Cybersecurity versus cyber risk
While (cyber)security and cyber risk have more than enough publications, they are often mistaken to be the same thing.
The purpose of this section is to help you reflect on reshaping the traditional understanding of doing security from an IT-centric perspective to practicing security while having a holistic understanding of the organization’s needs and requirements. This will help you perform a dynamic risk management assessment for appropriate security measure implementation.
Cybersecurity
Most organizations assign the security domain to their respective IT departments by designating a set of limited individuals almost working in isolation. Doing so introduces three limitations to their cybersecurity mission:
- A limited scope only related to the infrastructure stack with no or limited consideration to critical business applications
- Limited knowledge of the organization’s business continuity plan
- The operations team...