managing and insuring cyber risk - a risk perspective

20
A risk perspective Risk Management, Cyber & Insurance Dr Russell Price

Upload: iispeastmids

Post on 10-Aug-2015

182 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: Managing and insuring cyber risk - a risk perspective

A risk perspective

Risk Management, Cyber & Insurance

Dr Russell Price

Page 2: Managing and insuring cyber risk - a risk perspective

Introduction

Chairman of the Continuity Forum

Founding member of Cyber Risk & Insurance

Forum (CRIF) & Chair of GRS committee

BSI UK Risk Management Committee Chairman

ISO 22301, ISO 31000, BS 65000 & 31100

ISO 27000 – 27005

Cyber Essentials

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 2

Page 3: Managing and insuring cyber risk - a risk perspective

A riskier world?

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 3

Value of Tangible assets

Risk Management –A changing framework

1970’s 2015+

Production based economy

Mainly National/Local

Founded on Plant, Labour etc

Knowledge based

economy

REPUTATION

Value of Intangible assets

Knowledge

Reputation

Management

Image

Traditional

Asset

Protection

Page 4: Managing and insuring cyber risk - a risk perspective

Business Risks

27/05/2015 cyberriskinsuranceforum.com© 2015 Page 4

Page 5: Managing and insuring cyber risk - a risk perspective

What wasn’t included?

27/05/2015 cyberriskinsuranceforum.com© 2015 Page 5

PROFITS

Page 6: Managing and insuring cyber risk - a risk perspective

Risk Management

Big topic

Wide scope

Regulation

Compliance

Contract

Legal

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 6

Page 7: Managing and insuring cyber risk - a risk perspective

Risk Life Cycle

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 7

Issue ManagementEarly Issue Identification

Pressu

re /

Cost

/Im

pact

Opportunity to Influence

Difficult to Influence

Potential Current Crisis DormantEmerging

Period of Increasing Awareness

Origin Development ResolutionImpact

Time / Development

7

Page 8: Managing and insuring cyber risk - a risk perspective

The learning experience

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 8

1860’s 1970’s

Page 9: Managing and insuring cyber risk - a risk perspective

Risk Management Process

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 9

GenericApplied to all areas of operations & activities

Adaptive Works in the context of the organization

ExpectedDemonstrates ‘good practice’

ConnectedWorks in the context of the organization

Source ISO 31000

Page 10: Managing and insuring cyber risk - a risk perspective

Cyber Risk

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 10

We all have some

It needs to be understood

It connects & spreads between

organizations

Not just a technology issue It is a

core business RISK!

It must be managed BETTER!

Page 11: Managing and insuring cyber risk - a risk perspective

Addressing your Cyber Risk

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 11

Level 4

Level 3

Level 2

Level 1

WHERE ARE YOU?

Page 12: Managing and insuring cyber risk - a risk perspective

Informed on Risks

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 12

Intelligent Decision Making

Realistic risk assessments

Better Performance

+

=

Page 13: Managing and insuring cyber risk - a risk perspective

Demonstrating Good Practice

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 13

Page 14: Managing and insuring cyber risk - a risk perspective

The Insurance Sector

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 14

Very Mature across many sectors

Complex

Global

Conservative

Tightly regulated

It is a business!

Page 15: Managing and insuring cyber risk - a risk perspective

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 15

Control Areas

PreventionPrevention

Physical Security

Network

Security

Infrastructure Security

Policy

Awareness

DetectionDetection

Fraud

Auditing

Intrusion Detection

Security Event Management

Systems Management

ResponseResponse

SOC

CIRT

Forensic Investigation

Crisis Management

Training

ResidualResidual

Cyber Liability

First Party

Third Party

Page 16: Managing and insuring cyber risk - a risk perspective

Evidence

Planning

Activity

Capabilities

Context

Hard and Soft controls

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 16

Preparation

Prevention

People

Relationships

Processes

Proactive

Page 17: Managing and insuring cyber risk - a risk perspective

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 17

If it was your money

would you want to:

See how the risks would

impact on the business

What the effective

capabilities really were

Know that the firm is acting

responsibly

Now fill in an Application Form

Page 18: Managing and insuring cyber risk - a risk perspective

Summary – A Global Change

Awareness of risks

Responsibilities

Amplification

Expectations

Measurement

Convergence

Capabilities

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 18

We know more

Legal and Compliance

Expansion & Cascade

effects

Stakeholders & Media

Ability to assess &

manage

Interaction & connection

Ability to act

Page 19: Managing and insuring cyber risk - a risk perspective

Questions

cyberriskinsuranceforum.com

[email protected]

+44 (0) 208 993 1599

@cyberriskinsure

Russell Price

[email protected]

07770 666004

Page 20: Managing and insuring cyber risk - a risk perspective

21/05/15 © cyberriskinsuranceforum.com © 2015 Page 20