We are constantly told that once the pandemic subsides, we will enter a ‘New Normal’. Many people are trying to predict what that ‘normal’ will be, but the truth is, no one knows. Undoubtably, some people who have got used to working from home will want to stay there. Why do a horrible commute if you don’t have to? Some businesses will streamline in order to recover some of their losses. Some businesses will thrive.
One thing that will remain common is the threat from internet enabled crime or, as it is commonly referred to: Cyber Crime. In fact, it is likely to increase. As businesses change, re-structure and re-focus, the cyber criminals will look to take advantage of any uncertainties such situations create.
Also, in common with the old world, will be the difficulty in communicating cyber risk to the board. Actually, it will probably become harder as their priority will be to keep the business running month to month. Cyber will probably not register.
I have been reflecting on the way we, the IT security profession, communicate with the decision makers and the information we present them to help them to make decisions. In reality, we don’t present them with much that Boards easily understand.

When we talk to them about risk we generally tell them that something has a low, medium or high risk of happening and if it does happen, it can have a low, medium or high impact on the business. These levels have been pseudo calculated in some way using a chosen risk methodology. We are all familiar with the risk matrix in figure 1, but what does low, medium or high likelihood mean? What does low, medium or high impact really mean? Boards deal in figures, tangibles, things that can be quantified and we have not yet translated cyber risk into real-life meanings. No wonder they are not listening.
In the world of the ‘new normal’, we are going to be competing with even more distractions at board level, therefore our message on cyber risk has got to be more concise and eye catching. At Sandettie, we have developed a new risk assessment tool which will give Boards the information they need to make the important decisions. We have taken the approaches used by the insurance and actuarial industries which model risk in financial values and we have developed a risk assessment tool which models an organisation’s financial exposure to cyber risk.
Imagine the reactions from a board if you presented them with a simple graph which showed their current financial cyber risk exposure as shown in Figure 2. This particular graph, which is generated using a computer-based simulation, demonstrates the range of financial exposure for a given risk.

The X axis represents the probability of a loss in percentages and the Y Axis the potential loss. The simulation that was run in this scenario showed that the maximum exposure was £320,000. The minimum was zero because, of course, an event may not occur. However, there is a 35% chance that in any one year, this organisation could experience a loss of £45,000. Now that means something to the board.

In the second graph, shown in figure 3, we show the effects of spending £10,000 on implementing controls. The first thing that is evident is that the chance of this risk materialising is reduced from 38% to 12.5% and the risk of incurring a £45,000 incident is reduced to 11%. This information facilitates the board in making a reasoned decision.
As money gets tighter, boards will need to make what they have go further. Presenting them with information that is not easily understood will relegate it to the ‘too hard to deal with’ pile. Presenting information in a format which promotes quick interpretation will result in reasoned and informed decisions.
You can develop your own risk assessment tool based on this approach. There are many publications on the subject, in particular: How to Measure Anything in Cyber Security Risk by Douglas W. Hubbard and Richard Seiersen. There are also many texts on insurance risk and actuarial risk. Alternatively, you can speak to us and we would be more than happy to run your risk assessments and help prepare your board report.
Peter Loomes – Is a Director of Sandettie Ltd. a specialist Cyber Security, Privacy and Digital Transformation Consulting Practice. Peter is a Certified by the NCSC as Cyber Security Professional specialising in Security and Information Risk Assessment.
They are all extracted from statements from companies that have experienced a data breach.
December was the last time I blogged about GDPR. I can’t believe it is 7 months. It isn’t because I got bored of GDPR and gave up talking about it, it was because between January and June, my feet didn’t touch the ground. There was a massive demand for GDPR advice. In June I took a bit of a well-earned break and when I return in July, I see the entire world seems to have forgotten about GDPR.

It is clear that the 
It is a big week for all things GDPR (General Data Protection Regulation).
25th May 2018 is now only 257 working days away. Some reading this may wonder what the significance of that date is. Actually, according to a survey I conducted recently, probably about 33% of readers will be asking that question. Friday 25th May 2018 is GDPR day. The day our current Data Protection Act is retired in favour of the European Data Protection Regulation.