The Entrepreneurs Weekly
No Result
View All Result
Thursday, July 31, 2025
  • Login
  • Home
  • BUSINESS
  • POLITICS
  • ENTREPRENEURSHIP
  • ENTERTAINMENT
Subscribe
The Entrepreneurs Weekly
  • Home
  • BUSINESS
  • POLITICS
  • ENTREPRENEURSHIP
  • ENTERTAINMENT
No Result
View All Result
The Entrepreneurs Weekly
No Result
View All Result
Home Business

How To Navigate The Top Risk And Security Trends Of 2022, According To Ostendio’s CEO

by Brand Post
July 28, 2022
in Business
0
How To Navigate The Top Risk And Security Trends Of 2022, According To Ostendio’s CEO
152
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter


As technology continues to evolve, businesses are seeing both the upsides and pitfalls of advancements like the cloud.

On the one hand, cloud environments have enabled companies to expand their footprints and allow employees to permanently telecommute. In fact, Gartner estimates that around half of all knowledge workers will rarely step foot in a traditional office for the foreseeable future. On the other hand, the virtual aspect of the internet, the cloud, and widespread digitization have opened up organizations to serious corporate security risks.

Employees will start to become more involved in the security operation and will be measured and … [+] rewarded based on this participation.

getty

To get a better understanding of the biggest security concerns facing leaders and brands today, I sat down with Ostendio’s Grant Elliott. As the security and risk management platform’s CEO, co-founder, and chairman, Elliott keeps an eye on the emerging threats that keep business owners and CISOs up at night.

Serenity Gibbons: Let’s start by talking about the most critical risks you’re seeing right now. What’s your top pick?

Grant Elliott: The number one threat faced by businesses is the growing inability to understand where their data is stored and who has access to it. The challenge for organizations today is how to ensure only those required, with legitimate rights, can access and use that data.

Gibbons: That’s scary, given that Beta News reporting estimates about one-third of all hacking incidents can be linked to “inside jobs.”

Elliott: Yes. Failure to identify and manage access to data has led to a rise in both the number of data breaches each year and the related financial and reputational cost to an organization. According to a recent Ponemon/IBM report, the average cost of a data breach is $4.2m, the highest average total cost in the 17-year history of the report.

Gibbons: Okay. What gets your vote for the second biggest type of security threat that needs to be taken seriously?

Elliott: Complacency. When organizations are complacent and take shortcuts to managing risk, security, and compliance, they put their business, employees, and customers at risk.

Gibbons: So an auto-piloted, “set it and forget it” system isn’t feasible?

Elliott: It isn’t. There is no automated shortcut to running an effective security program.

We’ve met with many organizations, who have since become customers, that have either tried to manage the process through spreadsheets or held the belief that an “automated” system could adequately protect their data, only to fail a security audit and put their organization at further risk.

To be successful, businesses must get boardroom buy-in to invest in building robust integrated risk management and data security programs that can be verified by an external auditor.

Gibbons: I’m guessing that a lot of organizations know about these threats and try to thwart them. Why aren’t they gaining traction?

Elliott: To manage threats, organizations often focus on their production data stored in a cloud environment such as AWS or Azure and fail to recognize that their data might be free-flowing across their organization. Without clear governance and mechanisms to enforce data security, sensitive data can find itself duplicated in all sorts of places providing potential attackers with a multitude of access points.

Gibbons: What’s your best advice for CISOs tasked with trying to make sense of everything?

Elliott: Communicate with your executive team and board of directors. It is important that the modern CISO communicates risk management effectively to ensure corporate buy-in at the highest level of the organization.

Only effective risk management communication will allow the modern-day CISO to ensure they have a sufficient security budget and executive buy-in to drive operational security throughout the extended organization and reduce overall organizational security risk.

Gibbons: Good points. How about a year or two down the road, though? We know that more threats are bound to arise. Are there any pragmatic ways that CISOs can future-proof their corporate systems against today’s and tomorrow’s risks?

Elliott: Businesses should start by managing and tracking all assets at a holistic level. Not just an asset’s attributes but criticality, risk, and accessibility. It is also essential to understand integration points because of the increased use of APIs. When a single asset is breached we need to understand if that might give back-door access to other assets.

Organizations should also be implementing their security and risk management program in line with an industry-acceptable security standard and ensure compliance by having it audited by a credible and independent third-party auditor to prevent confirmation bias. When sitting for an exam, you don’t get to grade it too.

Gibbons: I’d like to end on a hopeful note. Can you share three positive trends in the risk and security world that you expect to see in the coming five years?

Elliott: Sure. Number one, there are an increasing number of tools available to help organizations protect their data. Organizations will use these tools to help build and operate security and risk management programs on a holistic level. While some automation in these tools may prove helpful, the reality is that people and systems are complex and most controls will continue to be procedural.

The GRC (Governance, Risk, and Compliance) tools of the future will be fully aligned with the core operational tasks of the organization, ensuring that all actions and activities are managed and tracked and that all employee operations work as a matter of process to protect information and provide on-demand evidence for independent verification.

