Skip to content
![]()
Cyber Risk – Understand & Protect
Here are a few problem statements you should ask yourself & your team:
What Are My Critical Assets?
- You will want to discover and record your assets
- Understanding the asset inter-dependencies, verification of assets & assigning associated risk ratings will be next
- Classifying the priority of each asset is paramount to determine monitoring & performance measures
Do We Have Reasonable Security Controls?
- Have we implemented the necessary security controls to protect our critical assets?
- How effective are our controls at preventing and detecting threats / events?
- How often do we review these controls?
- Do we review our security strategy regularly & include emerging risks and threats where our environment is changing?
What Monitoring Do We Have?
- Do our security tools provide actionable reports, alerts & insights to effectively monitor our environment?
- Back-in-time forensic capability
- Alerts & system logs are securely correlated & classified by severity
- Roles are defined for security operations & include escalation procedures for security incidents
Is Continuous Testing Necessary?
- What is our approach to cyber threat / risk management ?
- Do we focus on reacting to threats or incidents? OR
- Do we focus on pro-actively identifying threats / risks before they are exploited?
- If you follow the pro-active approach then continuous testing is necessary
Will Our Incident Response Process Be Effective?
- Do we have documented & communicated incident response & recovery plans?
- Is there a back up plan, which is tested regularly & updated with changes?
- Will our staff & stakeholders know how to react & respond to an incident?
- Will our off-site / off-line back up allow us to successfully restore operations?
Are We Covered With Zero Trust?
- Does our security framework always ensure we verify & authenticate before we trust a user, device or application?
- Access is limited to the task and/or role?
- An ongoing monitoring & risk process is in place to detect & respond to threats?
- Access is conditional based on identity, device posture, location, time of day etc
We Understand Cyber Risk, We would love to discuss with you how to – Understand & Protect What Is Critical To You & your enterprise…