Napoleon Would Have Been A Great CISO

Napoleon is considered one of the greatest commanders in history. A tactician and strategist ahead of his times who built a large empire that ruled over much of continental Europe. To this day his wars and campaigns are studied at military schools worldwide.

One of my favourite Napoleon quotes is “The battlefield is a scene of constant chaos. The winner will be the one who controls that chaos, both his own and the enemies.”

This has been used as an analogy for how to succeed in business but I think it is just as applicable to success in the field of information and cyber security. Without the ability to organise and co-ordinate your resources (people and technology) your organisation will remain open to the evolving threat of cyber crime.

Here are some thoughts on a battle plan of practical steps you can take;

1. Start by defining which information assets are of greatest importance to the business i.e. those where the impact of a breach in security would be detrimental to your business.

2. Make sure you have the most critical security controls in place that will provide protection against the most common attack patterns. Control frameworks like CIS Critical Security controls and Cyber Essentials are very effective and have been vetted across a very broad community of government and industry practitioners.

3. Ensure you have consistent processes and workflows in place, to check that you continue to have the right control coverage across your critical information assets and that each security control is functioning as intended.

4. Make sure your workflows have SLA’s associated with them so that control owners can be measured and held accountable over time.

5. Automate compliance checks for your security controls wherever possible to minimise the threat window and free up your skilled resources

6. Measure and report on the effectiveness of your controls over time so you and other stakeholders can clearly establish exactly where they are falling short & use as a basis for continual improvement.

Implementing these battle tactics will mean you can take control, avoid chaos and defeat your cyber enemies.

