How to maintain a strong cybersecurity posture amid the COVID-19 crisis

March 20, 2020
Take stock of your current activities and focus on defending your key assets as best you can

With the current operational focus on keeping people healthy, business continuity management and operational resilience in the face of the disruption, many organizations are reviewing their capacity to manage their cybersecurity. This is a sensible precaution.

Managing to secure your organization’s activity throughout the next few months is going to be challenging. Resilience is difficult enough when you have a full complement of security staff and the full attention of the board.

With a potentially significant depletion in staff and senior executives whose attention may be understandably elsewhere, the necessary focus on cyber-related issues might be lacking. Unfortunately, just because we are busy elsewhere does not mean that the criminals and others have taken a break from their activity - there are plenty of COVID-19 phishing emails doing the rounds and the ransomware bots remain active no matter what.

So, what can you do to ensure that your organization remains resilient and able to continue to deliver your business services?

Take Stock and Focus

You should first take stock of your current activities and focus on defending your key assets as best you can. Agile and dynamic organizations are going to be well-placed to come out of this situation in the best possible way, so instill that thinking in yourself and your stakeholders. 

Areas to focus attention include:

  • Supply chains are a constant worry to most cybersecurity teams. It’s so very difficult to accurately assess the effectiveness of another organization’s security, which is why it is often left to third parties to make those risk assessments for you. However, with travel restrictions in place, some assessment bodies have suspended the requirement to have onsite security assessments. So look at your supply chain cybersecurity requirements and see if you can suspend the on-the-ground inspection requirements until the situation improves. You could ask your suppliers what they might do to maintain their security in the meantime and encourage them to make incremental improvements in other areas to compensate - increasing logging, improving their patching, ensuring multi-factor authentication and enhancing their own security operations center's activities would all help. And do some scenario planning with them so that they understand what you expect of them in the short term to deal with the situation as it is today and if it gets much worse. This might be particularly key if you rely on multiple small businesses that are naturally less resilient and heavily dependent on key staff and processes. You might also need to look at paying your own invoices upfront or at least on very short terms to help maintain liquidity for the small firms that might very quickly otherwise run into cash flow problems.
  • Recruitment of new staff may become a significant issue in the short term; this could put operational activity at risk if you are unable to provide the support, testing, advice and guidance to ensure the security considerations are managed appropriately. Some firms have suspended compulsory redundancies thereby reducing availability, while other people are hunkering down and not moving while the situation is uncertain. All of these mean that new team members you had hoped to recruit may not be available, so think about how you might make up the numbers you need with virtual, remote, part-time and contract staff. 
  • In-house security operations centers are going to be facing the challenges of staff absences and while you might be planning transference of operations to a secondary location within your organization or planning to move to a back-up site, as many of the banks in the UK have done, you need to test that you have both the capacity and capability to do so. And remember that a potential infection might invalidate your contract if you're using a commercial back-up site so check the small print in your contract.
  • The challenges of working from home for staff are significant. It’s important to re-emphasize that managers will need to focus on maintaining morale and the mental health of their colleagues. One delightful way a team here at NCC Group is doing this is to have a “remote team lunch” once a week using teams to spend some social time together. The mental health of your colleagues is always important but do look at what support is available to them and make sure that they are aware of any employee assistance programs your organization provides.
  • Continuation of corporate governance is something that many organizations would rather not think about but should absolutely review in light of the situation. Simple operational decisions like not allowing the board to gather in person for their monthly meetings or restricting contact between operational sites might help ensure that the governance of the organization can survive the difficulties. Many executives will be designated as legally responsible, have banking authorization, corporate signatory powers, etc. and be deputies for each other. But with travel restrictions and sickness absence do you have sufficient liquidity yourselves and will you be able to maintain approve investments, sign off budgets and pay invoices? How will you cope if senior executives and officers, particularly those with legal responsibilities and financial obligations, are taken ill and are unable to fulfill those requirements? Having authorized deputies and alternates might ensure that the organization is able to maintain operations despite the pressures faced. Gatherings such as shareholder meetings might also need to be organized in alternative ways while remaining legally quorate; something for your legal advisers and corporate governance experts to be thinking about sooner rather than later.

This difficult situation may last for several months and with the current spread of the virus in different countries, it seems likely that the impact will affect local operations at different times. Wherever you are in your planning assumptions, having a trusted adviser with global reach and the experience to deliver security services at all levels, is well worth considering.

About the Author:

Tim Rawlins is the director and senior adviser at NCC Group. NCC Group (https://www.nccgroup.trust/us/) is one of the largest and most respected security consultancies in the world with over 35 global offices, 2,000 employees and 15,000 clients. Listed on the London Stock Exchange, it works with leading organizations to protect their businesses, brand value and reputation against an ever-morphing and increasing threat landscape. The services portfolio leverages expertise and capabilities in technically challenging security assessments; penetration testing; attack simulations, vulnerability and risk management; cryptography; securing software applications, cloud environments and IoT; and incident response programs. NCC Group security consulting has built a strong reputation in the industry and business circles, consistently tackling technically-challenging security problems, supported by a commitment and dedication to security research.

About the Author

Tim Rawlins

Tim Rawlins is director and senior adviser at NCC Group. NCC Group (https://www.nccgroup.trust/us/) is one of the largest and most respected security consultancies in the world with over 35 global offices, 2,000 employees and 15,000 clients. Listed on the London Stock Exchange, it works with leading organizations to protect their businesses, brand value and reputation against an ever-morphing and increasing threat landscape. The services portfolio leverages expertise and capabilities in technically challenging security assessments; penetration testing; attack simulations, vulnerability and risk management; cryptography; securing software applications, cloud environments and IoT; and incident response programs. NCC Group security consulting has built a strong reputation in the industry and business circles, consistently tackling technically-challenging security problems, supported by a commitment and dedication to security research.