7 strategies for CSO cybersecurity survival

Adrian Taylor, VP of EMEA at A10 Networks, lays out 7 key strategies that can streamline the workload of chief security professionals. The result is a must read for CSOs, CIOs and CISOs, but also CEOs that may be delegating an overwhelming workload to their security teams. 
Adrian Taylor, VP of EMEA at A10 Networks, lays out 7 key strategies that can streamline the workload of chief security professionals. The result is a must read for CSOs, CIOs and CISOs, but also CEOs that may be delegating an overwhelming workload to their security teams. 

CSOs, CIOs and CISOs have never had it so tough. Alongside their traditional responsibilities of safeguarding the corporation’s physical assets on a day-to-day basis and preparing crisis management strategies, they must now face a cybersecurity threat environment that is growing exponentially.

Today, ransomware has become one of the greatest network security threats organizations have to deal with. Increasingly sophisticated and distributed at high speed via the internet and private networks using military-grade encryption, today’s ransomware attacks demand multi-million-pound ransoms. Ransomware is expected to cost businesses around £15bn this year and nearly £200bn by 2031. 

But ransomware is only one of the many threats organizations have to deal with. There are also distributed denial of service (DDoS) attacks, Man in the Middle (MitM) attacks, social engineering, insider threats, malware, and advanced persistent threats (APTs) to contend with – and those are just the most common network security threats.

Below are seven strategies to make cybersecurity professionals’ organizations safer from the countless network security threats they’ll be facing in the near future:

1. Create a “security-first” culture

The problem for CSOs is that, while most employees have some basic knowledge of cybersecurity best practices, that is pretty much all they have. Without ongoing training, knowledge testing and awareness, staff behaviour is one of the biggest cybersecurity risks that organizations face.

A study by Accenture revealed that less than half of new employees receive cybersecurity training and regular updates throughout their career. Just four in ten respondents said insider threat programs were a high priority. 

Organizations must look to create a robust and distributed digital immune system with a radical re-engineering of staff behaviour. Business leaders need to have accountability for cybersecurity; security teams need to collaborate with business leaders to create and implement policies that will actually work, and those policies need to be routinely re-evaluated and tested.

2. Create a continuous security education program 

A “security-first” culture requires that all members of the culture appreciate the concept of network security threats. For this to actually have an impact on culture, however, staff must be trained routinely to ensure that their knowledge is current.

3. Implement a zero trust model throughout the business

Well-trained staff and a monitored environment are crucial to the successful protection of any organization but without a foundational zero trust environment, defences will be intrinsically weak.

The zero trust model is a strategy for preventing network security threats that all enterprises and governments should be using to defend their networks. It consists of four components:

  • Network traffic control: Engineering networks to have micro-segments and micro-perimeters ensures that network traffic flow is restricted and limits the impact of overly broad user privileges and access. The goal is to allow only as much network access to services as is needed to get the job done. Anything beyond the minimum is a potential threat. 
  • Instrumentation: The ability to monitor network traffic in-depth along with comprehensive analytics and response automation provides fast and effective incident detection.
  • Multi-vendor network integration: Real networks aren’t limited to a single vendor. Even if they could be, additional tools are still needed to provide the features that a single vendor won’t provide. The goal is to get all of the multi-vendor network components working together as seamlessly as possible to enable compliance and unified cybersecurity. This is a very difficult and complex project but keeping this strategic goal in mind as the network evolves will create a far more effective cybersecurity posture.
  • Monitoring: Ensure comprehensive and centralized visibility into users, devices, data, the network, and workflows. This also includes visibility into all encrypted channels.

At its core, the zero trust model is based on not trusting anyone or anything on the company. This means that network access is never granted without the network knowing exactly who or what is gaining access. 

4. Implement SSL visibility – “break and inspect”

TLS/SSL inspection solutions that decrypt and analyze encrypted network traffic are key to ensuring policy compliance and privacy standards in the zero trust model.

Also called “break and inspect”, TLS/SSL inspection bolsters zero trust in three major ways. It allows for the detection and removal of malware payloads and suspicious network communications, prevents the exfiltration of sensitive data, and enables the zero trust model to do what it’s supposed to do – provide in-depth and rigorous protection for networks from internal and external threats.

