Pillars of Risk Management Cyber Risk

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Pillars of Risk Management Cyber Risk

CYBER RISK AS ONE OF THE PILLARS OF RISK MANAGEMENT

On the main Pillars of Risk Management page, I explained why my team and I kept Cyber Risk alongside Technology Risk, Enterprise Risk Management, Operational Resilience, Business Continuity, Governance & Compliance, Third-Party Risk, Risk Assessment and the Risk Register even as we added newer areas such as A.I. & Risk, Human Behaviour, Trust, Future of Work and Signals.

Cyber Risk remains one of those established foundations because so much of what we now value, use and depend upon exists in digital form. Our money, identities, communications, photographs, customer information, business records and access to important services increasingly sit behind passwords, applications, networks and online platforms. The technology has changed enormously, but the underlying concern is familiar: how do we protect something valuable from being accessed, stolen, changed, disrupted or misused by someone who should not be able to do so?

This page also continues naturally from Technology Risk and Enterprise Risk. Technology Risk asks what happens when the technology we depend upon fails, becomes unavailable or does not perform as expected. Cyber Risk focuses more specifically on what happens when somebody deliberately tries to compromise, manipulate, steal from or disrupt that technology or the information it contains. When the consequences spread beyond the system itself and begin affecting customers, finances, operations, reputation or the ability of the business to continue, Cyber Risk becomes part of the wider Enterprise Risk picture.

The newer risks on this website do not replace Cyber Risk. In many cases, they change the form in which Cyber Risk appears. A phishing email may now be written by A.I. A fake voice recording may impersonate someone we trust. An A.I. agent may have access to systems that previously only a person could use. The questions sound new, but many still lead us back to familiar Cyber Risk ideas about identity, access, authentication, information, permissions, monitoring and human judgement.

WHAT IS CYBER RISK?

Cyber Risk is the possibility that digital systems, information, identities or services are accessed, altered, stolen, disrupted or misused in a way that causes harm.

For an individual, that might mean someone taking over an email account, stealing online-banking credentials, impersonating them, accessing personal information or tricking them into transferring money. For a small company, it could mean an employee clicking on a phishing message, ransomware making business records unavailable, a stolen password being used to access customer information or a fraudulent payment instruction appearing to come from the owner.

The important point is that Cyber Risk is not simply an “IT problem”. When somebody compromises an email account, the consequences may be financial. When customer information is stolen, there may be privacy and reputational consequences. When ransomware prevents a business from accessing its records, the problem also becomes one of Business Continuity and Operational Resilience.

This is why Cyber Risk sits within the wider Pillars rather than in isolation. A cyber event may begin digitally, but its consequences can spread across the business.

HOW DID CYBER RISK COME ABOUT?

Cyber Risk developed as information, communication and money moved into connected digital environments. When computers were largely standalone machines, many risks were more contained. As people began connecting computers to networks and then to the internet, the benefits of connectivity also created new ways for someone elsewhere to reach information and systems.

Email made communication faster, but it also created phishing. Online banking made financial transactions more convenient, but it created new opportunities for account theft and fraud. E-commerce allowed even small businesses to sell beyond their immediate location, but it also meant that customer information and payments increasingly travelled through digital systems.

Smartphones extended this further. Email, banking, messaging, photographs, passwords and work applications could all sit on one device in a person's pocket. As our digital lives became more useful and more interconnected, access to them became more valuable too.

Cyber Risk therefore did not emerge because technology was inherently dangerous. It emerged because the more useful and connected technology became, the more attractive it became to misuse, manipulate or exploit.

The same pattern continues today. Cloud computing, remote work and A.I. create enormous benefits. They also raise new questions about who can access what, how identity is verified, what information leaves the organisation and how malicious actors may exploit new technology.

WHAT CYBER RISK QUESTIONS DID INDIVIDUALS AND SMALL BUSINESSES USED TO ASK?

