TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»The Truth about Business Risk Intelligence
    Cyber Security

    The Truth about Business Risk Intelligence

    February 25, 2019Updated:February 25, 2019No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Starting a business risk intelligence (BRI) program often requires overcoming challenges that involve resource allocation, operational bandwidth, or stakeholder support, to name a few. And occasionally, these challenges can be exacerbated by myths and misconceptions about what BRI is and can accomplish. As someone who has long been an avid supporter and practitioner of BRI, I feel it’s my duty to share—and debunk—some of the most persistent and misleading BRI fallacies I’ve heard over the years.

    Myth: BRI is derived solely from Deep & Dark Web (DDW) data 

    Fact: The most effective BRI programs rely on data sources that provide visibility into the myriad threats, adversaries, and related activities that contribute to business risk. These sources tend to vary depending on a program’s intelligence requirements (IRs), but they typically include illicit online communities such as DDW forums and marketplaces, card shops, chat services and/or messaging platforms, paste sites, and various other DDW and open-web sites frequented by threat actors. Keep in mind that relevance, accuracy, and timeliness of data are far more important than—and not necessarily indicated by—the source from which it is collected.

    Myth: BRI has nothing in common with cyber threat intelligence (CTI)

    Fact: The use cases CTI programs typically deal with are among the many that BRI supports. Both types of intelligence can enable cyber defenders to more effectively detect and react to threats stemming from cybercrime, hacktivism, vulnerabilities and exploits, and DDoS activity, to name a few. BRI and CTI are also both suitable for malware analysis, threat hunting, breach investigations, and identifying and triaging indicators of compromise (IOCs). 

    In other words, BRI encompasses CTI—but that doesn’t mean both types of intelligence are identical. The most notable difference is that BRI provides a higher caliber of context and visibility that enables it to not only support CTI use cases but also address the business risks posed by a broad spectrum of cyber, physical, fraud, and insider threats. And although both BRI and CTI are often leveraged by cybersecurity-related business functions, only BRI can also provide tangible value to functions related to fraud, insider threat, physical security, and corporate security, among many others.

    Myth: BRI is not suitable for public-sector organizations 

    Fact: It’s true that business risk is generally not a consideration for public-sector organizations because they are not businesses. However, many of the core principles of BRI can still benefit the public sector—just in different ways than they tend to benefit businesses. 

    For example, let’s consider the visibility BRI provides into illicit online communities. This visibility helps businesses more effectively safeguard business assets from the threats and adversaries that originate and operate within these communities. And because many of the same types of threats and adversaries also target or otherwise impact the public sector and its constituents, this visibility can also:

    – Guide law enforcement investigations, arrests, and prosecutions;

    – Inform policies and regulatory responsibilities for civilian agencies; 

    – Help defense and intelligence agencies identify and address intelligence gaps and conduct further analysis in support of mission objectives.

    This concept also applies to BRI’s focus on integrative use cases and cross-functional collaboration, among other core principles that can help optimize private- and public-sector intelligence programs alike.

    Myth: BRI does not address digital risks

    Fact: The easiest way to debunk this myth is to look at how business risk compares to digital risk. As I’ve written previously, business risk is commonly defined as the possibility that a business will incur a loss due to uncertainty in one or more of the following five categories of risk: financial, compliance, strategic, reputational, and operational. Digital risk, meanwhile, refers solely to uncertainties and consequential losses related to digital business transformation, which according to Gartner is the process of “exploiting digital technologies and supporting capabilities to create a robust new digital business model.”

    So why isn’t digital risk considered a category of business risk? The answer is that the five categories of business risk already encompass digital risk. For example, a business’s launch of a mobile application for its customers would likely be a digital risk because it pertains to digital business transformation and creates a new vector through which potential cyber threats could target and possibly compromise customers’ data. Cyber threats and compromises tend to also be factors for operational, strategic, reputational and compliance risk, all of which are areas of business risk that the mobile application could impact as a result.

    But although the usage of new technologies and other digital risk factors can impact business risk, so can a business’s location, industry, market share, assets, stakeholders, partners, investors, political climate, physical infrastructure, and the nearly countless other factors that fall beyond the scope of digital risk. Indeed, this distinction reinforces a crucial point: all digital risks are business risks, but not all business risks are digital risks. And similar to how BRI encompasses CTI, business risk—and thus BRI—also encompass digital risk.

    Keep in mind that myths and misconceptions are easy to find in all areas of security, not just BRI. Most of these fallacies are relatively harmless and easy to sniff out, but some—including the examples I described above—can cause us to overlook or misinterpret resources or strategies that would otherwise benefit us and the assets we’ve been entrusted to protect. And as security practitioners, it’s our responsibility to not only identify and debunk the fallacies we come across, but also to educate those around us on what effective security truly looks like.

    Josh Lefkowitz is the CEO of Flashpoint, which delivers Business Risk Intelligence (BRI) to empower organizations worldwide with meaningful intelligence and information that combats threats and adversaries. Lefkowitz has worked extensively with authorities to track and analyze terrorist groups. He has also served as a consultant to the FBI’s senior management team and worked for a top tier, global investment bank. Lefkowitz holds an MBA from Harvard University and a BA from Williams College.

    Previous Columns by Josh Lefkowitz:
    Tags:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.