Enterprise Cyber Risk Management as a Value Creator
摘要
Over the last 40 years, I’ve enjoyed helping organizations comply with various privacy, security, and breach notification regulations and standards and improve their enterprise cyber risk management and cybersecurity posture. These efforts have been primarily defensive. The focus of my defensive work with healthcare organizations, for example, is captured in the subtitle of my book Stop the Cyber Bleeding,2 as How to Save Your Patients, Preserve Your Reputation, and Protect Your Balance Sheet. The verbs “save,” “preserve,” and “protect” are about safeguarding, assuring, and “managing the downside.” Although critically important, “managing the downside” does not align with the language of most companies' strategic objectives, which include creating value, driving revenue growth, and enabling their business. In other words, those defensive verbs are not about using cybersecurity to “create and manage the upside.” You need to think about cyber opportunities that can help achieve your business goals.