Individuals and small-business owners have been asking Cyber Risk questions for years, even if they never used that terminology. Earlier questions tended to be practical: Do I need antivirus software? Is this email really from my bank? Should I open this attachment? How do I stop somebody guessing my password? What happens if my computer gets a virus? Is it safe to use my credit card online?

These are everyday versions of Cyber Risk questions involving malware, authentication, access control, social engineering and financial fraud.

The tools used to manage those risks were similarly practical. People installed antivirus software, used passwords, updated operating systems, backed up important files and learned not to open suspicious attachments. A small business might have told employees not to share passwords, restricted who could access accounting records or kept a separate backup in case a computer was infected.

None of this required a sophisticated Cyber Risk framework. The underlying principle was simple: make it harder for the wrong person or malicious software to access something important, and be prepared in case that protection fails.

WHAT CYBER RISK TOOLS CAN AN INDIVIDUAL OR SMALL BUSINESS USE?

A small business can manage a significant amount of Cyber Risk using a relatively small number of practical controls. The most important are often to protect accounts, keep software current, limit access, back up important information, help people recognise suspicious activity and know what to do when an incident occurs.

Passwords are one of the oldest examples. For many years, the basic advice was simply to choose a strong password. That approach has had to evolve because attackers became better at stealing, reusing and cracking passwords. Multi-factor authentication (MFA) adds another layer by requiring something in addition to the password. If the password is stolen, the attacker may still be unable to access the account without the second factor.

Software updating is another simple but important control. Vulnerabilities can be discovered after software has already been released, and security updates or patches help close weaknesses that could otherwise be exploited. For individuals and small businesses, keeping devices and applications updated remains one of the most practical forms of Cyber Risk mitigation.

Access control also matters. A small company does not need every employee to have access to every account or every piece of information. Limiting access to those who genuinely need it reduces the potential damage if an account is compromised.

Backups provide another useful example of how the Pillars overlap. A backup may first appear to be a Technology Risk control against accidental data loss, but it is also a Cyber Risk control when ransomware deliberately makes information unavailable. The same tool can therefore mitigate more than one type of risk.

HOW IS CYBER RISK DIFFERENT FROM TECHNOLOGY RISK?

Technology Risk is broader than Cyber Risk. Technology Risk includes system failure, availability, poor implementation, obsolescence, capacity problems and technology dependency, while Cyber Risk focuses more specifically on malicious or unauthorised activity involving digital systems, information or identities.

Suppose a booking system becomes unavailable because of a faulty software update. That is primarily a Technology Risk issue. If the same system becomes unavailable because an attacker has deployed ransomware, it is also a Cyber Risk event.

The operational consequence may look similar—the business cannot take bookings—but the cause and the controls required are different. Technology Risk may lead us towards testing, change management, backup, redundancy and recovery. Cyber Risk adds controls such as authentication, access management, phishing protection, vulnerability management, security monitoring and incident response.

The two Pillars therefore share some tools while looking at different aspects of the same technology environment.

HOW DOES CYBER RISK BECOME AN ENTERPRISE RISK?

Cyber Risk becomes an Enterprise Risk when the consequences extend beyond the digital system and begin affecting the wider objectives or performance of the business.

A stolen email password may initially look like a technical security problem. But if the attacker uses the account to send fraudulent payment instructions to customers, the issue becomes financial and reputational. If confidential information is also accessed, privacy and legal consequences may follow.

A ransomware attack can similarly move very quickly from Cyber Risk into Technology Risk, Operational Resilience, Business Continuity, Third-Party Risk, Trust and Enterprise Risk.

For a small company, this is important because there may be no separate department handling each consequence. The same owner may be dealing with the lost system, customers, money, employees and recovery at the same time.

Enterprise Risk therefore helps us ask the broader question: if this cyber event occurs, what else in the business does it affect?

HOW HAS CYBER RISK CHANGED?

Cyber Risk has changed because our digital lives and working habits have changed. We use more online services, store more information digitally, work from more places, rely on more external platforms and communicate in ways that make identity harder to verify by sight or sound alone.

