Demystifying cyber risk in the age of AI

Demystifying cyber risk in the age of AI

KSIB

Managing cyber risk without a specialist team

If you are an executive or board member of an organisation that does not have a specialist cyber team, tackling cyber risk in a practical yet appropriate way might seem out of reach. With each day bringing news about increased AI threats, particularly with respect to information security, it can seem overwhelming and difficult to manage risk. To respond to this, Steve Brown, a 30-year respected veteran of the Australian information technology and security community and KSIB’s head of technology, AI and cyber, has created a comprehensive, practical guide to help CEO’s, directors and business executives, along with IT teams, manage cyber risk in the age of AI.

The guide incorporates all the important requirements of the various cyber and information security checklists and frameworks that exist and distils these into an easy-to-navigate, actionable plan.

The real value, however, is not simply the guide alone. It is the applied judgement of a seasoned global CISO that defines material harm, sets a defensible risk appetite and prioritises risk scenarios. This enables executives and boards to answer, with evidence, four questions:

  1. What are the cyber events that could seriously harm us?
  2. How much of that risk are we choosing to carry?
  3. What are we doing about the risk we are not willing to carry?
  4. How do we know it is working?

How the guide works

The first 3 chapters of the guide focus on defining risks, setting context and providing an introduction. The remaining 12 chapters (each on a digestible step in the process) help you act.

In summary:

Start from the business.

First establish what the organisation must protect. Cyber risk only matters insofar as it threatens important business outcomes.

Define what harm means before discussing any risk.

The impact scale pins down, in concrete terms, what Limited, Major and Severe harm to each outcome look like. Without this, every later conversation about “high risk” means something different to each person in the room.

Let the board set its tolerance in those same terms.

Risk appetite is the board saying, for each kind and level of harm, how much likelihood it will live with. Because it is expressed on the impact scale, it is checkable later.

Find what the outcomes depend on.

The asset register is built by walking from each outcome down to the systems, data, suppliers and people it rests on. An asset’s importance is derived from the harm its failure could cause.

Establish who and what threatens them.

The threat profile is a short list of attacker and hazard types relevant to the sector – drawn from published threat reporting.

Write the stories where threats meet assets.

Scenarios are the working unit of risk in this method: “this class of threat, acting on these assets, causes this level of harm to this outcome, about this often.” Each scenario is then rated for impact and likelihood, and its position against appetite is derived by comparing those ratings with the appetite table.

Choose controls to close the gap.

The controls library starts from a universal baseline every organisation needs regardless of analysis, then works scenario by scenario: for each risk sitting outside appetite, choose treatments that bring it inside, and records the reasoning.

Measure, and report to the board.

Metrics prove controls are present and effective. The board pack puts scenarios, appetite positions, treatment progress and metrics on one page.

Repeat on a rhythm.

Set the review loop: an annual re-walk of the whole chain, quarterly board reporting, and defined events – an incident, a new system, a new obligation – that reopen specific steps out of cycle. The review loop is the method’s continual-improvement mechanism: the artefacts are living documents, and reality (incidents, metrics, audit findings) feeds back into the ratings.

THE YARDSTICK What harm means, and how much is tolerated THE RISK What could happen, how bad, how often MANAGING IT What we do, whether it works, who decides Context and triggers Scope, obligations, and the nine conditions that add rigour Outcomes The four to six things that must hold for the organisation to survive Impact scale Limited, Major and Severe harm written out per outcome Risk appetite The board’s tolerated likelihood for each level of harm Threat profile The actors and hazards relevant here Asset register What the outcomes depend on, and the zones they sit in Scenario register Threats acting on assets, harming an outcome Ratings and positions How bad, how often, and inside or outside appetite Controls and treatments A baseline for everyone, plus a package per scenario outside appetite Metrics and control health Whether the controls are present, working, and closing the gap Board pack Assembled by selection from a small set of the earlier steps Review loop The annual pass, the events that reopen, the decisions that expire sector, exposure what must survive walk from outcomes what harm means coverage check how much is tolerated grounds each one each scenario rated tolerated bands controls to measure evidence decisions taken generates the set levels of harm what sits outside appetite CONFIRM OR REOPEN, ANNUALLY AND ON EVENTS

THE YARDSTICK

What harm means, and how much is tolerated

Context and triggers

Scope, obligations, and the nine conditions that add rigour

Outcomes

The four to six things that must hold for the organisation to survive

Impact scale

Limited, Major and Severe harm written out per outcome

Risk appetite

The board’s tolerated likelihood for each level of harm

THE RISK

What could happen, how bad, how often

Threat profile

The actors and hazards relevant here

Asset register

What the outcomes depend on, and the zones they sit in

Scenario register

Threats acting on assets, harming an outcome

Ratings and positions

How bad, how often, and inside or outside appetite

MANAGING IT

What we do, whether it works, who decides

Controls and treatments

A baseline for everyone, plus a package per scenario outside appetite

Metrics and control health

Whether the controls are present, working, and closing the gap

Board pack

Assembled by selection from a small set of the earlier steps

Review loop

The annual pass, the events that reopen, the decisions that expire

CONFIRM OR REOPEN, ANNUALLY AND ON EVENTS

The method, end to end: the yardstick, the risk, and managing it.

To discuss how to obtain a high level strategic assessment of your needs and access to the detailed guide, contact us at www.ksib.com.au or email Kristin or Steve directly at kristin@ksib.com.au or steve@ksib.com.au. We work with you and your team to help you manage this risk in the most practical way possible. Our work ranges from initial assessments and strategic direction through to hands-on support where needed.

KSIB

Liability limited by a scheme approved under Professional Standards Legislation.

Next
Next

The strategic role of the CPO in AI implementations