Entry 13

How should we approach the development of cyber-policy and -infrastructure given the “short arm” of predictive knowledge?

When discussing cyber threat predictions it is always a challenging topic. There are so many different reasons behind a cyber attack. Just when the government finally conquers one cyber attack there is a new one that they have yet to prepare for. This is why we see so many different response plans. Technology is ever-evolving, and cyber criminals seem to be getting smarter as well which makes it more and more difficult for the government and regular businesses to combat. Companies or organizations or strong infrastructures need to have strong security policies in order to protect things like assets, and other valuable information pertaining to their business or employees. It is found that each year cyber threats are accountable for over a billion dollars stolen from businesses and organizations. “As breaches become the new norm, having a cybersecurity policy becomes not just a matter of saving face, but of saving money, data, and valuable employee resources. Each year, thousands of breaches take place around the world, resulting in the theft of over 1 billion records of personally identifiable information.” In addition, the Ponemon Institute’s 2015 Cost of Data Breach Study, the average total cost of a data breach increased 23 percent over the past two years to $3.79 million. The sustainability of the business hinges on what every employee does, both internally and externally,” says Davis Truong, Enterprise Architect for Malwarebytes. Cybersecurity policy should include, which security policies will be implemented, how updates and patches will be applied to information systems, and how often data will be backed up. When planning these security policies, businesses should refer to the NIST in order to best secure their information. Cybersecurity policy should clearly address an organization’s security needs and communicate best practices for users in order to mitigate risks of cyber incidents.