IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

C-suite and IT must collaborate for safer businesses

"Business-driven security" is the name of the game at RSA Conference 2017

Security professionals need to come together with business decision makers in order to find solutions that can serve the needs of both. That's according to Zulfikar Razman, CTO of RSA.

In his opening keynote at RSA Conference 2017, Ramzan talked up the need for "business-driven security", which brings the needs of both together through collaboration.

"Security isn't just a technology problem, it's a business problem," Razman told the several thousand delegates in attendance.

"The inability to draw connections between security details and business metrics is what I call the gap of grief. Corporate executives don't care if an incident involved SQL injection or cross-site scripting. They'd like to understand the business implications."

There are three key elements to making business-driven security work, said Razman. First, risk should be treated as a science, not a dark art, using consistent and rigorous methods for analysis. Second, businesses should simplify what they control for example, the number of different security solutions they use.

"I spoke to one chief information security officer recently who has 84 different security vendors. Eighty-four! How do you manage that many vendors? How do you justify to your board and executive suite the return on investment from these vendors? You can't," said Razman, urging companies to only use those that truly bring value to their business.

Finally, organisations must plan for "chaos they can't control", said Ramzan, which means an incident response plan that has the 'ABCs' availability, budget and collaboration.

On availability, Razman said an incident response plan shouldn't be a wishlist; it needs to be solid. "It sounds obvious, but it's such a common mistake," said Razman, giving the idea of putting "empty fire extinguishers in every hall" as an example of good intentions that will in fact be useless in a real emergency.

Budget, he added, is absolutely vital, because there will be unexpected costs.

"An incident response plan without budget authority is a fairytale," he said.

The final element collaboration is important because every department, from finance to legal to marketing and others all have important roles to play when an incident takes place. Therefore, these teams must be working together beforehand, during the planning phase.

"People will be working 24/7, camping out at the office. That's not the time for introductions," said Razman.

Features editor Jane McCallion is on the ground at RSA Conference 2017 in San Francisco all week. Follow her on Twitter for live updates and bookmark our dedicated page for more coverage from the business security conference.

Image credit: Jane McCallion

Featured Resources

Four strategies for building a hybrid workplace that works

All indications are that the future of work is hybrid, if it's not here already

Free webinar

The digital marketer’s guide to contextual insights and trends

How to use contextual intelligence to uncover new insights and inform strategies

Free Download

Ransomware and Microsoft 365 for business

What you need to know about reducing ransomware risk

Free Download

Building a modern strategy for analytics and machine learning success

Turning into business value

Free Download

Recommended

What does a CISO do?
Careers & training

What does a CISO do?

12 May 2022
Business value on AWS
Whitepaper

Business value on AWS

27 Apr 2022
How to delete a Facebook business page
social media

How to delete a Facebook business page

11 Apr 2022
What is Business Intelligence (BI)?
business intelligence (BI)

What is Business Intelligence (BI)?

3 Mar 2022

Most Popular

Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
Costa Rica declares state of emergency following Conti ransomware attack
ransomware

Costa Rica declares state of emergency following Conti ransomware attack

10 May 2022