Cybersecurity: How Much is Enough?

No ratings

Presented at ISC2SecureSummit 2019 by

Advice on costs and benefits of cyber security program for process control systems and critical infrastructure is often confusing and contradictory. We will explore the question "how much is enough?" as it relates to cyber security, and draw some simple conclusions. We will demonstrate how classic "natural disaster" risk models and other IT-centric security risk models that attempt to quantify the likelihood of attacks are poor fits to physical or cyber security problems. A good understanding of the characteristics of control system networks, industrial processes, safety systems, protection systems, security systems and attack capabilities are all prerequisites to an effective risk management strategy. Assembling all this knowledge and these costs into a simple matrix for business leaders to understand and evaluate is very much possible. Join us to review approaches to risks, calculations, costs, and understand how to communicate these to business decision-makers.