Setting the Right Security Culture
CIOREVIEW >> Australia Tech Australia >> NEWS

Chief Information Security Officer at Allianz Australia

Mackenzie Muir

Setting the Right Security Culture

Mackenzie Muir
Mackenzie Muir, Chief Information Security Officer at Allianz Australia

Information security experts are accustomed to the evolving complexity of the threat environment and frequently witness alterations in the methods and practices of attackers. . Over recent years we have seen a dramatic evolution of the data security landscape thanks to a rise in malware, phishing and zero-day exploits. This rapidly changing area should be addressed as a company priority owing to the increasing senior management expectations and stringent regulations.

Effective cyber security is about knowing what is important to your business – that is, identifying the ‘Crown Jewels’ and focusing security resources, such as people, time, money and attention, towards them. This needs to be done while maintaining a minimum level of ‘security hygiene’ across the board, that being the security requirements your systems must meet and comply with, across all business units within the organisation.  

Managing the balance between these two areas and the objectives of other business functions is where information security teams find their challenges. The effort required to not just list every system – if you don’t know them all, then you cannot be sure you know your Crown Jewels – but have senior management agree and endorse the list of those systems cannot be underestimated. It also cannot be a one-off activity; managing your systems and lists require regular reviews based on the pace of change in your business.   

Once you have identified the Crown Jewels of your business you need to define the level of security they require. It needs to be above the minimum level set for everything, but how far above? What additional controls need to be applied to these systems, such as micro-segmentation or more frequent User Access Revalidation – otherwise known as UAR – activities? 

Effective cyber security is about knowing what is important to your business – that is, identifying the ‘Crown Jewels’ and focusing security resources, such as people, time, money and attention, towards them

Identity is central to this security; you need to know who can access your systems and whether they should. This can be controlled through a request and approval process, regular access revalidation and finally, removal on termination. There should be absolute minimums that apply to all your systems, and increased controls that apply to the Crown Jewels. Depending on your industry and business context, an annual binary revalidation may suffice. Simply put, should user Jamie Bloggs have access to the system or not? It’s a binary – yes or no. 

Setting the right security culture is important for ongoing success. Security is everyone’s responsibility but not everyone can, or should, be a security expert. You should ask yourself, what is the security role you want each employee to take? What relationship do you want the business and its people to have with your security team? How do you facilitate these roles and relationships with effective training and awareness? 

At Allianz Australia, for example, we set a phishing reporting requirement this year for all managers and executives across the organisation. This was linked to individuals KPIs and not only encouraged the right behaviours for secure security practices but also facilitated the accountability required to achieve distributed responsibility for security within the business. As a result, we have seen improved uptake of training initiatives, improved results in phishing simulation exercises and increased security awareness across the business.  

For cyber security to be effective it needs to be viewed as a critical business enabling activity – something that is a key part of winning the next contract or maintaining the customer’s trust in the firm and its products. When you lead with this objective and focus your conversations and culture to this objective, you will be heading in the right direction to improve your organisations security posture.  

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.