In short
Cybersecurity should be treated as a business risk owned by the C-suite/board, not just an IT/tech problem. Guests argue companies waste money on isolated vulnerability fixes and compliance, instead of prioritizing protection for critical business activities and using a “cyber threat narrative” to align business owners, IT, and security.
Guests
Thomas Parenti and Jack Domet, co-founders of Archifact Group; co-authors of the HBR article “Sizing Up Your Cyber Risks” and the HBR Pressbook “A Leader’s Guide to Cybersecurity.” Jack is described as the management expert; Thomas as the cybersecurity/leadership co-author.
Key claims
“Worldwide we’re failing at cybersecurity”; compliance can coexist with breaches (Target example); threat intelligence must translate into actionable changes; security awareness training should connect to employees’ real job actions; adversary identification is business-oriented.
Notable examples
Target PCI compliance before hack; financial services client spending ~$3M/year on threat intel with no actionable results; an Asian auto manufacturer locking development networks into corporate intranet, forcing contractors to use fake accounts and granting outsiders global intranet access; phishing attacks becoming targeted via research (e.g., LinkedIn).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Cybersecurity Reality Check
2:12 to 3:39
Discussing the reasons for rising cyber attacks and companies' failures in cybersecurity.
“Presumably a lot of these companies that are hit take some precautions to protect themselves.”
Compliance vs. Actual Security
3:39 to 5:38
Exploring the misconception that compliance equates to security in regulated industries.
“The focus on fixing these computer vulnerabilities, it's seductively dangerous because there is some value here.”
Engaging Non-Tech Leaders
5:38 to 7:45
How to engage senior leaders in cybersecurity discussions as business risks.
“that what effectively happens is they translate in their minds being compliant with requirements as equivalent to being adequately protected.”
The Cyber Threat Narrative Process
7:45 to 10:00
Importance of a narrative process in identifying business risks and cybersecurity.
“Well, it's an interdisciplinary process.”
Balancing Security and Efficiency
10:00 to 13:01
Navigating the balance between cybersecurity precautions and operational efficiency.
“Propel Fitness Water with Gatorade electrolytes, zero sugar, and vitamins.”
Understanding Targeted Cyber Attacks
14:01 to 14:16
Learn how attackers utilize personal information for targeted cyber attacks.
“It's not just Nigerians, princes who want you to give millions.”
The Importance of Security Awareness Training
14:42 to 15:01
Discover the value of security awareness training in cybersecurity.
“This is a job for Indeed Sponsored Jobs.”
Understanding Cybersecurity Implications
15:01 to 16:34
Explore the deeper cybersecurity implications of daily work tasks.
“We could then ask, what is the value that you derived from taking this security training?”
Identifying Cyber Threats and Adversaries
16:34 to 17:50
Learn how to identify unique cyber threats based on business context.
“We might all even be using all the same systems, but our cyber threat narratives will be very different if we're an oil company versus a credit card company.”
Evaluating Business Changes and Cybersecurity
17:50 to 19:51
Understand how business changes impact cybersecurity risks.
“There are a couple of ways in which companies can start to address that issue, one of which is what do they have that would be of value to someone else?”
Show all 17 chapters
Preventing Cyber Attacks: Strategic Focus
19:51 to 21:04
Get insights on how to prevent cyber attacks by focusing on critical activities.
“Depending on where a company operates, the adversaries it might face in one area could be very, very different from the adversaries they could face in another part of their business in another part of the world.”
Dynamic Cybersecurity Planning
21:04 to 23:11
Learn about the ongoing need for dynamic cybersecurity planning.
“In all areas of risk, whether it be financial risk, physical risk or cyber risk, there are no guarantees that what you do will be sufficient to fend off the attack that you actually face.”
Organizational Structure and Cybersecurity
23:11 to 24:31
Explore how organizational structure impacts cybersecurity effectiveness.
“And as we've discussed previously, people will find a way around it.”
Cybersecurity for Small Organizations
24:31 to 26:48
Understand how smaller companies can effectively manage cybersecurity risks.
“Oftentimes, because this has traditionally been a technology issue, the CISO may report to a CIO, a chief information officer, who would be responsible for developing software or deploying computer capabilities.”
Common Misconceptions about Cybersecurity
26:48 to 27:33
Learn about common misconceptions related to cybersecurity solutions.
“and then you can think about how a cyber attack could cause these risks to materialize.”
Best Practices for Cyber Attack Recovery
27:33 to 28:01
Discover effective strategies for recovering from a cyber attack.
