Ice Cream Shop or Military Base?

Cyber security can often feel like a game of absolutes — either we’re secure or we aren’t. But it’s more complicated than that. The answer is almost always that we’re somewhere in between.

Cyber risk, like all other risk, exists on a spectrum. We have to decide how much risk we can tolerate, then apply treatments and other mitigations to close the gap. Determining that tolerance is one of the most important technology decisions boards and executives make — it informs the whole cyber security program.

But how do we know what our risk appetite is?

One discussion exercise I run with organisations helps find the answer. Everyone in the room gives a number from 1 to 5 describing the organisation’s ideal cyber risk posture. One is an ice cream shop. Five is a military base.

The purpose isn’t to land on some point in between that describes us perfectly. The purpose is to have an open conversation about the kinds of risks we face, the ways we use technology, and how much tolerance the business has for disruption.

Take the ice cream shop. We’re probably taking digital payments and using some systems for ordering ingredients and managing staff, but we aren’t storing sensitive customer data. If we go offline, we can keep operating on cash, or take payments from a backup mobile terminal. Cyber hygiene still matters, but security may not be a major area of investment. Even at the low end the basics are non-negotiable — the scale starts from one because no one is at zero.

Now think about the military base. Security is top of mind. We’re storing extremely sensitive information, and we need assurance that it hasn’t been accessed without authorisation or altered. The success of our information systems can be a matter of life and death — we rely on them for far more than information storage, from accessing controlled stores to communicating time-sensitive orders and managing access by identity and clearance. Here there’s serious investment in a layered security program that is continuously monitored, reviewed, and improved.

Most of the organisations I work with land somewhere in the middle. The exercise gives us a group conversation that can challenge assumptions and build a consensus on what our ideal posture looks like. Usually we start with a few different positions in the room — some say three, some say five — and over the course of the discussion we work out why those positions were chosen. I’m yet to work with a group that couldn’t reach a consensus to carry forward into the decisions that follow.

From there, I most organisations benefit from formalising the output of that discussion in a risk appetite statement. That can be used alongside governance activities like reviewing cyber risk assessments, developing treatment plans, or shaping an organisational cyber security program. As leaders, we can direct investment more confidently and understand the trade-offs we’re making with risk because we’ve had a clear conversation about what it actually means for our organisation.


 This article was originally published here on Linkedin as part of the Leading Digital series from Longitude Advisory.

← Back to Resources