Number two, there will be an increase in demand for security audits and certifications such as SOC 2, FedRAMP, and ISO or to obtain security certifications such as HITRUST. Gartner predicts that 60% of organizations will use cybersecurity risk as a “primary determinant” in conducting third-party transactions and business engagements by 2025. This helps organizations know how to set realistic goals, and build an appropriate and effective security program.

Gibbons: What’s your third expectation?

Elliott: Organizations that have adopted a fully remote workforce will start treating their employees as the first line of defense, rather than as a threat. Employees will become more involved in the security operation and will be measured and rewarded based on this participation. Expectations will be made clearer via more effective process and procedure documentation; more frequent and more targeted training, involvement in security drills such as Business Continuity Plan/Disaster Recovery exercises and clear communication from management around risk management.

We will also see an increased demand for asset management, tracking all data points and who has access, particularly as employees, join, leave or change roles. We call this building a “culture of security” where all employees are involved and trained in how to handle data properly.



Source link

Tags: CISOsGartnerGrant ElliottThe Top Risk And Security Trends

Related Posts

Here Are the Best Strategies for Owning Multiple Franchises | Entrepreneur
Business

Here Are the Best Strategies for Owning Multiple Franchises | Entrepreneur

July 31, 2025
Nvidia Leaders Become Billionaires, Joining CEO Jensen Huang | Entrepreneur
Business

Nvidia Leaders Become Billionaires, Joining CEO Jensen Huang | Entrepreneur

July 30, 2025
Federal Reserve Holds Rates Steady, Fifth-Straight Time | Entrepreneur
Business

Federal Reserve Holds Rates Steady, Fifth-Straight Time | Entrepreneur

July 30, 2025
  • Trending
  • Comments
  • Latest
Meet Amir Kenzo: A Well Known Musical Artist From Iran.

Meet Amir Kenzo: A Well Known Musical Artist From Iran.

August 21, 2022
Behind the Glamour: Bella Davis Opens Up About Overcoming Adversity in Modeling

Behind the Glamour: Bella Davis Opens Up About Overcoming Adversity in Modeling

April 20, 2024
Dr. Donya Ball: Pioneering Leadership Solutions for Tomorrow’s Challenges

Dr. Donya Ball: Pioneering Leadership Solutions for Tomorrow’s Challenges

May 10, 2024
Nasiyr Bey’s Journey from Brooklyn to Charlotte: The Entrepreneurial Path to Owning a Successful Cigar Lounge

Nasiyr Bey’s Journey from Brooklyn to Charlotte: The Entrepreneurial Path to Owning a Successful Cigar Lounge

August 8, 2024
Augmented.City Startup Developers Appeal To US Politicians With An Open Letter

Augmented.City Startup Developers Appeal To US Politicians With An Open Letter

0
U.S. High Court Snubs Challenge To State And Local Tax Deduction Cap

U.S. High Court Snubs Challenge To State And Local Tax Deduction Cap

0
GOP Lawmaker Blames Biden For Russia-Ukraine War: Putin ‘Could never have Invaded’

GOP Lawmaker Blames Biden For Russia-Ukraine War: Putin ‘Could never have Invaded’

0
Brad Winget’s Tips and Tricks on Having a Career in Real Estate

Brad Winget’s Tips and Tricks on Having a Career in Real Estate

0
Here Are the Best Strategies for Owning Multiple Franchises | Entrepreneur

Here Are the Best Strategies for Owning Multiple Franchises | Entrepreneur

July 31, 2025
Nvidia Leaders Become Billionaires, Joining CEO Jensen Huang | Entrepreneur

Nvidia Leaders Become Billionaires, Joining CEO Jensen Huang | Entrepreneur

July 30, 2025
Federal Reserve Holds Rates Steady, Fifth-Straight Time | Entrepreneur

Federal Reserve Holds Rates Steady, Fifth-Straight Time | Entrepreneur

July 30, 2025
Mark Zuckerberg Outlines Meta’s Superintelligence AI Vision | Entrepreneur

Mark Zuckerberg Outlines Meta’s Superintelligence AI Vision | Entrepreneur

July 30, 2025

The EW prides itself on assembling a proficient and dedicated team comprising seasoned journalists and editors. This collective commitment drives us to provide our esteemed readership with nothing short of the most comprehensive, accurate, and captivating news coverage available.

Transcending the bounds of Chicago to encompass a broader scope, we ensure that our audience remains well-informed and engaged with the latest developments, both locally and beyond.

NEWS

  • Business
  • Politics
  • Entrepreneurship
  • Entertainment
Instagram Facebook

© 2024 Entrepreneurs Weekly.  All Rights Reserved.

  • About Us
  • Advertise
  • Contact Us
No Result
View All Result
  • ENTREPRENEURSHIP
  • ENTERTAINMENT
  • POLITICS
  • BUSINESS
  • CONTACT US
  • ADVERTISEMENT

Copyright © 2024 - The Entrepreneurs Weekly

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In