Home > Blog > CISO Strategy > Security Readiness Has to Be Maintained

By Michael Henry, CEO, Accelerynt

Security readiness changes when the business changes, which is to say constantly. An acquisition adds another environment. A reorganization moves decision authority. A configuration change alters what a control covers. This quarter’s slides may look similar to the ones from the last board meeting, but the conditions underneath them have most definitely changed.

We’ve seen escalation chains that no longer match the organization and containment playbooks that haven’t kept up with an acquisition. We’ve also seen automation paused because the team no longer trusted it.

In one engagement, a new IT Operations partner put automated work back in human hands. Their team was measured on tickets closed, and automation left them fewer tickets to count. We had solved the problem. Apparently, that was a problem.

Readiness can slip through neglect or a deliberate change in how the work gets done. During an incident, the response team has to wade through this drift before it can act. Someone has to find the current owner, establish whether the procedure still applies, or check what an automated action will affect. The organization is replaying decisions it thought were already settled.

Separate Judgment From Avoidable Delay

Human judgment absolutely belongs in incident response. Shutting down a critical service can have consequences that require a business decision. An unfamiliar attack may warrant investigation before containment. Experienced team members earn their stripes by understanding those tradeoffs.

Searching for the person authorized to make that decision is wasted effort and causes delay. The response plan still lists an owner. Unfortunately, that person now works somewhere else.

NIST’s updated incident-response guidance makes room for both preparation and judgment. It calls for defined authority and tested procedures while recognizing leadership’s role in high-impact decisions. Readiness includes knowing which decisions can be settled beforehand and which require someone to assess the situation. NIST SP 800-61r3

The practical goal is to give your team fewer internal uncertainties to resolve while they are investigating an external threat.

Check What the Plan Depends On

An incident response plan depends on technical conditions that often change without announcing themselves. A Conditional Access policy may acquire an exclusion. A detection rule may be disabled. An account may retain privileges after its owner changes roles.

Checking the document will not reveal those changes. The team needs evidence from the environment itself, compared with the state it approved.

That is the part of the problem we address with the Accelerynt Security Platform. ASP identifies configuration gaps and tracks changes against approved baselines. Findings identify the affected accounts or policies, and their history shows whether a gap remains open or returns after remediation. The team has something specific to investigate. ASP capabilities

Organizational readiness needs a different test. A configuration assessment cannot tell you whether the escalation reaches the right person or whether that person can authorize action. An exercise can expose those gaps. CISA recommends involving senior leadership and board members in response-plan exercises, making the decisions part of the test. CISA guidance for corporate leaders

Both checks matter. A current procedure can depend on a control that has drifted. A correctly configured control can feed a response process nobody has practiced.

What Leadership Should Ask

Boards and CEOs should expect evidence that readiness is being maintained as the organization changes. A useful security update explains what changed, which assumptions were checked, and what remains unresolved.

After an acquisition, that might mean identifying the inherited environments and confirming who has authority to contain an incident in each one. After a response exercise, it might mean showing where decisions stalled and whether the revised process has been retested.  Management owns the corrections. The board should be able to understand the remaining exposure and any decision that requires its attention.

At the next security review, pick one material change since the last assessment. Find out which controls and response arrangements it affected, and what evidence shows they still work.

← Previous

Integrating Checkmarx One with Microsoft Sentinel: Consolidating Application Security Visibility