There is no question that the web has changed the way we do business and conduct our personal online presence . The power of high speed data calculations and instant communication have enabled incredible developments. The technical landscape has also developed the conditions for advanced means of sabotaging, stealing or otherwise exploiting others’ work. Information assurance is the goal of anyone whose created an organisation that holds any kind of data.
There is a liability associated with owning a web domain, website or network, particularly if your users, employees or other stakeholders entrust you with their personal data. This applies even if you’re a small business, given that on average, SME’s fail within 6 months of a cyber-attack, being hacked undoubtedly threatens your organisations existence and the livelihood of your employees. In the EU GDPR was supposed to help with data protection, yet many organisations remain woefully at risk.
Enormous volumes of threat intelligence data have been collected, stored and made useful. There are different ways to categorise cyber-security threats, by timing, by threat actor, or by their place along the cyber kill chain. The arguably most useful way to prioritise security threats is by their capacity for disaster. Different scoring and evaluation systems have been authored to quantify and address security status and risks.
Research organisations, industry members, and government bodies have been collaborating for years to develop a universal threat metric. Several different criteria and measurement rubrics have been created as result of these collaborations. These respective models generally focus on some universal aspects of online security:
- Specific threats
- Identifying weaknesses
- Security best practices
- Testing applications for resilience against attacks
- Study of education, training, and security practices in “real life”
- Quantifying economic value of information assurance
- Privacy concerns
- Risk assessment
The appropriate measurement tool can depend on your objective. It is possible for your own team to develop individualised cybersecurity risk measurement tools. You can measure and rank incidents and then prioritise specific vulnerabilities to address. Rank threats by the amount of regular effort in the IT department it would take to resolve the hack, in creating new accounts and such activities.
You can measure the number of stakeholders whose data was compromised. Many businesses will, regardless of other steps, need to quantify risks in terms of the bottom line. The monetary value of losses is a figure comprised of several major costs.
There could be criminal liability charges brought against you if your company is determined to be dangerously negligent. Not only can victims sue for damages, but governments in both the USA and Europe are stepping in and mandating network security measures in the name of personal data privacy and for the benefit of data integrity, eCommerce safety and national security. Whilst GDPR is now enforceable within the UK, organisations have been remarkably slow and reticent in ensuring compliance, with up to 68% of companies yet to even clean their organisational storage systems of out of date and “no reason to be held data”. Promoting the ICO this week to warn that a more robust approach to compliance is now to be utilised.
Measuring cybersecurity risks only helps you prepare for specific risks. These activities in self-reflection will make your organisation stronger. You can also determine the ROI of your threat intelligence program. By comparing your recent history with scenarios and projections, your efforts are validated.
InstaDigital offer a full threat assessment and Penetration Testing Service, contact us today for an informal chat to protect your clients, your data and your brand integrity.







