خبرگزاری امارات اینترنشنالامارات و خلیج فارس، بین‌المللی
Kior Shah: Cybersecurity has become a board responsibility
Technology

Kior Shah: Cybersecurity has become a board responsibility

منبع تصویر: gulfnews.com

By Emarat International News Agency Editorial 2 min Read time 31,852

Kior Shah, Deputy CISO at Sophos, considers cybersecurity a business responsibility and emphasizes the importance of investing in this area. With the rise of cyber threats that can impact operations, revenue, reputation, and customer trust, organizations are forced to rethink how they manage cyber risk.

Board Responsibility in Cyber Risk Management

Kior Shah states: "Cybersecurity is no longer just an IT department issue. When an attack can halt operations, disrupt revenue, and damage customer reputation, cyber risk becomes a business risk and the responsibility shifts to the board."

The challenges are compounded as hackers increasingly use artificial intelligence and operate across various domains such as identity, email, endpoints, networks, and cloud. Shah emphasizes that independent defense of each of these layers is no longer sufficient.

Connected Defense and Smart Investment

Shah refers to the concept of "connected defense," which includes prevention, detection, threat intelligence, and response as a unified system. For Chief Information Security Officers (CISOs), resilience does not depend on the number of tools implemented, but on "how quickly we can see, decide, control, and recover, and how prepared we are before an attack occurs."

This shift also changes board conversations about investment and responsibility. John Dherst, a recognized SANS trainer at the SANS Institute, says: "Cyber risk is business risk. IT leaders must translate technical concerns into simple business language to effectively request funding and clarify the medium- and long-term risks of cyber threats to the board."

Investment in cybersecurity should not be limited to technology alone. Dherst emphasizes that "everyone in an organization is responsible for cybersecurity," especially with the expansion of shadow IT that increases the potential attack surface.

Success metrics also require a different mindset. Dherst states: "Strong cybersecurity protection is akin to normal business operations. It is tedious, but tedious is the goal." When incidents occur, regular and precise decision-making becomes critically important. He adds: "Do not focus on how the attack happened. Concentrate on why it happened, so history does not repeat itself."

Ultimately, Shah concludes that in the age of artificial intelligence, "the speed of decision-making and coordinated response will determine cyber resilience."

Source: gulfnews.com