Contextualizing cyber risk: Mapping business as a system

Blog

TAX ALERT | July 05, 2022

Authored by RSM US LLP


What would happen if one of your critical lines of business suffered a cyberattack? Would business come to a screeching halt? Board members need to know how their organization plans to manage security risks, but in a 2022 Harvard Business Review survey, only 68 percent of directors said their board “regularly or constantly discussed cybersecurity.”

To close this gap, boards need a better understanding of how business could be impacted by cyberthreats. Articulating business as a system offers the necessary perspective and addresses three of the obstacles that boards face when considering risk: the current cybersecurity landscape, information filtering, and lack of context.

The current cybersecurity landscape

According to the newly released 2022 RSM US Middle Market Business Index Cybersecurity Special Report, of the 402 senior executives polled, 22 percent of middle market executives said their companies experienced a data breach in the past year, down from 28 percent in last year’s survey. Both larger and smaller market organizations also reported a decrease in attacks.

But a reduction in breaches doesn’t mean there is room for complacency. Attacks will continue and smart leaders are preparing to meet those threats. In fact, 72 percent of executives anticipate that unauthorized users will attempt to access data or systems in 2022 and 62 percent believe they are at risk for a ransomware attack in the next 12 months.

The reality of information filtering

Board members depend on information produced and presented by the organization’s leadership team, which may be filtered through several layers of gatekeepers on its way to the quarterly meeting.

While not intentionally incomplete, these snapshots of the business may leave knowledge gaps that impact decision-making. Even well-meaning leaders may not have an accurate read on the organization’s risk profile if information from the information technology teams on the front lines is not clearly communicated. Executives may not know if all purchased solutions have been implemented, whether they are performing as intended, and which challenges remain. This information gap can leave organizations unaware of their actual risk profile. So, while 96 percent of leaders report they are confident in their organization’s efforts to safeguard data, the reality often falls short of expectations.

Lack of context

Though cybersecurity professionals stay up-to-date on threats, vulnerabilities, and solutions, they usually lack a clear picture of the overall business, its processes, and financial complexities. Questions such as, “If we develop a cybersecurity framework and find gaps in the overall security program, how does that affect the organization overall?” and “Which lines of business are critical to the company’s profitability?” can only be answered if their cyber knowledge is rooted in the context of the overall business.

Evaluating the impact of specific security risks on various lines of business and understanding the implications of a breach across the enterprise require context. The best way to get those insights is by mapping out the business as a system.

Business as a system

At its highest level, mapping business as a system means considering how the organization makes money, identifying the key supporting business processes, and putting into context how cyber risk may affect these critical business process. It is helpful to visualize the flow of the business, and then identify the relevant and contextualized security scope areas that hinder strategy and increase business risk.

Executives need to share a variety of perspectives to chart the business as a system, and the results will offer business-contextualized insights for the board and other decision-makers. Building a map of an organization is a four-phase process:

  • Phase one: Develop a high-level business process map;
  • Phase two: Complete focused business process decomposition or reengineering;
  • Phase three: Conduct a control framework analysis (following the National Institute of Standards and Technology’s Cybersecurity Framework); and
  • Phase four: Evaluate the enterprise as a system.

Once created, the map illustrates the way processes and risks are interrelated. If a process is responsible for significant revenue, addressing risks to that line of business takes on greater urgency. And as a picture of the enterprise emerges, it is easier to identify the places where processes converge and cybersecurity is of greatest concern.

Connecting the dots

Even as cyberattacks evolve, the map of the business will guide strategic growth and risk management efforts. With the framework of business as a system, leaders can map a course forward. Board members can ask better questions to the cybersecurity professionals—now that they understand the context—and then connect the dots between vulnerabilities and impact to the bottom line.

Republished with permission from NACD Boardtalk.

This article was written by Ken Stasiak and originally appeared on Jul 05, 2022.
2022 RSM US LLP. All rights reserved.
https://rsmus.com/insights/services/risk-fraud-cybersecurity/contextualizing-cyber-risk-mapping-business-as-a-system.html

RSM US Alliance provides its members with access to resources of RSM US LLP. RSM US Alliance member firms are separate and independent businesses and legal entities that are responsible for their own acts and omissions, and each is separate and independent from RSM US LLP. RSM US LLP is the U.S. member firm of RSM International, a global network of independent audit, tax, and consulting firms. Members of RSM US Alliance have access to RSM International resources through RSM US LLP but are not member firms of RSM International. Visit rsmus.com/about us for more information regarding RSM US LLP and RSM International. The RSM logo is used under license by RSM US LLP. RSM US Alliance products and services are proprietary to RSM US LLP.

Firley, Moran, Freer & Eassa is a proud member of RSM US Alliance, a premier affiliation of independent accounting and consulting firms in the United States. RSM US Alliance provides our firm with access to resources of RSM US LLP, the leading provider of audit, tax and consulting services focused on the middle market. RSM US LLP is a licensed CPA firm and the U.S. member of RSM International, a global network of independent audit, tax and consulting firms with more than 43,000 people in over 120 countries.

Our membership in RSM US Alliance has elevated our capabilities in the marketplace, helping to differentiate our firm from the competition while allowing us to maintain our independence and entrepreneurial culture. We have access to a valuable peer network of like-sized firms as well as a broad range of tools, expertise, and technical resources.

For more information on how the Firley, Moran, Freer & Eassa can assist you, please call us at (315) 472-7045.

Let’s Talk!

You can reach us at info@fmfecpa.com or fill out the form below and we’ll contact you to discuss your specific situation.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.