Perspectives: Managing cyber risk during times of organizational change
Cyber incidents often surface during periods of change. An acquisition closes, a new vendor is onboarded, systems are connected for the first time. During those moments, security controls, business processes and accountability do not always line up.
That creates opportunities for attackers. It can also make an already difficult situation even harder to manage when an incident occurs.
Many organizations invest heavily in security controls. Yet some of the most significant cyber exposures arise when responsibilities are unclear, decisions are made in silos, or no one has a complete view of how systems, vendors and teams connect.
For risk managers, the challenge is recognizing those gaps before they turn into larger problems.
Breakdown begins
Organizations today rely on a growing network of third parties — vendors host data, support business applications, manage infrastructure and connect directly to critical systems. That connectivity improves efficiency, but it also creates dependencies that may not become apparent until something goes wrong.
Consider an acquisition. One company may have mature cybersecurity practices while the other follows a very different approach. Bringing those environments together takes time and during the transition, ownership may be unclear, controls may not be applied consistently and visibility may be limited.
The same dynamic appears when organizations onboard vendors, deploy new technology, or expand operations. Access expands, processes evolve and additional stakeholders become involved. Each decision may seem reasonable on its own, but problems often emerge when no one is looking at how those decisions interact across the broader environment.
Event consequences
Cyber incidents rarely stay confined to the technology itself; business operations can be impacted as well. That is especially true when organizations are integrating systems, onboarding vendors, or changing business processes. During those transitions, responsibilities and dependencies may still be evolving, making incidents harder to contain.
A ransomware attack can disrupt operations, increase regulatory obligations, affect customers and create contractual issues. A data breach may lead to legal costs, notification requirements, reputational damage and professional liability concerns. A third-party incident can interrupt operations even when an organization’s own systems are unaffected.
The response rarely falls on IT alone. Security teams investigate the event, legal teams assess obligations, communications teams prepare messaging, business leaders work to keep operations moving, and risk and insurance professionals evaluate financial impacts and coverage considerations.
Preparation is critical. Organizations that respond most effectively have already established roles, responsibilities, and decision-making authority before an incident occurs.
Build the response
When a cyber event occurs, time is limited and organizations do not have the luxury of sorting out responsibilities in the middle of a crisis.
That challenge often becomes more complex after an acquisition, technology implementation, or organizational restructuring. Decision-making authority may shift, reporting lines may change and teams may be working from different playbooks.
In a crisis, people should not be debating who makes key decisions, who needs to be informed, or when outside resources should be brought in.
A strong incident response plan should answer several basic questions:
- Who has authority to make key decisions?
- When should issues be escalated?
- What role does each team play?
- Which outside partners need to be contacted?
- How will information be communicated during an incident?
Having a plan is important, but it is not enough on its own. Tabletop exercises often reveal communication gaps, unclear responsibilities and integration issues that may not be apparent on paper. They also give teams a chance to collaborate before a real event occurs.
Recovery matters
Most cybersecurity discussions focus on prevention, but recovery deserves equal attention.
When systems go down, the ability to recover data and restore operations often determines how disruptive an incident becomes. Backups, recovery procedures and business continuity plans all play a role, but they need to be tested regularly.
It is important to understand what can be recovered, how long recovery will take and whether those timelines align with the needs of the business.
Restoring technology is only part of the recovery process. Customer commitments still need to be met, employees still need to do their jobs and vendors still need to deliver. Those realities often determine how quickly normal operations resume.
When systems, vendors, or business processes change, recovery plans need to change with them.
Third parties
Third-party risk remains one of the most challenging aspects of cyber risk management.
Acquisitions, vendor onboarding and new technology deployments often expand access to systems and data before every risk is fully understood. Those transitions can introduce new dependencies and create gaps in visibility and oversight.
Most organizations conduct due diligence before entering a vendor relationship. That is an important first step, but it should not be the last one.
Organizations should understand:
- What systems a vendor can access
- What data the vendor maintains
- How the vendor would respond to a cyber incident
- Whether the vendor relies on additional service providers
Risk does not stop with direct relationships. A problem affecting one provider can quickly affect dozens or hundreds of organizations.
Vendor reviews should not stop once a contract is signed. As relationships evolve, vendor access, security practices and incident response expectations should be revisited.
Match reality
Frameworks such as the National Institute of Standards and Technology’s Cybersecurity Framework and the Center for Internet Security’s Controls provide valuable guidance for managing cybersecurity risk. Frameworks, however, are only part of the picture.
Most policies make sense when they are written, but the challenge is making sure they still reflect how the business operates months or years later.
Employees adopt new tools, business units change processes and vendors introduce new technology. Over time, day-to-day operations can drift away from what policies were originally designed to address, so regular reviews help close that gap. Controls should remain aligned with operations and responsibilities should remain clearly defined.
Keeping policies current takes ongoing attention and clear accountability. Cybersecurity and risk reviews should be part of major decisions, including acquisitions, vendor onboarding and system implementations.
The risk manager’s role
As organizations grow, add vendors and connect more systems, cyber risk becomes harder to manage.
Risk managers are often in a position to see across the organization. While they may not be cyber experts, they can often help connect in-house security or a managed security service provider, legal, operations, compliance and insurance teams before small gaps become larger problems.
Strengthening incident response plans, testing recovery capabilities, evaluating third-party relationships and keeping policies aligned with day-to-day operations can go a long way toward reducing both cyber and liability exposures.
Technology will continue to evolve, and organizations will continue to change along with it. Acquisitions will happen, new vendors will be brought in and systems will be connected. Those moments create opportunity, but they can also introduce risk. Understanding key dependencies, clarifying ownership and preparing teams to respond can make those transitions easier to manage. They will also often determine how well an organization responds when it is put to the test.
Aaron Belair is president, technology, North America, at Intact Insurance Specialty Solutions. He can be reached at [email protected].