NEWS
F-Secure expands their risk management service portfolio with CBIQ
By VARINDIA - 2017-09-14

F-Secure has introduced Cyber Breach Impact Quantification (CBIQ), a new service that quantifies the cost of cyber breach impact to an organization.
"Companies think it's too difficult to quantify cyber risks so they invest millions in all sorts of controls, just to be on the safe side," says Marko Buuri, Principal Risk Management Consultant, F-Secure. He further added, "But they may be investing in the wrong places, and when the actual breach happens, they’re caught off-guard. CBIQ removes that ambiguity, so they know the right level of security investment they’ll need to protect their core assets."
According to the company, client data from F-Secure risk management assessments suggests most large organizations are ill-prepared to handle breaches: While 50% have a crisis management team that’s prepared for physical disasters or business disruptions, only 20% have a crisis management team capable of effectively leading a cyber crisis. 65% of companies have never run a crisis management exercise to rehearse a cyber incident. Quantifying the cost of a potential breach can help spur organizations to take action to become more prepared and resilient.
Predicting breach cost before it happens lets decision-makers know how much is actually at stake, enabling them to make informed cyber risk decisions. It empowers them to focus cyber investments in the right places, provides justification for security spending, and informs decisions related to cyber insurance. It also improves the quality of risk reporting, bringing results down to hard numbers.
When performing a CBIQ assessment, F-Secure consultants workshop with and interview knowledgeable people in the organization to analyze operational activities. They factor in multiple loss forms associated with breaches such as costs of forensic investigations, service restoration, legal response, communication activities, and business interruption.
Consultants feed these costs into F-Secure’s unique purpose-built simulator tool, which calculates the most likely outcomes and determines the mean and standard deviations in real time. Based on years of firsthand expertise investigating and helping organizations recover from real-world cyber breaches, the tool provides quick, cost-effective results and visually clear, understandable reports. The final CBIQ outcome is a risk report based on an organization's own cost structure and expected losses.
Buuri says, “The CBIQ approach differs from usual methods of representing risk in categories such as high, medium or low that are produced by general tools such as Excel.” "Where other risk assessments show vague, debatable results, we show definitive numbers based on transparent, justifiable input. Why settle for guesstimates when you can produce a defendable view of the risk?”
CBIQ is a part of F-Secure’s complete risk management service portfolio. Services include Incident Response Maturity Assessments, which offer a comprehensive view of the maturity level of a company’s key cyber resilience capabilities, as well as risk process development, crisis management exercises, risk modelling, workshop facilitation, and training.
See What’s Next in Tech With the Fast Forward Newsletter
SECURITY
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.