papers to aid them in their self-directed cyber-protection efforts. For those who would rather not go it alone, and would prefer some outside assistance and expertise, IBM System Lab Services has built the Cyber-Incident Response Storage Assessment (CIRSA) using the NIST Framework to expedite clients’ cyber resiliency protection efforts. For organizations that would like assistance and expertise, the CIRSA offering is a great vehicle for starting down the path to cyber resiliency.
Cyber threats like ransomware, which made its very first appearance in 1989 and has been on security teams’ and law enforcement’s radar for the past 7 or 8 years, are not fads. It’s not going away. In fact, the cash-rich ransomware industry is flourishing. As a result, organizations are moving from the era of possibility to the era of probability of a successful cyber breach. It’s not hyperbole to say that it’s no longer a question of if an organization will face a cyberattack but rather when.
Protecting against ransomware is a top priority for most organizations as they look to protect themselves against lost productivity, lost brand equity or trust, and lost revenue. Protection against ransomware should be a 2-pronged approach with a focus on security and resiliency:
In the past, business continuity was comprised of 3 protection practices. We now have a 4th protection practice. I will start by reviewing the 3 well-established protection practices and then talk about where cyber resiliency fits in.
Thankfully, the US National Institute of Standards and Technology (NIST) has published a “Cybersecurity Framework” for safeguarding critical infrastructure. The framework integrates industry standards and best practices to help organizations develop or improve their cyber protection measures.
The NIST Framework is made up of 5 functions. You can think of these functions as steps, but notice that they are in a loop, signaling that there’s an expectation of continuous updates and improvements over time. Keep in mind that cyber resiliency is all about planning and preparing before a breach occurs. Not surprisingly, the first 4 functions — identify, protect, detect and respond — focus on planning and preparation to ensure a successful recovery.
Anyone can download and use the NIST Framework (link resides outside ibm.com) and corresponding white papers to aid them in their self-directed cyber-protection efforts. For those who would rather not go it alone, and would prefer some outside assistance and expertise, IBM System Lab Services has built the Cyber-Incident Response Storage Assessment (CIRSA) using the NIST Framework to expedite clients’ cyber resiliency protection efforts. For organizations that would like assistance and expertise, the CIRSA offering is a great vehicle for starting down the path to cyber resiliency.