What is cyber resilience?

By on 05 Nov 2018

fShare
0
Pin It

Learn about cyber resilience, why it's so important and how cyber resilience certification can boost your career in cyber resilience.

Introduction

In an age where we spend lots of time in cyberspace, we’re more exposed to cyber threats than anyone could imagine. Hence, it’s in every person’s interest to be cyber aware online and take steps to keep themselves and their organisations free from cyber harm.

Playing catchup

Preventing malicious cyberattacks isn’t enough nowadays, especially for large corporations and companies. Cybersecurity is always one step behind cybercriminals. That’s because as hackers find new security holes to exploit, software and IT hardware companies rush to bring out fixes to patch the hole. Cybersecurity organisations are therefore always playing catchup.

Expect to suffer a cyber breach

It’s not a question of if an organisation will suffer a cybersecurity breach, it’s a question of when. This means an organisation must assume it will suffer from a breach at some point and take steps to ensure incidents are detected promptly and the effects are corrected. It cannot rely entirely on defensive procedural and technical controls (cybersecurity) to prevent an incident [1].

Recovering from cyberattacks is vital

Organisations are concluding that protecting their assets and networks must be enforced on a much larger scale by not just preventing external cyberattacks, but also by detecting them in advance. That’s why cyber resilience is needed. Recovering business operations with as little damage as possible is vital in the aftermath of such cyberattacks.

History of cyber resilience

It all started in 1990 when the internet was born. Computers at that time had limited access to information on the web. When the need to access resources and the usage of electronic communication increased, security controls were enhanced to protect valuable personal and business information. Cybersecurity techniques weren’t enough for the dynamic and rapid changes of the digital age within large businesses, putting them at high risk with no backup plan. Therefore, cyber resilience came into existence to recover and adapt after any misfortunate cyberattacks.

Definition of cyber resilience

Cyber resilience is defined as the ability to prevent, detect and correct any impact that incidents have on the information required to do business [2]. Cyber resilience differs to cybersecurity as, in addition to preventing cyberattacks, cyber resilience detects them and corrects the damage.

Why is cyber resilience important?

Cyber resilience is extremely important because it helps organisations take the necessary measures to address risks, ensuring they can continue delivering their business objectives and outcomes in total confidence, and build trust in business relationships with internal and external customers.

We all heard of the May 2017 WannaCry cyberattack that affected the NHS in the UK. WannaCry was malicious software that exploited a vulnerability in a Windows PC which hadn’t been updated for a long time. It blocked access to NHS staffs’ computers and asked for money to release it. It may have slipped into the NHS’s network by files normally sent via email.

WannaCry had a negative impact on the NHS, as staff were forced to revert to pen and paper and use their own mobiles after the attack affected key systems including telephones. Some hospitals and doctors' surgeries in England were forced to turn away patients and cancel appointments [3].

The NHS had to act fast to recover from the damage that this incident caused. This required it to update its current software and applications and put in place a prevention strategy.

The example of WannaCry shows that the theft of customer and employee data, corporate strategies and financial records can not only cost organisations a fortune but can have serious consequences for their customers too. Consequently, preparing to deal with such threats is crucial and dealing with the consequences is a hefty task.

Course picked for you

Cyber security awareness

Learn cyber security in just 1 hour with this online course

View cyber security

Cyber security awareness

Learn cyber security in just 1 hour with this online course

How cyber resilience is performed

Corporate risk management, in addition to merging cybersecurity and business continuity management, is a framework that some organisations use to carry out cyber resilience.

Tasks, procedures and tools can help this framework to succeed, include:

  • Scope Statements
  • Gap Analyses
  • Risk Assessment Tools
  • Information Security Continuity Plans
  • Internal Audit Procedures
  • Business Continuity Policy, Objectives and Planning Procedures
  • Business Impact Analysis Procedures
  • ISO standards like ISO 27001 and ISO 22301

Some organisations integrate cyber resilience into a management system based on ITIL®[4] and this has been proven to be effective [5]. If organisations choose to base their cyber resilience management system on ITIL, they’ll often use the same lifecycle stages of ITIL - strategy, design, transition, operation and continual improvement.

Who is responsible for cyber resilience?

The departments responsible for cyber resilience typically stretch beyond the IT department, as human resources, project management and leadership & management teams are often involved. At the same time, it is always the individual’s responsibility to be cyber alert while using their personal or work devices.

Secondly, it’s the organisation’s responsibility to educate its staff about cyber resilience with up-to-date learning programmes such as induction training, awareness sessions and monthly meetings.

Finally, board members and upper management have a pivotal role in applying an efficient and practical cyber resilience strategy that protects the organisation’s assets, outcomes and interests.