Remote and hybrid work are important examples. A business that once relied largely on computers inside one workplace may now have employees using laptops, mobile devices, home internet connections, cloud applications and collaboration tools from different locations. The traditional organisational boundary has therefore become less obvious.

The growth of cloud and SaaS services has created another shift. Small companies increasingly keep email, customer records, documents, accounting information and important business applications with external providers. Cyber Risk therefore overlaps more strongly with Third-Party Risk, because part of the organisation's security depends upon technology operated by somebody else.

Digital identity has become more important too. One person may have dozens or even hundreds of accounts across banking, social media, business software, cloud services and online platforms. Identity itself has become a valuable digital asset.

Behaviour has changed as well. People expect speed and convenience. They communicate through messaging applications, work from phones and respond quickly to requests. That convenience can be exploited. A convincing urgent request for money, a login link or a password reset can succeed precisely because it resembles normal digital behaviour.

Demographic change also influences Cyber Risk. Younger generations may be very comfortable with digital technology, but familiarity does not automatically reduce susceptibility to fraud or manipulation. Older people may face different types of impersonation or online scams. Small businesses increasingly rely on freelancers, remote workers and external service providers, creating more accounts, devices and access relationships to manage.

A.I. adds another layer again by changing how convincing digital deception can become.

HOW DID COVID-19 AND REMOTE WORK CHANGE CYBER RISK?

COVID-19 accelerated existing Cyber Risk trends by moving work rapidly outside traditional workplaces and increasing dependence on cloud systems, remote access, video communication and home networks.

For many individuals and small businesses, work devices were suddenly being used at home. Employees connected through different networks, shared information digitally more frequently and depended heavily on email, messaging and online meetings.

This made controls that could travel with the person more important. Multi-factor authentication, device security, secure remote access, cloud security, account monitoring and user awareness became more significant because the work environment itself had become distributed.

Remote work also changed how people verified one another. A request that might once have been confirmed by walking across the office now arrives through email, messaging or video. That behavioural change matters because Cyber Risk is not only about technical vulnerabilities; it is also about how people decide whether a digital request is genuine.

This is where Cyber Risk begins to connect more strongly with Human Behaviour and Trust.

WHY ARE PEOPLE SUCH AN IMPORTANT PART OF CYBER RISK?

Many cyberattacks succeed by influencing a person rather than breaking through a machine. A phishing message may create urgency. A fraudulent payment instruction may appear to come from someone senior. A fake login page may imitate a familiar service. An attacker may persuade someone to reveal information rather than technically steal it.

The professional term social engineering describes many of these techniques, but the underlying idea is simple: sometimes the easiest route into a system is through the person who already has legitimate access to it.

Traditional Cyber Risk controls therefore include training and awareness. Employees are taught to recognise phishing, suspicious attachments and unusual requests. But this also exposes a limitation of training alone. People are busy, tired, distracted and sometimes under pressure. A control that relies upon every person spotting every suspicious message every time will eventually encounter human error.

This is why Cyber Risk connects deliberately with Human Behaviour → Human Error, Cognitive Bias, Risk Culture and Why People Ignore Procedures. Cyber Risk can explain the malicious technique, while Human Behaviour can help explain why intelligent people still fall for it.

The interconnection matters because telling someone simply to “be more careful” is not always an adequate Cyber Risk control.

HOW IS THE CYBER RISK TOOLKIT CHANGING?

The Cyber Risk toolkit is evolving from mainly protecting devices and networks towards protecting identities, cloud services, distributed workforces, third-party connections and increasingly A.I.-enabled interactions.

Traditional tools remain important. These include antivirus and endpoint protection, firewalls, patching, vulnerability management, passwords, access controls, backups, phishing awareness, incident response and security monitoring.

But the emphasis is shifting. Passwords increasingly sit alongside multi-factor authentication. Basic access control is developing into stronger identity and access management, particularly where people use many cloud applications. Periodic vulnerability checks may be supplemented by more continuous monitoring of weaknesses and attack surfaces.

