There are many factors and premises an organization must consider to define its cybersecurity strategy; however, the mere fact that an organization asks itself this question is already a sign of maturity.
First of all, cybersecurity is a “set of measures to protect information by addressing the threats that put at risk the information handled by interconnected information systems“, according to ISACA (Information Systems Audit and Control Association).
In other words, we are talking about systems, networks and data that we need to protect. And this protection will depend on the infrastructure we have, the organization’s resources to protect them, its maturity, etc.
Cybersecurity-related technology does not make sense on its own; rather, it is obliged to support the organization’s strategic objectives. For example, if the organization wants to open a new line of business or digitize an area by implementing new software, cybersecurity must be the area in charge of protecting the organization against attacks that jeopardize the information security of these new services.
This is why, in some models, a role such as the CISO sits within senior management in order to learn first-hand about the business’s strategic objectives and protect them appropriately. As with any strategy, the involvement of senior management is a key element.
What factors can determine the cybersecurity strategy?
There may be certain premises that determine the organization’s cybersecurity strategy, such as legal factors. For example, if an organization has systems in place to support essential services, it will be considered critical infrastructure and will need to take a series of requirements into account within its strategy. Compliance is therefore an aspect to consider when implementing cybersecurity in a company.
All of this leads us to conclude that the cybersecurity strategy will depend on the organization’s strategic and business objectives, on the resources and capabilities it possesses, and on internal and external factors that we will call context. Adapting to our reality is essential to succeed in bringing the strategy down to an organization’s operational layer.
A good starting point for defining the security strategy is to answer the following question: what is critical for the organization? which are the assets we cannot do without?
It is also advisable to ask this question to several leaders or areas within the organization, since it is fairly common for an important business process to depend on an asset that only one area is aware of.
Once we know what we need to protect, we need to carry out the exercise of identifying the risks that could jeopardize its integrity and identifying the controls we have in place. Without knowing what could happen to us and what we have, it would be a mistake to start implementing controls straight away.
This exercise will allow us to identify our strengths and weaknesses in terms of cybersecurity in the company, identify our shortcomings and act on them. It will also give us an overview of our different layers and how we protect our most valuable assets:

Defense-in-depth diagram
Cybersecurity strategy: Defense in depth
At this point we would be forming a strategy known as defense in depth. This concept originates in the military world; it is a strategy that slows the enemy’s advance through the various methods and controls (layers), instead of relying on a single protection method, however excellent it might be.
This strategy ensures that the attacker needs more time and knowledge to achieve their goal, which is to compromise the security of our critical assets. It also allows the defender to formulate a more effective response.
However, let us not think only about technical measures and cybersecurity programs. Just as important, if not more so, is how the user interacts with our systems. This management layer contains all the organization’s policies, regulations and procedures, and provides the basic principles on which to structure the rest of the more technical safeguards.
The complexity of organizations’ infrastructure makes it necessary to implement a management framework that allows all implemented processes to be maintained. Reporting relevant data to management, incident management, risk assessment and management, compliance management, etc., will have to be defined and maintained.
We have the option of defining these processes according to the organization’s needs or implementing an information security framework recognized in the industry. There are some that, depending on our purpose, we could implement: ISO 27001, CIS Security Controls, NIST Framework, PCI-DSS, ENS, etc.
It will depend on the organization’s resources and needs whether to implement one or combine the requirements of two or more. For example, if we need certification from a third party we will choose ISO 27001, whereas if we are developing a payment gateway, PCI DSS is likely to be a good option. Of course, this kind of task will be much easier if we have a tool that lets us combine all the aspects of such a system at different scales within our organization. At GlobalSuite Solutions we can support you by implementing the procedures that ISO 27001 standard applies, making an initial compliance assessment and working on the formulation of gap closure to update your Information Security Management System (ISMS) and your cybersecurity systems to achieve their automation through GlobalSuite®.
A constantly evolving cybersecurity strategy
But that is not all: when we define a strategy we must bear in mind that our reality is constantly changing when it comes to cybersecurity. The strategy we define must be flexible enough to adapt to market requirements and new technologies over time.
A recent example of the need to adapt the cybersecurity strategy to change in companies was the one brought about by the COVID-19 pandemic. Most organizations had a strategy for protecting users outside the corporate network based on authentication using a controlled and secured service, such as a VPN connection. These types of connections were sized for a limited number of users; however, these needs changed when everyone had to connect from home.
From one day to the next, organizations were forced to provide access to new devices, in some cases non-corporate ones, a huge number of connections incompatible with the licenses they had, etc. In other words, overnight the strategy for protecting user devices had to change.
Both manufacturers and companies needed to offer and adopt cybersecurity solutions that hardened the device used to connect rather than the network used to do so, since being outside the corporate perimeter they had no access to it.
We must be ready for change, also in our strategies because, although we do not know how, it is certain that it will come.
How to implement your cybersecurity strategy?
The team’s knowledge, the number of cybersecurity programs required and the constant updating involved in implementing all these controls lead to a high degree of complexity that an organization often cannot take on by itself. That is why many companies rely on external support to help them deal with cyber incidents, monitor their infrastructure for anomalies or, in short, provide cybersecurity solutions in a specialized way. We would be talking about managed SOC services, CERTs, cyber-risk insurance, etc. Depending on the size of our company, the strategy of outsourcing operations can become a good alternative.
And now, what is your strategy? Whatever it is, it is important to keep in mind the following conclusions:
- Decisions based on data and information: the first step to defining a strategy is to know our organization, what is important and what our strengths and weaknesses are.
- The cybersecurity strategy must be supported by senior management. And conversely, cybersecurity must support and adapt to the business objectives.
- The cybersecurity strategy must support the business objectives. The first step is to know what is important for the organization, the second is to protect it.
- Implementing a cybersecurity management framework will allow us to better manage the processes. Whether ISO 27001, 27110, ENS, the NIST framework, etc. It is a good strategy to choose a standard that defines and relates the different processes.
- The strategy is a consequence of your context. To define a strategy, you must know your reality. Resources are always limited.
- Defined security responsibilities and roles. It is essential to determine who handles what in order to define the different processes to implement for good cybersecurity management.