What careers are available in cyber resilience?

Cyber resilience professionals are in-demand within the finance, publishing, banking, retail, marketing and law sectors. Some of the common job titles found in cyber resilience are:

  • Cyber Resilience Consultant
  • Risk Manager
  • Security Consultant
  • Auditor
  • Information Security Consultant
  • IT Auditor
  • PCI DSS Consultant
  • Penetration Tester
  • Senior Auditor
  • Senior IT Auditor
  • Senior Penetration Tester
  • Senior Tester
  • Tester
  • Audit Manager
  • Operations Manager
  • • Security Manager
  • Senior Audit Manager
  • Senior Manager
  • Technology Risk Manager
  • IT Security Auditor [6]

Landing a cyber resilience role

Getting into these roles usually requires cyber resilience experience and qualifications. Starting in a cybersecurity role can help you ascend to a more complex job in cyber resilience. Qualifications wise, academic degrees from universities/colleges and professional certifications will make your CV stand out from the crowd and boost your chances with employers.

There is a professional cyber resilience qualification called RESILIA® [7]. It is part of the same suite of AXELOS Management Best Practice products as PRINCE2® [8], ITIL® and MSP® [9].

RESILIA certification exists at two levels:

RESILIA Foundation – this helps students understand how decisions effect good/bad cyber resilience. Students also learn how to make good cyber resilience an efficient part of business and operational management.

RESILIA Practitioner – this helps students understand what actual cyber resilience looks like in practice, and the risks that can easily harm cyber resilience. Students will also gain an understanding of how to get best balance of risk, cost, benefits and flexibility within an organisation.

How can RESILIA help companies and individuals?

RESILIA professional certification can help an organisation or enterprise to:

  • Design and deliver cyber resilient strategies and services in line with business needs
  • Integrate cyber resilience into existing systems and processes
  • Establish a common language for cyber resilience across the organisation
  • Minimize the damage from a security breach and enable speedy response and recovery [10].

On the other hand, RESILIA enables individuals to contribute to better cyber resilience, avoid social engineering pitfalls and help educate others about being cautious and alert online.

Conclusion

Continued use of the internet and an increasing reliance on networks means cyberattacks will rise and never end. Having inadequate cyber resilience strategies and hoping that your organisation won’t be hit is courting disaster. The demand for cyber resilience professionals will continue to grow. In fact, there’s currently a huge gap in knowledgeable cyber resilience professionals, so now is the perfect time to start a cyber resilience career.

Inspired to start a career in cyber resilience? Knowledge Train® has an accredited RESILIA Foundation online course to help get you started! Contact our team and ask for a demo!

List of references

[1] AXELOS (2015). Cyber Resilience Best Practices. Norwich: TSO (The Stationery Office). 7.

[2] AXELOS (2015). Cyber Resilience Best Practices. Norwich: TSO (The Stationery Office). 8.

[3] Chris Graham. (2017). NHS cyber attack: Everything you need to know about 'biggest ransomware' offensive in history. Available: https://www.telegraph.co.uk/news/2017/05/13/nhs-cyber-attack-everything-need-know-biggest-ransomware-offensive/. Last accessed 04 Sep 2018.

[4] ITIL® is a registered trade mark of AXELOS Limited, used under permission of AXELOS Limited. All rights reserved.

[5] AXELOS (2015). Cyber Resilience Best Practices. Norwich: TSO (The Stationery Office). 49.

[6] Unknown. (2018). Cyber Resilience Jobs. Available: https://www.itjobswatch.co.uk/jobs/uk/cyber%20resilience.do#Skill-Set-Job-Titles. Last accessed 05 Sep 2018.

[7] RESILIA® is a registered trade mark of AXELOS Limited, used under permission of AXELOS Limited. All rights reserved.

[8] PRINCE2® is a registered trade mark of AXELOS Limited, used under permission of AXELOS Limited. All rights reserved.

[9] MSP® is a registered trade mark of AXELOS Limited, used under permission of AXELOS Limited. All rights reserved.

[10] John Tibble. (2018). Don’t WannaCry? Then don’t think Cyber is just for 'Spooks'. Available: https://www.axelos.com/news/blogs/may-2018/dont-wanna-cry-dont-think-cyber-is-just-for-spooks. Last accessed 05 Sep 2018.

Course picked for you

Cyber security awareness

Learn cyber security in just 1 hour with this online course

View cyber security

Cyber security awareness

Learn cyber security in just 1 hour with this online course

Please NOTE! This site uses cookies and similar technologies.

This site uses cookies to enhance your user experience. Please read our cookie policy by clicking here Learn more

I understand

Follow Us