2016年-德勤全球_Assessing_cyber_risk_17页_3mb
报告摘要
Deloitte Cyber Risk Assessment Summary
Core Content
Deloitte's Assessing Cyber Risk guide emphasizes that cyber risk is not just a threat to be mitigated, but a strategic opportunity that can drive business performance. The document outlines a framework for boards and C-suite leaders to evaluate their organization's cyber risk posture and align it with broader business objectives. It positions cyber risk as a key component of organizational maturity, with the ultimate goal of achieving a secure, vigilant, and resilient business environment.
Main Views
- Cyber Risk as a Value Creator: Cyber risk is not only a challenge but also an opportunity to enhance performance through better technology adoption and globalization.
- Leadership Responsibility: The board and C-suite must take an active role in understanding and managing cyber risk, as it affects all parts of the business and its ecosystem.
- Cyber Maturity Scale: Organizations are evaluated on a maturity scale (High, Moderate, Low) based on their approach to cyber risk management, from foundational security to proactive, integrated strategies.
- 10 Critical Questions: A set of 10 questions is provided to help leaders assess their current state and identify areas for improvement in cyber risk management.
Key Information
1. Do we demonstrate due diligence, ownership, and effective management of cyber risk?
- High maturity: Board and C-suite are actively involved, have clear policies, and challenge management on cyber issues.
- Moderate maturity: Oversight is present but lacks depth, with limited challenge and high-level assessments.
- Low maturity: No formal framework, and cyber risk is not a priority for leadership.
2. Do we have the right leader and organizational talent?
- High maturity: Cyber leaders have both technical and business skills, and there is a strong, aligned talent strategy.
- Moderate maturity: Cyber leaders focus on technical risks, and staff knowledge is limited.
- Low maturity: Cyber knowledge is siloed in IT, and there is no strategic investment in talent.
3. Have we established an appropriate cyber risk escalation framework?
- High maturity: Escalation is clearly defined, integrated with risk appetite, and supported by policies and procedures.
- Moderate maturity: Escalation is not consistently integrated, and processes are ad hoc.
- Low maturity: No formal framework in place, with ad hoc responses to incidents.
4. Are we focused on, and investing in, the right things?
- High maturity: Cyber investments align with strategic goals, with clear business cases and focus on critical processes.
- Moderate maturity: Investments are not aligned with strategic goals, and there is an imbalance in security measures.
- Low maturity: No clear cyber strategy, with minimal investment and no business justification.
5. How do our cyber risk program and capabilities align to industry standards?
- High maturity: Cyber programs are aligned with industry standards, and regular benchmarking and compliance checks are performed.
- Moderate maturity: Some best practices are implemented, but alignment with standards is inconsistent.
- Low maturity: No reference to industry standards, with only minimal compliance efforts.
6. Do we have a cyber-conscious culture?
- High maturity: A strong, company-wide culture of cyber awareness and responsibility is established.
- Moderate maturity: Awareness is present but limited to specific groups or functions.
- Low maturity: Awareness is reactive and focused only on IT, with little emphasis on broader business implications.
7. What have we done to protect against third-party cyber risks?
- High maturity: Third-party due diligence and risk management are formalized, with clear policies and training.
- Moderate maturity: Some steps are taken, but due diligence is inconsistent.
- Low maturity: No formal measures in place for third-party risk management.
8. Can we rapidly contain damages and mobilize response resources?
- High maturity: Comprehensive incident response plans are in place, integrated with business continuity and disaster recovery.
- Moderate maturity: Basic response policies exist but are not fully integrated.
- Low maturity: Minimal or no incident response plans in place.
9. How do we evaluate the effectiveness of our cyber risk program?
- High maturity: Regular assessments, internal and external reviews, and lessons learned are part of the process.
- Moderate maturity: Assessments are periodic and not always applied to improve practices.
- Low maturity: Assessments are sporadic or nonexistent.
10. Are we a strong and secure link in connected ecosystems?
- High maturity: Proactive sharing of threat intelligence and strong relationships with partners and regulators.
- Moderate maturity: Ad hoc sharing and limited collaboration.
- Low maturity: No external relationships or information sharing.
Strategic Recommendations
- Set Cyber Maturity Goals: Leaders should define a target state for cyber maturity that aligns with strategic objectives.
- Develop a Holistic Cyber Strategy: Cyber risk management should extend beyond IT and include all business processes, partners, and customers.
- Invest in Talent and Leadership: Cyber leaders must have both technical and business acumen, and the organization must support a culture of cyber awareness.
- Improve Cyber Resilience: Organizations should focus on not only securing systems but also being vigilant in monitoring threats and resilient in responding to and recovering from attacks.
Contact Information
- Nick Galletto: Global Cyber Risk Services Leader, Email: ngalletto@deloitte.ca, Phone: 416-601-6734
- James Nunn-Price: Asia Pacific Cyber Risk Services Leader, Email: jamesnunnprice@deloitte.com.au, Phone: +61 2-9322-7971
- Ash Raghavan: Global Cyber Center of Excellence Leader, Email: araghavan@deloitte.com, Phone: 212-436-2097
- Chris Verdonck: EMEA Cyber Risk Services Leader, Email: cverdonck@deloitte.com, Phone: +32 2-800-24-20
- Ed Powers: US Cyber Risk Services Leader, Email: epowers@deloitte.com, Phone: 212-436-5599
Conclusion
Deloitte encourages organizations to treat cyber risk as a strategic imperative, not just a technical challenge. By answering the 10 key questions and aligning with industry standards, leaders can build a more mature, resilient, and value-creating cyber risk management program. Cybersecurity is not a static effort but an ongoing journey that requires continuous improvement, leadership engagement, and cultural transformation.
试读结束,高清完整版pdf/doc/ppt,请点下载