TLP WHITE - FINAL
Entities that fail to recognize this concept may exhibit an imbalance by having an over
reliance on perimeter controls, at the detriment of clearly defined and regularly exercised
responses (Element 5) and a viable, tested contingency plan for the resumption of operations
(Element 6).
Outcome 4: An adaptive cyber security approach is adopted.
Both cyber threats and the vulnerabilities which they exploit continue to emerge and evolve.
Correspondingly, entities need to be adaptive and avoid a static fortress mentality to ensure
their cybersecurity procedures reflect the ever changing landscape within which they operate.
Building on Element 5 (response) and Element 6 (recovery), incident response mechanisms
need to be well-rehearsed such that economic functions can continue to operate through
disruption or stress, whether at the entity, sector, cross-sector or international levels. As
disruptions may impact the financial sector in unexpected ways, flexibility is key in reactive
functions. Coupled with Element 4 (monitoring), it is the agility and experience to rapidly
identify and contain disruptions that largely influence the resulting impacts. Related, the
overall focus should be on fostering an environment of continuous improvement and learning
as part of the cybersecurity program.
Outcome 5: There is a culture that drives secure behaviors.
Building on Element 7 (information sharing) and Element 8 (continuous learning), a
continuous focus on skills and behaviors is essential for embedding effective cybersecurity
into the fabric of an organization.
In many cybersecurity incidents, flawed procedures or human factors play a key role (e.g.
leveraging weak passwords, social engineering, poor security awareness, etc.). Effective
cybersecurity strategies consider aspects of people and processes on an equal footing with
technical solutions, and reflect this in investment decisions taken. Training and awareness are
equally important, targeted at the end user, employee, and senior management.
In a world where individuals often trade security for convenience, the manipulation of human
psychology is as relevant as an adversary's technological sophistication. Each individual
understands that they have a role to play. Effective cybersecurity relies on engaging and
educating people, and enabling them to handle information safely. Cybersecurity training and
awareness can enhance technical knowledge as well as offer opportunities to change
behaviors. Effective training aims for genuine and measurable change, shaping culture in a
meaningful way, rather than seeking compliance with a set of policies. The adage that people
are considered as the weakest link is reversed, instead promoted as the most valuable asset.
PART B: Promoting effective cybersecurity assessments
As entities embed the G7FE and strive to achieve the desired outcomes outlined above, there
is a necessity to conduct regular assessments to measure the effectiveness of their
cybersecurity programs.
Cybersecurity assessment can be defined as the systematic collection, review, and use of
information on the cybersecurity practices and controls of individual financial sector entities
(private or public) or sector participants collectively for the purposes of: (i) judging
performance, measured against intended outcomes; and (ii) providing feedback and setting
out areas for improvement, including remedial actions.
3