Using Metrics to Tell a Security Risk Story episode artwork

EPISODE · Apr 6, 2020

Using Metrics to Tell a Security Risk Story

from Info Risk Today Podcast · host InfoRiskToday.com

Metrics can help CISOs clearly communicate the potential impact of risks to senior executives and win support for a risk management strategy, say Randall Frietzsche, enterprise CISO of Denver Health, and consultant Dave Bailey of CynergisTek, who describe a step-by-step approach in a joint interview.

Episode metadata supplied by the publisher feed · Published Apr 6, 2020

Embed this episode

NOW PLAYING

Using Metrics to Tell a Security Risk Story

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

I'm Marianne Colbusak-McGee, executive editor and information security media group, today I'm speaking with Randall Fricci, enterprise CISO at Denver Health, and Dave Bailey, director of security services at Consultancy Synergistic, about how organizations can better leverage metrics to tell their security risk story. So Dave, as you work with healthcare sector entities, what do they struggle with the most when it comes to making risk assessment data actionable? What kinds of data and metrics are we talking about when it comes to effectively illustrating security risk? What sorts of metrics should be leveraged?

When we go in and assess the health system industry, what we generally find is that for the most part, the folks that run their IT service delivery, they've got a good understanding of how they deliver their service to the clients, how they impact patient care from their systems. What is difficult is when you overlay security risks and how you address the risks of today, whether that be financial risk from data breach or whether that's patient safety from the fact of a true hack from a cyber perspective, it's really difficult to be able to take that risk from a CISO and translate it up to the business so they can make the right decisions. There isn't enough time, money and resources to be able to address all their risk and they have to be able to continually assess risk and be able to communicate to their leadership to be able to make, you know, what I consider to be the best decision. Everyone may make a different decision, but they have to be able to make the best decision at that particular time, knowing that they don't have enough time on your resources to address everything.

On the second part of the question, when it comes to what types of metrics, it's really, really important to be able to take the IT speak and look at the business aspect of it. So these are things like what type of gaps do I have by my assets and by my systems and how many risks do I have for each of these things and how does that translate to some business line? I think those are the metrics that are really, really important to be able to tell that story. Randall, what can you tell us in terms of how your organization is leveraging metrics to tell a risk story that puts risk data in perspective for your internal audiences and who is part of that internal audience?

As Dave said earlier, you don't have infinite resources, so the foundational part of risk management for me is having a very strong and mature foundation. And that foundation includes things that make us more efficient at doing that and less impactful for the business. And so that's why we always do risk stratification, and inject it into the purchasing stream. That way, any contracts that we're going to sign with the business, we have high-level risk stratification questions, what kind of data, how much data, what is the way we're going to share it, how is the vendor going to have it, are they going to put it on the public internet, web portal, so forth.

Those are the risk stratifiers for me that tell me what else do we need to do, if anything, with this particular contract. And that way, we don't do one size fits all cookie cutter and blast everything with the same volume. We do it according to how that risk is stratified. And then we tier that vendor in terms of the risk.

If it's all of our patient data on a web portal, that's a tier one vendor, that's a very high-risk vendor for us. Or tier two or tier three lower risks, less amount of data, less sensitive data, less risky ways of presenting the data. So that's for us very important key there, that helps us build those relationships, the organization, because they know that we're driving to make us as efficient we can. So we do have the appropriate security risk analysis done, but we're not holding up the business.

And I think that's key for everyone to see why it's important to participate. And then from that, we, sort of speaking to what Dave said, we assess against the set of control objectives, and that set of control objectives should be based on some accepted framework. And we use the NISTs, cyber security framework for that. So we assess the vendor, or we assess the change within our organization against the control objectives, and then we will risk rate those.

And when we risk rate those, we also tie them to a business risk, like legal, regulatory, patient safety, financial, reputational. We tie those control gaps to a business risk. And when we do that, we score that risk. That adds a certain number of value to a risk bucket.

That risk bucket is financial risk, legal risk reputation, and so on. And I can say I've added 10 risks or 10 control gaps to my financial risk bucket, where I've mitigated risk around my reputational risk bucket. And that way I get those metrics in a way that the organization understands why we're doing. It's aligned to their goals.

And also I can show trending up or down. This is the work that we're doing in this area. And you can see the results, or here in our, here's an area that we need more work on. And so we have a couple initiatives, and that way you justify that initiative that you need to help address those risks for the organization, in a way that is speaking their language.

