October is Cybersecurity Awareness Month, but Michael Tanji isn’t celebrating. He said there is little to gain from emphasizing once a year what businesses should preach and practice every hour of the day. Ever heard of a company that observed an annual Profit Month? It wouldn’t last long.
“Everyone surges on Cybersecurity Month, as if the threat predictably goes up just before Halloween,” said Tanji, director of cybersecurity for MxD, the National Center for Cybersecurity in Manufacturing as designated by the U.S. Department of War. “We harp on completing annual training, but nobody said you only had to train once a year. Security culture has confused ‘important’ with ‘special,’ and business has confused ‘special’ with ‘rare.’ We’re worse off for it.”
Whenever a business emphasizes cybersecurity best practices, even in October, it’s doing something important. But the trouble, Tanji said, comes when protecting manufacturing systems and processes gets downgraded to the equivalent of an annual physical.
“Think of it like this: What are the subjects you, as a CEO or business unit leader, talk about on a weekly, if not daily, basis?” he asked. “Operations? Financials? Logistics? Why? Because they’re the most important aspects of your business, correct? When do you talk about cybersecurity? Once a year, watching the same canned video, and only because you’re forced to? This sort of behavior is you telling your people in no uncertain terms that cybersecurity isn’t a topic of importance and doesn’t warrant attention, much less effort.”
Tanji said the message of this year’s Cybersecurity Awareness Month should be that the concept is obsolete and that businesses should stop treating cybersecurity as something special.
“Make cybersecurity a part of those weekly or daily conversations you have with the rest of the team,” he said. “Make sure issues are put into a context everyone will understand and delivered in plain English. Come up with metrics that make sense for your business and make sure they’re treated as seriously as production numbers or financials. This is how you prove your commitment to a more secure enterprise and supply chain.”
Four questions for Michael Tanji:
What else frustrates you about Cybersecurity Awareness Month?
Michael Tanji: It has become one of those things we know how to do, rather than something that actually works. As far as I know, no data shows that 20-plus years of Cybersecurity Month has done anything to strengthen cybersecurity postures.
Make the argument for going all in on cybersecurity.
Tanji: This is a contest between nations, and manufacturers were drafted without their knowledge. The opposition declared war a long time ago, and it chose to use tactics that don’t look or feel like war but cause damage nevertheless. Not fighting back, or at least putting up a resistance, is tantamount to surrendering. It’s hard to grasp this because most of the messaging in this space focuses on crime, financial loss, regulatory failures, etc. Even in military circles, the kind of conflict we’re in is treated as a fringe topic, but it’s the war we’re in, not the war we want to fight.
How do you make cybersecurity an integral part of ongoing operations?
Tanji: You have to make a commitment to improving your cybersecurity posture. With money, not lip service. As with any other business effort, you have to identify what success looks like and how you’ll measure it, and make sure you have the resources (including human resources) to do things properly. You need someone to lead the effort, not necessarily do all the work. Some percentage of everyone’s working hours has to be allocated to supporting the security function. It might only be 10 minutes, but it’s something that can’t be skipped.
What are three things companies should start doing better?
Tanji: Once you’ve made the commitment to improving cybersecurity, you should align security achievements with rewards. People respond to incentives, and security is no different. Make adhering to security policy and performing security functions rated items in performance reviews. Some percentage of their bonuses should depend on it.
Understand what security metrics are important to you and measure them as you would every other aspect of your business. Understand what is working and what isn’t, and make corrections. Identify leading indicators that will help you get ahead of problems rather than respond to them.
Implement the security features you’ve already got. For Windows or Mac, you’ve got a firewall and antivirus programs built in. Make sure they’re turned on. Go to your IT and OT [operational technology] vendor websites and get familiar with their security reporting and solution pages. Make sure patches are set to update automatically, if possible. Deal with the low-hanging fruit so you can concentrate your scarce cybersecurity expertise on the issues that require a heavier lift.