Cyber practitioners are also paying more attention to machine identities. In the past, access discussions focused mainly on people: which employee should be allowed into which system? As applications, automated processes and A.I. agents increasingly communicate with one another, software itself may have credentials and permissions.

The question is therefore expanding from “Which people have access?” to “Which people, devices, applications and automated agents have access, and what are they permitted to do?”

WHAT ARE RISK PRACTITIONERS BEGINNING TO USE OR ADAPT NOW?

Risk and cybersecurity practitioners are increasingly adapting established tools in response to faster attacks, cloud dependency, distributed work, more sophisticated social engineering and A.I.-generated content.

One area is continuous monitoring. Cyber Risk can change far more quickly than an annual review cycle. Suspicious account activity, new vulnerabilities, changes in access and security events can therefore be monitored more frequently where appropriate.

Another is behavioural monitoring. Rather than looking only for known malicious software, security tools can identify unusual activity, such as an account suddenly accessing information or systems in a way that differs significantly from its normal pattern.

Threat intelligence is also becoming more important because organisations increasingly want to understand not only their own weaknesses but what attackers are actually doing outside the organisation.

For a small business, these capabilities may be built into cloud and security services rather than delivered through a large in-house cyber operation. The underlying purpose is the same: notice suspicious activity earlier rather than discovering it only after substantial damage has occurred.

Incident response is evolving too. Instead of focusing solely on how to prevent an attack, businesses increasingly need to know what they will do when prevention fails. Which accounts should be disabled? How will the business continue? Who should be contacted? How will systems be restored? What information might need to be communicated to customers or others?

At that point Cyber Risk connects directly with Business Continuity and Operational Resilience.

HOW IS A.I. CHANGING CYBER RISK?

A.I. is changing Cyber Risk by making some attacks easier to create, more convincing and potentially easier to scale, while also becoming a tool that defenders can use to detect and analyse suspicious activity.

One visible change is the quality of fraudulent communication. Phishing messages once often contained obvious spelling errors or awkward wording. Generative A.I. can produce polished messages in multiple languages and adapt them to particular contexts.

A.I. can also make impersonation more convincing. Synthetic voices, images and video can make it harder to rely on sight or sound alone when deciding whether somebody is genuinely who they claim to be.

This changes the Cyber Risk toolkit because the traditional advice to “look for obvious mistakes” becomes less reliable. Verification therefore becomes more important. If an unusual payment request appears to come from someone you know, confirming it through a separate trusted channel may be more effective than deciding whether the message looks genuine.

This is where Cyber Risk leads naturally into Trust → Deepfakes, Digital Identity and Information Integrity.

The newer risk may be a deepfake, but the established Cyber Risk question underneath it remains familiar: how do I verify identity before giving somebody access, information or money?

WHAT ARE DEEPFAKES CHANGING ABOUT CYBER RISK?

Deepfakes change Cyber Risk because voice, image and video can no longer always be treated as sufficient evidence of identity.

For years, people learned to be suspicious of email. A telephone call from someone they recognised might have felt more trustworthy. A video call seemed stronger still. Synthetic media weakens that assumption.

This does not mean that people should distrust everything they see and hear. It means that for important actions, such as transferring money, revealing confidential information or changing account access, verification may need to rely on something other than appearance or voice alone.

An established control such as authentication therefore evolves. The question is no longer merely whether someone knows a password. It can involve multi-factor authentication, trusted-channel verification, digital identity controls, transaction approvals and confirmation processes.

The newer problem looks very different from an early computer virus, but it still sits partly inside Cyber Risk because it concerns identity, authentication and unauthorised action.

WHAT CHANGES WHEN A.I. AGENTS HAVE SYSTEM ACCESS?

Agentic A.I. creates a new Cyber Risk dimension when an A.I. system is given credentials, access rights or permission to interact with other systems.