“Okay, so let's say that the worst happens, either you haven't followed your advice and you're hit with an attack or you have tried your best and somehow the criminals have still gotten to you.”
Understanding Cybersecurity Responsibilities
28:01 to 30:14
Learn how executives can prepare for and respond to cyber breaches.
“you will have to respond to some sort of cyber breach.”
Transcript
Automatic transcript. May contain errors.0:00When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast. That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs. Propel Fitness Water with Gatorade Electrolytes, Zero Sugar, and Vitamins.
0:35Propel hydrates better than water to help you get the most out of your workout and get back to your best self. What propels you? Propel with Gatorade Electrolytes.
0:55Welcome to the HBR IdeaCast from Harvard Business Review. I'm Alison Beard.
1:06From Apple and JPMorgan Chase to Marriott and British Airways, some of the most sophisticated companies in the world have fallen victim to cyber attacks in recent years. Business-critical activities have been disrupted, customer data has been compromised, and the threats continue. So what can organizations do to prevent themselves from becoming the next target? By now, most accept that they need to invest significant cash and resources into cybersecurity capabilities. But too often, this important job is left to IT leaders rather than the full C-suite and board. Today's guests say that companies need to take a much different approach, with leaders at the very top thinking about cyber risks as not just a technology issue, but a significant business problem to be solved.
1:52Thomas Parenti and Jack Domet are co-founders of the cybersecurity firm Archifact Group and co-authors of the HBR article, Sizing Up Your Cyber Risks, as well as the HBR Pressbook, A Leader's Guide to Cybersecurity. Thomas and Jack, thanks so much for being here.
2:08Thomas Parenty:We're so happy to have the opportunity to talk with you today. Thanks for having us.
2:22Presumably a lot of these companies that are hit take some precautions to protect themselves. So where are they going wrong?
2:29Thomas Parenty:We have come to the realization that essentially worldwide we're failing at cybersecurity and that in spite of all of the investment in public attention, the number and impact of cyber attacks is only rising. In some sense, that's the reason that we're talking right now. And you can think of our current cybersecurity situation today as comparable to trench warfare in World War I. The progress is negligible and the casualties are high. There are several reasons why the focus on cybersecurity and cybersecurity technology ends up undercutting its capacity to protect. First, no company has all of the resources to fix every cybersecurity issue, and not all fixes are equally important.
3:14Thomas Parenty:It's only by starting with a company's most critical business activities and how cyber attacks could disrupt them that one can start to prioritize this whole process of risk mitigation. Unfortunately, there are many companies who sort of skip the step of first thinking about what are the most important business activities that could be disrupted by a cyber attack. And instead, they end up focusing on individual technologies to fix individual problems within their computer systems. The focus on fixing these computer vulnerabilities, it's seductively dangerous because there is some value here. However, a company can spend all of its resources, significant resources, fixing these vulnerabilities without ever addressing the fundamental issue, which is protecting the business activities for which the computers were procured.
4:11So you're basically having the IT department say, well, we're compliant and best practices for a lot of these systems. when they're not taking into account the most important business functions that these systems are protecting.
4:27Thomas Parenty:There are numerous examples of vendors, including Target, who were compliant with the relevant payment card security standards at the very moment that they were successfully hacked. For certain companies, especially those in high school, When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast.
5:07That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs. Propel Fitness Water with Gatorade electrolytes, zero sugar, and vitamins. Propel hydrates better than water to help you get the most out of your workout and get back to your best self. What propels you? Propel with Gatorade electrolytes.
5:30Thomas Parenty:Regulated industries such as financial services, they are subject to so many different compliance requirements that what effectively happens is they translate in their minds being compliant with requirements as equivalent to being adequately protected. And that ends up actually diminishing the security of these companies as opposed to achieving its goal of increasing protection. So, Jack, you're the management expert. Why do organizations operate this way? Why aren't they thinking more holistically about business risks? Well, part of that starts from the fact that since its very inception, cybersecurity has been, it's come out of the technology department.
6:19Thomas Parenty:And it's been looked at in terms of an attack and defense technology paradigm versus one that's related to any other complex business risk that a company might face. Now, there's no question that, you know, given the neglect of cybersecurity over time by most companies in the past, many companies do in fact need to invest more. But as Thomas mentioned, companies like the ones in the financial services space with really large cybersecurity budgets don't nearly get the cyber protection benefit that they should given the dollars that they spend. And we have an example of one of our financial services clients that spent about$3 million a year on cyber threat intelligence.
