
On a recent stay in an AirBnB I came across a once familiar sight that I hadn’t actually seen in a while (although maybe I don’t stay away as much as I used to), and it immediately got me thinking about not only the assurance it actually provided me but also the motivations of the person who put it there (or probably the motivation of the person who instructs the cleaner to keep putting it there!).
The ‘Sanitised for your protection’ label wrapped around the toilet seat is undoubtedly meant to provide an immediate sense of comfort and a visual confirmation that a standard has been met. But has it? Does it guarantee the toilet is clean, or just that the owner/maintainer wanted me to believe it was?
In Penny’s recent blog post ‘Passed the audit, but lost the data’, she highlights the dangers of over-reliance on a compliance certificate that not only represents a moment in time but also the imperfect reality of how policies and procedures are implemented in the real world. Did the cleaner actually scrub the toilet or just re-attach the ribbon?
Stepping out of the bathroom (before I take this analogy any further) and into the boardroom, when the report becomes the deliverable, we are in danger of losing sight of the objective; actual cyber resilience. Leadership can gain a false sense of security, assuming that because an assurance activity was completed, the risk is managed.
This is when I believe layered assurance activities really come into play.
If you’ve got that certificate, think about assurance activities that can provide continuous checks and balances beyond it. ISO standards highlight the importance of continual improvement, but don’t focus enough on assurance activities beyond checking that you have some sort of ‘internal audit’ approach in place. In practice, the internal audit is often just a another point-in-time dry run of the external audit, and whilst it provides assurance that you’ll get your new shiny certification, it won’t necessarily provide any more assurance that the controls are actually effective all year-round.
I often use penetration testing as an excellent example of a potentially good assurance activity that I believe is often wrongly deployed:
- It suffers the same pitfalls as the ISO certification that Penny highlights: it is just a moment in time assurance activity.
- It is often carried out to tell people something they probably already know: their systems are misconfigured and the software is riddled with bugs and vulnerabilities.
Am I saying organisations should ditch penetration testing then? Certainly not. We just need to tweak how and when we deploy what is a relatively expensive assurance activity to get maximum benefit. Firstly, only run a penetration test when you believe you have implemented effective security and want to demonstrate it with a relatively short pen test report (pen testers always find something! 😅). Secondly you should implement some form of continuous control monitoring as a first line assurance activity. The annual pen test becomes your second line activity, and the auditor checking you have a pen test report becomes your third line activity.
That pen test report is no longer the strip of paper around the toilet. Assurance activities are only worth doing if you have already done the hard work of implementing controls to manage your cyber risk.
Before you commission your next penetration test or schedule your next compliance audit, take a step back and evaluate your foundational security posture. Are you paying for an expensive report just to highlight the gaps you already suspect are there? Or are you investing in continuous control monitoring to maintain true, day-to-day hygiene? Don’t settle for the security equivalent of a paper strip over a problem you haven’t fixed yet. Put the hard work into building and maintaining robust controls first, and let your assurance activities do what they were meant to do: prove that your cyber resilience is real, not just an illusion.
Want to learn more about how we can help? Chat with us today.
Photo by Shubham Dhage on Unsplash