Traditionally, Cyber Risk practitioners spend considerable effort deciding which people should have access to which systems and what they should be allowed to do. Increasingly, the same questions may need to be asked about A.I. agents.

What systems can the agent access? What data can it read? Can it change information? Can it initiate a transaction? Can it send a message? Which actions require human approval?

An agent with excessive permissions creates a familiar Cyber Risk problem in a new form.

Established approaches such as least privilege, segregation of duties, authentication, access reviews, activity logging and monitoring therefore remain useful. But they may need to be supplemented by agent-specific permission boundaries, tool-use restrictions, human approval gates, action monitoring and mechanisms for suspending or revoking the agent's access.

The technology is new, but the principle is not: do not give more access than is necessary for the task being performed.

The deeper treatment of autonomous A.I. belongs under A.I. & Risk → Agentic A.I. Risk and Human Oversight, while Cyber Risk provides part of the established control foundation.

HOW DOES THIRD-PARTY CYBER RISK AFFECT A SMALL BUSINESS?

Third-party Cyber Risk arises when the security of a business depends partly upon another company that stores its information, operates its software, processes its payments or connects to its systems.

For small businesses, this is increasingly important because so much technology is purchased as a service. A company may have good internal password practices and still be affected if an external provider suffers a security breach. A supplier's compromised account may also be used to send a convincing fraudulent message to the business.

The question therefore shifts from “Are we secure?” to “Who else are we depending upon to keep us secure?”

Simple measures include understanding which providers hold sensitive information, enabling available security features such as MFA, reviewing who has administrative access and considering how the business would respond if an important provider suffered an incident.

More developed Third-Party Risk practices may include due diligence, contractual requirements, assurance reviews, incident-notification requirements and ongoing monitoring. Those tools are explored further under Third-Party Risk. The Cyber Risk connection is that security increasingly extends beyond the boundary of the business itself.

WHAT HAPPENS WHEN CYBER CONTROLS FAIL?

Cyber Risk Management needs to include recovery because no control can guarantee that every malicious attempt will be prevented.

A ransomware incident provides a simple example. Preventive controls may include software updates, endpoint protection, access restrictions, MFA and employee awareness. But if ransomware still succeeds, another group of questions becomes immediately important. Are usable backups available? How quickly can systems be restored? Can the business continue operating while recovery takes place? Who needs to be informed? How do we know the attacker has actually been removed?

Cyber Risk therefore connects directly with Business Continuity and Operational Resilience. The cyber response focuses on containing and removing the threat. Business Continuity considers how the business keeps operating. Operational Resilience asks whether an important service can continue or recover despite the disruption.

These are different Pillars looking at the same event from different angles. That is precisely how the wider Risk Management system is intended to work.

CAN A.I. ALSO HELP MANAGE CYBER RISK?

A.I. can assist Cyber Risk Management by helping analyse security events, identify unusual patterns, classify large volumes of alerts and support the detection of suspicious activity.

This is another example in which a new technology becomes both part of the risk and part of the evolving toolkit. A.I.-assisted security tools may help detect activity that would be difficult for a person to review manually across large volumes of information.

Automation also introduces its own questions about accuracy, false positives, false negatives and overreliance. A security system that generates too many alerts may simply be ignored. One that automatically takes action based on an incorrect conclusion can create another operational problem.

This reconnects Cyber Risk with A.I. & Risk, Human Oversight and Human Behaviour. The technology may be intelligent, but a business still needs to decide how much authority it should have and how its conclusions should be checked.

WHAT CYBER RISK QUESTIONS ARE PEOPLE ASKING NOW?

People today may never search for the phrase “Cyber Risk Management”. They encounter Cyber Risk through the situations happening around them.

Someone may ask, “How do I know whether this WhatsApp message is really from my boss?” That is a Cyber Risk question involving identity and social engineering, but it also connects with Trust.

Another person may ask, “Can somebody clone my voice and use it to steal money?” That leads into deepfakes, digital identity and verification, but underneath it lies the established Cyber Risk problem of impersonation.