7:01Thomas Parenty:But when we asked them for examples as to where they actually changed their cybersecurity protections or strategies on the basis of this intelligence, they were silent. $3 million year after year without any actionable result. And in your experience, is it hard to get non-tech leaders to really understand and get involved in these issues? While many companies don't do it, it isn't hard to get them engaged on the process if you change the nature of the conversation, if you change the starting point from which these conversations begin. And that really starts with looking at cyber risks as a business risk that could come and occur as a result of a cyber attack.
7:44So how do you kick off that kind of conversation with senior leaders at a company and the senior tech people?
7:51Thomas Parenty:Well, it's an interdisciplinary process. The approach that we take is that we introduce actually in the article is called a cyber threat narrative, where we bring resources from across the organization, starting with a business owner, someone who's running a business unit, someone who has responsibility for P &L to understand where are the business risks in their organization. What's actually important? What assets are critical to their operations? What activities do they do that provide competitive advantage to them and their organization and their business unit? Once those are identified, you're in a better position to engage with other resources throughout the organization to help quantify what those risks are.
8:34Thomas Parenty:And bringing in the IT department and your cybersecurity resources to understand what the threat environment might be that might affect those risks in some way or make them to come about. One of the dynamics that we are working to change is this perception on the part of non-technical business leaders that the cybersecurity field is so complex, so impenetrable, that they would never be able to understand it. And so it just is logical to delegate that or we should we actually say abrogate that responsibility to either cybersecurity or IT staff. Just as is true of every other business domain, what you need to know about it depends on your role and responsibilities.
9:22Thomas Parenty:And what boards of directors, senior executives and managers need to know about cybersecurity is significantly different. When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast. That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero?
9:57This is a job for Indeed Sponsored Jobs. Propel Fitness Water with Gatorade electrolytes, zero sugar, and vitamins. Propel hydrates better than water to help you get the most out of your workout and get back to your best self. What propels you? Propel with Gatorade electrolytes.
10:15Thomas Parenty:From that required by somebody who is rolling up their sleeves and, if you will, operating on the bits and bytes of a computer. Yeah. Where have you seen a company that hasn't been using that cyber threat narrative process go really wrong and miss a big hole in their systems and be attacked? One example that comes to mind is an Asian automobile manufacturer that we worked with a number of years ago, and they had suffered a breach. And in the aftermath of the breach, the cybersecurity team was tasked with making us so secure that this never happens again. And so the cybersecurity team decided to put the network used for the development of new automobiles inside their corporate network because they thought, ah, an attacker would need to go through two networks in order to be able to then steal information.
11:13Thomas Parenty:In principle, that sounds like a wonderful idea, except there were colleagues from other partner companies that work side by side with these automobile manufacturer employees, and they were now locked out. And so the only way that they could get their work done was to create fake employee accounts for all of these external contractors. And they did this knowing that this was perhaps not the best thing from a cybersecurity perspective, but it's what they needed to do in order to get their job done. And so this illustrates a couple of points, one of which is the cybersecurity people had no idea how the company that they worked for actually designed cars.
11:55Thomas Parenty:And so they proposed security mechanisms that both interfered with work and ended up resulting in the company being more vulnerable because all of these outsiders now had complete access to the corporate intranet globally. Right.
12:39Thomas Parenty:And so they saw no issue whatsoever in going around those protections. Were they then attacked again? One of the sort of insidious things about this particular situation is because all of these outsiders were now treated as insiders, we have no idea what they did. I mean, this is a really important point because we're told not to use open Wi-Fi at cafes or ever give our password to anyone. But there are times when you just think, no, I really have to send that email out. The work needs to get done. So how should organizations walk that line between putting in proper precautions but also ensuring that people still can be efficient?
13:27Thomas Parenty:You know, we've found that cybersecurity writ large is full of platitudes that seem obvious and compelling at first read. But if you think about them more thoughtfully, they're sometimes misinformed. One example where this often comes into a play is in a class of cyber attack called phishing. People often, you know, open attachments because you read your email. And occasionally those attachments result in malware being downloaded onto their computers. But, you know, and attackers have become savvier over time. It's not just Nigerians, princes who want you to give millions. They'll do research that's specific about you to your LinkedIn account, etc., so they can deliver a very targeted attack.
14:12Thomas Parenty:Yet the common thing. When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast. That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs. Propel Fitness Water with Gatorade electrolytes, zero sugar, and vitamins.
14:50Propel hydrates better than water to help you get the most out of your workout and get back to your best self. What propels you? Propel with Gatorade electrolytes.
