Cyber security insurance

profileBfh
BananAlqethami-riskprofilefinal-WithFeedback.docx

Fall 2022 Assignment 2

Cyber Risk Profile Worksheet

Your Name: Nestle (Thanks for picking a specific company. This was not part of the assignment requirements

Your Company Type: Food processing company

Date:

Question

NIST CSF Alignment

Use this area to provide a brief response

Reviewer Comments (LEAVE BLANK)

1. Does your organization know what assets it has and should be protecting? For example, do they maintain software, hardware & data inventory?

Identify – what is the organizations cyber risk exposure?

Nestlé's data inventory is a very valuable financial asset, and it is essential that this asset be protected under intellectual property laws. Privacy by design, processing for stated goals, lawful, fair, and visible processing, properly handling personal data, rights of persons and personal data security are some of the tenets around which Nestlé’s privacy policies are built.

Your organization does not conduct an inventory or IT or Software. See Pg. 1 of the Organization Description & Profile document.

1. Based on the organization type, what are some likely threat actors your organization should be concerned about?

Identify – what is the organizations cyber risk exposure?

Following are some of the threats actors for nestle;

· Retail giants such as Tesco & Walmart.

· Water scarcity

· Government Regulations

· Haunting Dark Past

I was looking for threat actors that could pose a threat to your organization. This could be external financially motivated criminals, hackers, or others we covered during lecture.

1. Your organization uses a variety of Applications to operate. In your opinion which one is the most critical and why?

Identify – what is the organizations cyber risk exposure?

Nestle uses SAP as one of its applications. The widespread use of enterprise resource planning (ERP) systems like Systems Applications and Products (SAP) may be attributed to their ability to improve communication and coordination across various divisions within an organization. It took me a while to get to this conclusion, but I think this software is crucial because of how long it takes to build and how complicated it is.

1. Do you believe your organization is doing everything it should to proactively identify threats and vulnerabilities? What is one possible area of improvement.

Identify – what is the organizations cyber risk exposure?

Nestlé took a proactive approach to worldwide phishing visibility. It started checking syntax and structure in new email topics. We don't utilize employee names or email content. This would solve the issue of workers doing their own investigative work, but it would create a "needle in a haystack" dilemma for the team.

Nestlé chose to construct a new Azure solution to improve its investigation process. PhishScreener leverages Microsoft Azure DevOps and Azure Machine Learning to score and flag incoming emails and route only questionable instances for further examination.

I am not sure where you are finding some of this information, it was not in the documents I provided.

Please see Assessments & Testing section of the Organization Description & Profile document.

1. Your organization does not have a 3rd party risk management program in place. How could this increase their cyber risk?

Identify – what is the organizations cyber risk exposure?

There would have been catastrophic cyber security issues for Nestle if there hadn't been a risk management program in place. A hacker could attempt to obtain unauthorized access to data kept on a computer or network. The goal might be anything from embarrassing or harming the victim to stealing confidential information.

A 3rd party risk management program helps an organization identify possible risk their 3rd party providers introduce to the organization. How would NOT having a program in place to assess the risk of 3rd party providers (IT providers, Data Management providers, Suppliers, etc.) increase the risk of your organization?

1. Do you believe your organization understands the potential impacts of a cybersecurity event? If not, please provide a quick recommendation of where they may be able to improve.

Identify – what is the organizations cyber risk exposure?

Nestle is under ongoing cyber-attacks globally, and fraudulent emails are widespread. After building a security system with many wrongful convictions, they moved to Microsoft's Azure platform and machine learning.

See question 4 under the Exposures section of the Description & Profile document.

1. Are there any laws, regulations or contract requirements your organization needs to comply with?

Identify – what is the organizations cyber risk exposure?

Laws bind Nestlé and its workers. Never compromise legal compliance. Employees must also follow internal norms and regulations. These company-specific policies may exceed legal requirements.

See the Organization section of the Description & Profile page. See the sample cyber insurance application document, Cybersecurity & Media controls, Question 14.