Randall, in addition to financial risk, what's your advice for how healthcare sector entities can translate their privacy, security, and compliance risks into business risks in order to engage the C-suite on identifying organizational risk tolerance and priorities for risk mitigation? Well, that's where you really need to understate your business well. I mean, down to the financials, because if I work in a health organization and we have PACS, which is our imaging, MRI, X-rays, and so forth, and we have that very sensitive, but large amounts of data, very big files. If a hospital gets ransomware into their PACS systems and it encrypts all of their imaging, and any new imaging is encrypted, then they have to go into virtue.

You can't image a patient. You can't treat that patient. So you have to go into virtue. Well, the virtue is a dirty word in healthcare.

And from my experience, mid-sized hospitals, it's about $10,000 a minute if you have to go into virtue. So I say the risk of ransomware is not just encrypting our data, it is going to put us on the verge of cost is $10,000 a minute. And then if I equate that over large files, restoring from backup, that's a week, two weeks, three weeks, you're talking millions and millions and millions of dollars. That's what the organization hears clearly.

If I just say I can't let ransomware in my PACS environment, they don't get that. But if I say $80 million, $80 to $100 million risk for a security breach, then they wake up and they go, wow, we get it now. That's for me very important to be able to understand the business really well and then use that to coach and frame your message to your board and to your executives and to your business leaders. Dave, as you work with healthcare sector entities, what mistakes do they make that they should try to avoid in achieving this?

This is a very, very prominent question in my humble opinion today. And folks, they have to assess risk on a cycle, right? So it is their obligation to go in and do these risk assessments. And a lot of times what happens is everyone, generally speaking, in order for me to determine what your risks are, I have to go look at your gaps, right?

I have to identify what your vulnerabilities are. And when you do those types of assessments, you generally tell an organization how mature they are. And a lot of organizations do look at those maturity scores and they consider them to be very important. Now, I don't want to say to someone that their maturity scores aren't important because it is a very, very good indicator of the type of processes that they have in place.

I mean, you're telling an organization, either they're effective in implementing those controls or they're not effective. Well, in the long run, what those vulnerabilities and those controllers have to lead to is a set of gaps. And really what has to happen is they have to do the risk analysis on those gaps. And when they determine what they're going to do, like how they're going to spend their time on the resources, really it should be a risk discussion only.

And a lot of times, you know, there's a lot of leadership, they get focused on the score. They get focused on whether I'm compliant or not or how I relate to the framework. And once again, I don't want to mislead this audience to say that I don't think that's important. I just want to place an emphasis where really is.

And the emphasis is, the byproduct of that is what your gaps are. From those gaps, you determine what your risks are. And I want to be able to help organizations say, hey, these are your risks. And here's how you need to prioritize them.

Now, why Randall is here from Denver, which I think is a really very good practice. And when you look at what I consider to be a mature organization, it's how do you take that information and translate it into the business discussion? So when you go to leadership, you're having the business discussion and you're not saying we need to go from a maybe a 5255 and then it's CSF. But we need to say, hey, we have too much risk around data encryption that could lead to data breach and here are the things that we need to do.

So the focus of the discussion is on the risk and how that risk is going to impact the business. So I think while the framework assessments is the foundation to lead you to the risk, it's really helping the industry focus on what that outcome is, what the risk is and where they should focus their efforts. It is very nice to see when an organization, as I felt, done a very good job of doing, like, instead of the active risk management, like they're taking their risks, they're prioritizing them, they're putting in the data that makes it relevant to them and their business, and they're making the determination, they're accepting risk, they're mitigating risk and they're able to tell their story. In my humble opinion, it doesn't mean that they're not going to have adverse effect in the event that something were to happen.

But what I've seen is that organizations have minimal impact when that happens and I've even seen in some cases where organizations come out of the process of something negatively happening to them in the best way they can because they do that. And when they're looked upon either by a regulator or by some litigation action that it is determined that they are doing their due diligence. And when you can demonstrate that, you know, you do put yourself at the best financial situation. And heaven forbid today, not going to, I don't want to see the time in healthcare where some cyber event leads to a patient incident.

We have a lot of indirect incidents right now, but I hope we don't get to that point. And right now, I think organizations need to really focus on how they are managing risk because unfortunately, today's threat, what the threat actors are, what healthcare is out to face, it's really throwing at an alarming rate and not necessarily at the same rate as the maturity of those programs. Thanks, Randall. Thanks, Dave.

I've been speaking to Randall Fitchy, Enterprise SISO at Denver Health, and Dave Bailey of Synergist Tech. I'm Mary Ann Kolbasek McGee of Information Security Media Group. Thanks for listening.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 6, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!