
How do cybersecurity teams identify the risks they face, and how to counter them?
The sector has been fortunate to see its budgets grow, even as wider spending on technology has come under pressure. But organisations also face growing cyber threats, and a wider range of risks. Crime, geopolitics and even AI play their part.
But is the answer to spend ever more on security tooling? Or is there a better way?
As we rely more on digital systems, the opportunities for cyber attack only increase. To stay ahead, organisations need a robust process to identify threats, and to develop a top-level approach to counter them.
This is where security frameworks come in. Standards such as Open FAIR, the Open Information Security Management Maturity Model (O-ISM3), zero trust architecture and an upcoming framework on security roles from The Open Group are all vital tools to help CISOs define what they need to defend, and how.
Investing in tools is only part of the answer. As our guest for this episode warns, we cannot keep going back to the board for more money. Organisations, too, need to avoid becoming locked in to any one vendor.
John Lindford is forum director of The Open Group’s security portfolio. As he puts it: “on the one hand, we’ve never had better resources, better tools, better knowledge and abilities. But on the other hand, threat actors have most of that as well, if not more.”
But there are steps defenders can take, including adopting zero trust architectures. The Open Group is also working on a framework that will define security roles and responsibilities. This, he argues, will also help security budgets go further.
About our guest
John Linford is the Forum Director of The Open Group Security Portfolio, which is comprised of the Security Forum, Open Trusted Technology Forum, and Assured Dependability Work Group. As staff at The Open Group, John supports the leaders and participants of Forums and Work Groups in utilizing the resources of The Open Group to facilitate collaboration and follow The Open Group Standards Process to publish their deliverables.
John serves on the Board of Directors for SiRA (Society of Information Risk Analysts) and has a bachelor’s and a master’s degree in economics from San Jose State University.
