Show Filters

Top Results

Cybersecurity Risk-Based Business Plan

Security Program Design

  • Used NIST Cybersecurity Framework (CSF) to develop security capabilities within business requirements and industry best practices

Stakeholder Education

  • Leveraged CSF, supporting industry information, and program documentation used to educate on security protocols and justify investment

Clarified Communication

  • Communicated security program and value to C-Suite to support business security decisions.

Challenge

A midsize southeastern energy company had a relatively new security technology department focused on implementing security technologies. The team was working on communicating the value of recent security technology investments.

Process

  • Aligned security capabilities with the NIST Cybersecurity Framework (CSF)
  • Identified the capabilities expected to be in place and the required supporting documentation
  • Utilized CSF and supporting industry information to guide priority and timing of implementation
  • Used maturity levels to report status on security improvements and improvements to risk profile
  • Maintained CSF functions throughout communications to consistently educate security stakeholders
  • Established capability and technology roadmap with security practices model, technical protective controls architecture, and segmented network architecture
  • Developed detailed work plans for key security technology focused projects
  • Documented a playbook to define responsibilities, procedures, and roles associated with each department

Result

  • Developed a roadmap to implement a cybersecurity framework to mature security capabilities enabled by security technology investments
  • Prepared the organization for CISO/CSO governance and oversight activities
  • Provided a method of communicating security program progress to senior leadership

Related Insights

Let’s Work Together

We don’t solve problems with canned methodologies. We help you solve the right problem in the right way. Our experience ensures that the solution works for you.