For any organization that hasn’t adopted a zero trust strategy combined with deep TLS/SSL traffic inspection, now is the time to start rethinking its cybersecurity posture.

5. Review and test DDoS defences regularly

Routine testing against a checklist of expected configurations and performance standards, as well as random tests of security integrity, is crucial to detecting a distributed denial of service attack. 

Network performance testing should be executed daily because a distributed denial of service attack isn’t always a full-bore assault. It can also be a low-volume attack designed to reduce, but not remove, connectivity.

6. Secure all inbound and outbound network traffic using SSL/TLS encryption

When users’ computers connect to resources over the internet, SSL/TLS creates a secure channel using encryption, authentication, and integrity verification. Encryption hides data communications from third parties trying to eavesdrop, while authentication ensures the parties exchanging information are who they claim to be. The combination ensures the data has not been compromised.

Any un-secured traffic must be constrained to specific secured network segments and monitored closely.

7. Establish and test disaster recovery plans 

A key part of a disaster recovery plan involves backups. However, it is surprising how often restoring from backup systems in real-world situations doesn’t perform as expected. It’s important to know which digital assets are and are not included in backups and how long it will take to restore content. 

CSOs should plan the order in which backed-up resources will be recovered, know what the start-up window will be, and test backups as a routine task with specific validation checks to ensure that recovery is possible. 

READ MORE:
Staying secure

The CSO’s job isn’t getting any easier, but solid planning using the seven strategies will help ensure an organization’s digital safety. In addition, partnering with top-level enterprise cybersecurity vendors will ensure that critical security technology and best practices are central to the organization’s cybersecurity strategy.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Adrian Taylor

Adrian Taylor is VP of EMEA at A10 Networks.

Tech and Business Outlook: US Confident, European Sentiment Mixed

Viva Technology • 11th February 2025

The VivaTech Confidence Barometer, now in its second edition, reveals strong confidence among tech executives regarding the impact of emerging technologies on business competitiveness, particularly AI, which is expected to have the most significant impact in the near future. Surveying tech leaders from Europe and North America, 81% recognize their companies as competitive internationally, with...

How smart labels are transforming supply chains

Sharath Muddaiah • 27th January 2025

As e-commerce continues to rise globally, the impact of just-in-time manufacturing and rising consumer expectations mean the need for real-time visibility has never been greater. Smart labels directly address this demand, offering solutions to long-standing challenges like shipment delays, theft, and the lack of traceability. With the smart label market projected to grow from $14.1...

The rise of loyalty apps

Sue Azari • 17th January 2025

Increased choice and a consumer more price sensitive than ever before, has made customers far more likely to shop around for the best deals. Price is now the number one factor in brand consideration. In an effort to bag a bargain, loyalty programs have become increasingly popular with consumers, with nine out of ten in...

Rocket launch challenges Elon Musk’s space dominance

Professor Sultan Mahmud • 16th January 2025

Amazon founder Jeff Bezos’s space company has blasted its first rocket into orbit in a bid to challenge the dominance of Elon Musk’s SpaceX. The New Glenn rocket launched from Cape Canaveral Space Force Station in Florida at 02:02 local time (07:02 GMT). It firmly pits the world’s two richest men against each other in...

Giesecke+Devrient launches new Smart Label at CES 2025

Giesecke Devrient • 06th January 2025

G+D has today launched the G+D Smart Label, its innovative tracking solution that transforms any package into an IoT device. Ultra-thin and only slightly larger than a credit card, the new Smart Label proposition has been jointly developed by G+D in conjunction with its hardware partner, Sensos to enable cost-effective, accurate location tracking for a...

Choose an AI solution to transform beyond technology

Kit Cox • 09th December 2024

The first step is knowing exactly what your business wants to achieve with AI; think faster, smarter and more efficient. Once you know what you are working towards, you can start looking for a solution that can help you make it a reality. AI integration can feel like a daunting task at the beginning, so...

A Roadmap to Security and Privacy Compliance

John Lynch Director of Kiteworks • 04th December 2024

Only by understanding the current regulatory environment and implementing robust data protection measures, can organisations enhance their security posture, ensure compliance, and build resilience against the latest cyber threats. This article provides a comprehensive roadmap of how to do it.