15:00Thomas Parenty:That cybersecurity departments typically put into place is what's called security awareness training. I just completed mine. You just did. We could then ask, what is the value that you derived from taking this security training? Don't answer that. I do think I'm more careful, but I think the big thing is the problem isn't necessarily stemming from a phishing attack. So one of the things that is important to note, and this is something that is illustrated both by your security awareness training and also by the example from the automobile company, is that while it is common for security training to talk about generic good things to do.
15:47Thomas Parenty:So if you're in a Wi-Fi hotspot, use a VPN so that the person sipping a latte next to you isn't also reading your email. But what is missing is informing employees about the cybersecurity implications of their own work. And so this requires actually going beyond a list of generic good things to do to actually looking at how an employee functions in their day-to-day work life and how the actions they perform either discourage a cyber attack from being successful or lay the groundwork for a cyber attack on the critical business activity that they are involved in from being effective. So, I mean, every company is a technology company now because we're all digital.
16:38We might all even be using all the same systems, but our cyber threat narratives will be very different if we're an oil company versus a credit card company.
16:47Thomas Parenty:Even within a company, where are your locations? What are your different business units? Each of these have different characteristics. They vary widely. And those might be the products and services that that business unit does or its location and the regulatory regime and geopolitical environment that lives within that location or their supply chain or their customers or their products and services, etc. All those things add together to drive a very different risk profile. So you talk in the article about imagining not only the threats, but also who your adversaries are. How do you do that sort of when what you're trying to do is keep up with criminals who are constantly trying to find new tools and strategies to get at you?
17:32Thomas Parenty:So I would say that the strategies that criminals or others use to attack you is one issue. And it is certainly relevant for cybersecurity staff to keep abreast of the latest techniques that cyber adversaries might use. However, in terms of identifying those cyber adversaries, that is something that is, for the most part, a very business-oriented activity that doesn't require technical knowledge. There are a couple of ways in which companies can start to address that issue, one of which is what do they have that would be of value to someone else? That could be the design of a product. It could be a collection of customers.
18:16Thomas Parenty:By identifying what a company has that could be of value, that's one way of looking at it. Another avenue that companies can take is, is there anything about the business that the company is in, the way in which it operates, that might attract some sort of attacker? With increasing discussions about climate change, companies that are viewed as carbon negative could attract this kind of attention. Or if there was a case in which a company was not or an organization was not being honest about certain of its business practices, that could invite a cyber attacker. And point of fact, that would be the situation that might.
19:00When you need to build up your team to handle the growing chaos at work, use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a$75 sponsored job credit at Indeed.com slash podcast. That's Indeed.com slash podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs. Propel Fitness Water with Gatorade electrolytes, zero sugar, and vitamins.
19:36Propel hydrates better than water to help you get the most out of your workout and get back to your best self. What propels you? Propel with Gatorade electrolytes.
19:45Thomas Parenty:Former employer NSA was in with respect to Edward Snowden. Depending on where a company operates, the adversaries it might face in one area could be very, very different from the adversaries they could face in another part of their business in another part of the world. Right. And I don't want to make it seem like you're advertising your business, but because these issues are so complicated and so different from function to function and company to company and geography to geography, do organizations need to bring in outside help and expertise? One of the things that we talk about in the book is the importance of building an internal capability to recognize what really, truly drives your cyber risk going forward.
20:34Thomas Parenty:And oftentimes those are changes in the way you do business because most of those new cyber risks come less from a new type of technical attack. It's actually that merger that you're about to go through or that new product that you're about to launch or that change to that internal application that you have. Those are all things that change the way that you're doing business. And those changes have implications as it relates to the risk that you face. So whether an attack is simple or sophisticated, are you saying that companies are able to prevent them if they take the right steps? In all areas of risk, whether it be financial risk, physical risk or cyber risk, there are no guarantees that what you do will be sufficient to fend off the attack that you actually face.
21:26Thomas Parenty:However, if you actually have focus on knowing what is important to protect, understanding the kinds of cyber attacks that could compromise critical activities, you are in a much, much better place to defend yourself properly than if you take more of a shotgun approach of, well, this is a general vulnerability. and so I'm going to buy a box that takes care of that. How frequently do leaders of a company or a function need to be reviewing and then revising what their plan is? It's an ongoing exercise, right? I mean, it's not a one-off thing. This is something that's dynamic. And to our point before in terms of where to look for cyber risks, where to anticipate them, it generally relates to changes that you're making to your business, whether it's a new product that you're launching, a new geography that you're getting into, a new supply chain partner that you're working with, all these point to changes in the way that you do business.