A small-business owner may ask, “Should I let employees use A.I. with customer information?” That crosses Cyber Risk, Technology Risk, A.I. & Risk, Data Privacy, Governance and Third-Party Risk.

Someone else may ask, “Can an A.I. agent be hacked or tricked into doing something it should not do?” That is a newer Agentic A.I. question, but it also takes us back to access controls, permissions, authentication, monitoring and incident response.

Another person may ask, “Why do intelligent employees still click phishing links?” Cyber Risk can explain the attack, while Human Behaviour helps explain the person.

And a small-business owner may ask, “If my cloud provider is hacked, what happens to my business?” That connects Cyber Risk, Third-Party Risk, Technology Risk, Business Continuity and Operational Resilience.

These questions sound contemporary because the technology and behaviours surrounding them are contemporary. The underlying Cyber Risk problem remains recognisable: how do we know who or what we are interacting with, what should they be allowed to access, and what happens if that trust is abused?

WHICH NEWER RISKS MAKE THE EVOLUTION OF CYBER RISK USEFUL?

The evolution of Cyber Risk is particularly relevant to A.I. & Risk, Trust, Human Behaviour, Future of Work and Signals, while remaining strongly connected with the established Pillars of Technology Risk, Enterprise Risk, Third-Party Risk, Business Continuity and Operational Resilience.

A.I. & Risk becomes relevant because A.I. can change both the attack and the defence. Generative A.I. can create more convincing fraudulent communications, while Agentic A.I. introduces new questions about credentials, permissions and autonomous action.

Trust becomes increasingly important because Cyber Risk is moving beyond protecting systems towards determining whether digital identities, messages, images and voices can be trusted. Deepfakes, misinformation and digital identity therefore have strong Cyber Risk connections without belonging entirely inside the Cyber Risk page.

Human Behaviour matters because many attacks exploit urgency, authority, curiosity, fatigue or habit rather than purely technical weaknesses. Future of Work creates new Cyber Risk questions as work becomes more distributed, employees use more external platforms and human-A.I. collaboration creates new forms of access and dependency.

Signals also has a role because it can help identify changing cyber threats and technologies before they become immediate problems. A new attack technique, vulnerability or emerging technology may initially belong on a watch list rather than immediately becoming a formal risk-register entry.

The established toolkit therefore continues to evolve around a familiar set of principles: protect valuable information and systems, verify identity, limit access, detect suspicious activity and prepare for the possibility that a control will fail.

CYBER RISK HAS MOVED FROM PROTECTING THE COMPUTER TO PROTECTING DIGITAL TRUST

The earliest everyday Cyber Risk questions often centred on a single machine. People worried about computer viruses, antivirus software and passwords. Those questions still matter, but the environment around them has expanded enormously.

We now use multiple devices, cloud services, mobile applications and online identities. Work moves between office and home. Suppliers hold our data. A.I. can generate convincing messages and synthetic voices. Automated agents may increasingly hold credentials and interact directly with systems.

The Cyber Risk toolkit has evolved accordingly. Passwords have been supplemented by multi-factor authentication. Device protection has expanded towards identity and cloud security. Periodic checks increasingly sit alongside continuous monitoring. Employee awareness is being supplemented by stronger verification processes. Access control is beginning to include machines and A.I. agents as well as people.

Yet the underlying questions remain recognisable. Who or what is trying to access something? How do we know they are genuinely who they claim to be? What should they be allowed to see or do? How would we notice if something unusual happened? What happens if our safeguards fail, and how do we recover afterwards?

Those are Cyber Risk questions.

The tools answering them will continue to change because the digital world will continue to change. The newer risks on this website—A.I., deepfakes, digital identity, human behaviour, changing work and emerging technology—do not make Cyber Risk less relevant. They show us why an established Pillar has to keep evolving.

That is why Cyber Risk remains one of the Pillars of Risk Management.