For most of us, alerts are a constant in our working day. We get reminders about meetings, notifications from dozens of apps, and other signals regarding activity we should act upon right now. For the technology leader, however, cyber alerts take priority over all others. But knowing about a security breach is pointless unless you know how to properly react in context.
You may quickly be able to resolve certain technical questions. After that comes the even more crucial issues to solve: who’s the culprit, what is their goal, is this an isolated event or part of a larger attack, and what is the appropriate response? Indeed, responding to cyber alerts is perhaps more about how to make decisions than it is about having technical savvy.
CIOs have to move fast, shortening as much as possible the gap between the alert and the action. This is commonly known as decision latency. Even if you make decisions in a relatively quick amount of time, it still might not be quick enough. And to add more complexity to the equation, speed in itself isn’t always the winning formula. In fact, fast decisions may not include the requisite judgment needed and, in turn, actually make the problem even worse.
This is why CIOs should use a cross-discipline approach for resolving security alerts. Keep in mind that a timely and effective cyber response involves more than the technical and security teams. Legal, risk, compliance, finance, procurement, communications, and business operations must play a role as well. Not to mention other parties like law enforcement, intelligence agencies, regulators, financial institutions, and partners. Also consider that CIOs don’t always have leeway to make independent decisions, as they may be constrained by the organizational structure and other dependencies.
To make the issue more complex, many enterprises – surprisingly – don’t have an established decision model. You can have all the necessary data, facts, and technical strategies on hand, but lack clarity on who makes the final decision. This ambiguity points to a defect in organizational design, not technology, so no amount of generative AI will clean up the mess. A potential solution is to develop a cyber strategy that aligns with the organization’s broader strategy. Doing so will enable a level of cyber maturity that separates world-class organizations from the also-rans.
Part of the problem is having the wrong perspective on cyber security. It’s not about how many controls you have deployed or the manner with which you perform system monitoring – it’s about being able to make quality decisions when everything is on the line.
More effective and efficient decisions come about through what experts call integrated intelligence. The concept tells us that the true value of data is not its volume, but rather in how it can filter the trivial from crucial and provide prioritized information. We then have the ability to distinguish pure technical activity from activity that connects the strategic dots. All which allows us to understand the most relevant issues regarding the alert and act accordingly.
Companies have improved their responses to cyber alerts by engaging in rehearsal scenarios. They test how they would act during a legitimate security breach. They identify what went right and wrong, and improve by assessing the gaps between the two. Exercises like this are valuable for employees, analysts, managers, and executives, who are often expected to have perfect judgment in inherently uncertain circumstances, all while battling distractions and equipped with too little time.
Uncertainty will never cease to part of how we respond to cyber alerts. CIOs will always have an incomplete set of data to inform their decisions. But with a plan built on concrete steps, organizations can vastly improve their readiness in the security trenches.