22:32Thomas Parenty:These introduce changes in technology because of the way that we work today. And those changes in the technology and the way you do business invite you to do new things with your business that drives new risks. Right. And so in some sense, the one answer is that companies need to incorporate into all of the processes used for making change some type of cybersecurity review. Now, this does not have to be and should not be a terribly onerous and time-consuming activity because, one, that will get in the way of doing business. And as we've discussed previously, people will find a way around it. But it is important to make sure that when companies are undertaking the changes that will introduce new cyber risk, that they are at least paying attention to that.
23:24Are there ways that companies should restructure themselves to make sure that people at every level and in every part of the organization are thinking about cybersecurity in a more careful way?
Read the full transcript
23:36Thomas Parenty:Yeah, I mean, it's about building. There's a few different things. One area that we look at is building an internal organizational capability to deal with this change management process that companies go through. As Thomas was mentioning, we need to have cybersecurity reviews as you change your business, just like you look at other risks. Another area where we think about organization and cyber is where do you put the capability for managing cybersecurity? Many companies, including probably two-thirds of the Fortune 500, have what's called a chief information security officer, commonly referred to as a CISO.
24:20Thomas Parenty:to have rolled up responsibility for dealing with cyber risk and deciding what risks need to be managed and what investments need to be made. But there are some issues in terms of where that CISO might report. Oftentimes, because this has traditionally been a technology issue, the CISO may report to a CIO, a chief information officer, who would be responsible for developing software or deploying computer capabilities. But the incentives for someone who's in charge of security and the incentives for someone who's in charge of building applications that are very different. Yeah. So that person should maybe be reporting to the CEO instead?
25:07Thomas Parenty:The CEO, while it would appear to be the best place for cybersecurity to report to, actually is not because one of the longstanding problems with cybersecurity is that it has lived in a silo frequently within the IT department. But it lives someplace else that made it very easy for other business leaders to ignore it and say it's somebody else's problem. And so if it reported to the CEO, the natural conclusion would be, ah, it's taken care of. After all, it reports to the CEO. But a good CEO is successful because the people who work for him get things done. Based on our experience, when a company is looking for a home for the cybersecurity organization, they should first look at where their most significant cyber risks reside, as well as finding a corporate home where the interests of the manager of cybersecurity are completely aligned with the executive to whom he or she reports.
26:20So we've been talking about a lot of big companies. How should smaller organizations deal with these threats? You know, on one hand, they're less likely to be targets. But then on the other hand, they have less money to invest and sort of fewer resources to throw at it.
26:39Thomas Parenty:So our advice for companies of any size is the same. Focus on your company's most significant activities and the business risks they face. and then you can think about how a cyber attack could cause these risks to materialize. Several years ago, I was talking with an electrician who was doing some work in my house. When he learned I worked in the cybersecurity field, he told me he needed a firewall. When I asked why, he replied that he thought his business partner was cheating him. I told him a firewall wouldn't help reduce his risk because firewalls help protect against attacks originating from the Internet, not from the office where both he and his partner sat.
27:18Thomas Parenty:That he immediately jumped from a cyber risk, his partner misusing computers to steal from him, to a technology fix is common and therefore completely understandable. That a firewall would come to mind also makes sense because firewalls are well known, if not well understood. Okay, so let's say that the worst happens, either you haven't followed your advice and you're hit with an attack or you have tried your best and somehow the criminals have still gotten to you. What are some of the best practices for recovering from that? Okay. So the first element is that while one should always focus on proactive measures, one does need to take into account that under some circumstances, you will have to respond to some sort of cyber breach.
28:09Thomas Parenty:And this is, again, a responsibility that falls not just to cybersecurity staff, but also to the leadership of a company. A company needs to have the technical capabilities to respond to the most likely forms of cyber attack on their most critical business activities. If you understand what those activities are and those cyber threats, that is something you can prepare ahead of time. From an executive perspective, they need to be in a position to make decisions and publicly engage in the aftermath of said cyber attack, essentially to pre-think the consequences and pre-think the decisions they will need to make, if you will, in the clear light of day as opposed to in the fog of war.
29:02So if I'm a manager with no expertise in these issues, where should I start to get more up to speed?
