Change is hard. Really hard. It requires us to set aside our ego, dedicate time to feeling uncomfortable, and develop new habits. Don't make change harder than it has to be!
Thoughts
When clients ask me how to get cyber secure, they usually expect a list of items and a program to implement those items. Often, I'll request documents, hold interviews, draw up a scope and develop a roadmap, only to find out that "now isn't a good time," or "something else just became a priority." It's not that people don't want to improve their cybersecurity, it's just too damn confusing, and overwhelming!
So here's my number one tip for cybersecurity: start small! Do whatever it takes to make some progress. Like any collective action problem, what you say and how you signal your priorities is as important as the improvements you'll make.
Words
The mistake that most people make is thinking they have to solve everything at once. It's demoralizing, and worse, you are afraid to speak about your successes before you're "finished." The trick is to break goals into small enough tasks that you constantly have something to brag about.
Now, despite having a quick win, it isn't always simple to demonstrate how it translates into lower organizational risk, because cybersecurity is a property of a system. You can't just pick any random cybersecurity task and expect it to make a proportional improvement on its own. There are few cheap and easy thing you can do though.
Often I recommend starting with implementing multi factor authentication, but maybe the first small task is creating a cybersecurity policy. Maybe it's holding that first senior executive meeting to discuss what the risks to your business actually are. It doesn't matter what it is or where you start, only that you communicate one thing to your team:
"This is a priority worthy of consistent effort"
That's it! That's the key to better cybersecurity. In fact, that's the key to better risk management in general. Doesn't sound so scary now, does it?
Actions
Maybe you're onboard at this point, but maybe you're a more practical type, and you just want to know what steps to take. In the spirit of this article, I'm going to keep thing short, and actionable. Here are three small things you can do to prevent catastrophes down the line:
- Commit to accomplishing one goal a week
- Measure your progress!
- Hold yourself accountable
On Monday, state a cybersecurity goal with your senior executive team. On Thursday, measure how much progress was made. On Friday, report up to the executive team and across to your peers what you accomplished or failed to get done.