5 ms·
Having helped implement NIST 800-171 for a small enterprise company preparing to work prime government contracts I can assure you it costs money either way. Ti
by bojo 3y ago
Having helped implement NIST 800-171 for a small enterprise company preparing to work prime government contracts I can assure you it costs money either way.
Time and money spent working with cybersecurity professionals writing SOG/SOPs which map the business practices to the standard. Money spent buying and setting up some of the necessary equipment to handle CUI properly. Time (indirectly money) spent redoing decades old business processes to map to the new paradigm. Time (indirectly money) as the business spent time training their staff up on the components relevant to their business units.
I agree that building a culture is at the root of it, however, that culture alone isn't going to move the needle unless everything else is in place as well. Worse, you have to walk the company through the 5 phases of grief because in general people don't entirely understand what is actually going on and why it's important. "So you can get government prime contracts" is an easy answer, but doesn't erase the confusion behind all of the hand-wavy procedural work required to execute them.
- konschubert 3y agoI'm not convinced that implementing cybersecurity standards actually improves security.
- bojo 3y agoNo disagreements there. What's a better answer though? No one wants to do it, most non-tech people don't understand it, yet the standards and procedures need to improve to reduce the attack surface area - especially for businesses which support critical infrastructure.
- konschubert 3y agoYou could legally mandate companies to insure themselves against cybersecurity risks. It's really an interesting idea: https://www.cato.org/sites/cato.org/files/serials/files/regulation/2013/3/v36n1-10.pdf https://www.cato.org/sites/cato.org/files/serials/files/regu... This creates a "market for effective practices", because companies that follow good security practices would get cheaper insurance. But it would allow insurances and companies to figure out dynamically what is cost effective and what isn't. There would be lots of financial incentive to figure out what protects you effectively and what is just security theatre.
- Veserv 3y agoMost companys already do. Unfortunately for the insurance companys their actuarial tables are backwards looking and cyberattacking is one of the fastest growing industrys. The smart insurance companys are all getting out of cybersecurity insurance because the premiums on the policys they wrote 10 years ago when the average attack cost $1,000 to remediate do not look so good when the average attack now costs $100,000 to $1,000,000 to remediate. Since the expected probability of a successful attack in any given year that requires payout is approaching 100% these days the insurance needs to be priced something like 10x-100x the prevailing prices to be survivable. Eventually it will shake out once the cyberattacking industry becomes mature because at that point backwards looking projections make sense. Until that time, we are in for a wild ride.