29:10Thomas Parenty:It's something that what they can do is simply have different discussions with the cybersecurity people that they already have in-house. Again, start the conversation with, here's a critical business activity. These are the concerns I have as a non-technical business manager in terms of what could go wrong. Now, talk to me, cybersecurity and IT people, about, one, what are the systems that support this activity so I know where you need to prioritize the attention that you give? And second, talk to me about how the cyber attacks that you know and follow would be able to compromise the system supporting my business and what are the sorts of impact?
29:58Thomas Parenty:If you have this conversation from the perspective of talk to me about how my business could be compromised instead of telling me what vulnerabilities need to be fixed with whatever priority, then you'll get somewhere. Thank you all so much for talking with me today. It has been our pleasure. Thanks for having us.
30:24That's Thomas Parenti and Jack Domet co-founders of the cybersecurity firm Archifact Group They're also the co-authors of the HBR article Sizing Up Your Cyber Risks and the HBR Pressbook A Leader's Guide to Cybersecurity
30:42This episode was produced by Mary Du We get technical help from Rob Eckhart Adam Buchholz is our audio product manager
30:53Thanks for listening to the HBR IdeaCast. I'm Alison Beard.
31:21Thank you.
From the publisher
Why Cybersecurity Isn’t Only a Tech Problem | HBR IdeaCast | Podcast
20 Dec 2022
---
Thomas Parenty and Jack Domet, cofounders of the cybersecurity firm Archefact Group, say that most organizations are approaching cybersecurity all wrong. Whether they’re running small companies or working in multinational corporations, leaders have to think beyond their IT department and technology systems to instead focus on protecting their businesses’ most important assets from attack. They need to work across functions and geographies to identify key risks, imagine potential threats and adversaries, and develop a plan for combating them. Parenty and Domet are the authors of the HBR article “Sizing up your Cyber Risks,” as well as the HBR Press book, A Leader’s Guide to Cybersecurity. (https://www.amazon.com/Leaders-Guide-Cybersecurity-Boards-Lead/dp/1633697991)
This episode originally aired on HBR IdeaCast on December 3, 2019.
Listen to more IdeaCast episodes here: https://www.youtube.com/playlist?list=PLzAU8TPKsJuaxff5Cp0P2DKE_tFyaWOOa
You can also listen to this episode on HBR.org, and wherever you listen to podcasts:
- HBR.org (transcript available here): https://hbr.org/podcast/2019/12/why-cybersecurity-isnt-only-a-tech-problem
- Apple Podcasts: https://podcasts.apple.com/us/podcast/why-cybersecurity-isnt-only-a-tech-problem/id152022135?i=1000458551631
- Spotify: https://open.spotify.com/episode/2ZuH3JGZjmoYoknIlntLcz
- Stitcher: https://www.stitcher.com/show/hbr-ideacast/episode/why-cybersecurity-isnt-only-a-tech-problem-65752077
- Google Podcasts: https://podcasts.google.com/feed/aHR0cDovL2ZlZWRzLmhhcnZhcmRidXNpbmVzcy5vcmcvaGFydmFyZGJ1c2luZXNzL2lkZWFjYXN0/episode/dGFnOmF1ZGlvLmhici5vcmcsMjAwNi0wNS0wODppZGVhY2FzdC4wNzEy?sa=X&ved=0CAIQuIEEahcKEwjY_tGer-j7AhUAAAAAHQAAAAAQCg
Series Description:
A weekly podcast featuring the leading thinkers in business and management.
About Harvard Business Review:
Harvard Business Review is the leading destination for smart management thinking. Through its flagship magazine, books, and digital content and tools published on HBR.org, Harvard Business Review aims to provide professionals around the world with rigorous insights and best practices to help lead themselves and their organizations more effectively and to make a positive impact. Learn more at www.hbr.org.
Chapters:
00:00 – Intro
1:36 – Why Are We Failing at Cybersecurity?
4:26 – The Management Risks
6:21 – Conversation With Senior Leaders
10:46 – Perfect Balance Between Precautions and Efficiency.
16:20 – Is External Help Necessary?
22:34 – How should smaller organizations deal with threats?
25:16 – How to succeed with no expertise
27:11- Outro
Follow Harvard Business Review: https://hbr.org/ https://www.linkedin.com/company/harv... https://www.facebook.com/HBR/ https://twitter.com/HarvardBiz https://www.instagram.com/harvard_bus...
Sign up for Newsletters: https://hbr.org/email-newsletters
#HarvardBusinessReview #business #management
Copyright © 2022 Harvard Business School Publishing. All rights reserved.
Learn more about your ad choices. Visit megaphone.fm/adchoices