1. Identify one possible area of improvement to strengthen Cybersecurity Governance for your organization (ex. Leadership involvement, strategy, investment, etc.)

Identify – what is the organizations cyber risk exposure?

Nestlé uses Azure Machine Learning to avoid cyber-attacks. They're aware of cyberattack hazards and are formulating a strategy.

Microsoft explains its Nestlé partnership. The two businesses built PhishScreener, which Microsft believes can detect phishing before an employee opens a bad link. Nestlé decreased false positives, speed up detection, and enhanced phishing coverage.

I was looking for ways your organization can add new policies and procedures, or improve ways to identify risks and exposures.

1. Does your organization have any Identity or Access Management control gaps that could be an issue during the cyber insurance process?

Protect – How is your organization defending against threat actors and vulnerability exploits?

Nothing about Nestlé's identity or management controls presents a risk throughout the cyber insurance procedure. There is zero tolerance for violations of the Nestlé Corporate Business Principles, thus the company works tirelessly to enhance its communications, procedures, and training to assure compliance.

I gave you the answer to this question. You could have copied and pasted my example here.

1. Privilege Access Management is starting to be a major area of focus cyber insurance carriers. Do you believe your organization has PAM controls in place? Briefly explain.

Protect – How is your organization defending against threat actors and vulnerability exploits?

Yes, Nestle has Privilege Access Management Controls in place. Every level of the employee has different accounts to access portal. The system is throughout fully centralized and controlled.

Your organization does not have Privilege Access Management in place. See the Protection section of the Description & Profile document.

1. Is data adequately secured in transit, at rest and in the cloud? Please identify possible gaps or areas of improvement.

Protect – How is your organization defending against threat actors and vulnerability exploits?

In both its transit and storage states, data is vulnerable and must be safeguarded. There are a number of options for securing information while it is in motion or at rest. Both in transit and at rest, data is safer when encrypted. Nestle uses the cloud for data storage. To further its business, Nestlé is embracing cloud computing in order to provide services that would be impossible to implement on-premises. Computing in the cloud is flexible, productive, and highly advanced. Numerous recent possibilities can be accessed via machine learning and statistical platforms. Nestlé has assembled a team of highly skilled data and analytics experts at a dedicated facility.

Following are the area of improvements for nestle;

· Optimize storage environment

· Coveraged infrastructure

Look at the documents I provided. Does your organization Encrypt data? If not, any place data is not encrypted would be a gap.

1. Does your organization do anything to train employees and reduce the likelihood and impact of Phishing and Social Engineering? Please list current controls and any recommended improvements.

Protect – How is your organization defending against threat actors and vulnerability exploits?

Nestle values collaboration with other training organizations. The most effective way to strike a healthy middle ground is to participate in training programs outside of Nestlé. These programs provide participants with the opportunity to learn about cutting-edge developments in management theory and to analyze practices and situations that are outside of their usual scope of work. Following are some controls being implemented by nestle;

· Confidentiality agreement between third party employee

· Cloud servers

· Usage of PAM.

Nestle's crisis illustrates the need for one of four approaches to handling similar situations. Negation, coercion, cooperation, and assistance are some of these strategies.

I was looking for evidence that your organization provides cybersecurity awareness training to their employees. See the sample cyber insurance application under the Cybersecurity & Media Controls section.

1. List some control gaps you identified in the Organization Profile or Cyber Insurance Application that increase your organizations exposure to cyber risk.

Protect – How is your organization defending against threat actors and vulnerability exploits?

According to Nestlé, the incident began in February when the corporation was conducting a test of a business-to-business function inside its own internal network. It seems that the information has been freely accessible online for weeks prior to Anonymous allegation of a cyber assault. The corporation also rebutted Anonymous' claims that passwords and sensitive client information were exposed in the hack, noting that just basic contact information was exposed.

This is not information that was included in the documents I provided. For this one you can pick anything you identified as a potential control gap in either document I provided.

1. What tools, technologies or services does your organization use to detect possible cybersecurity events?

Detect/Respond – How does your organization detect incidents and respond?

Following are some tools I recommend to nestle for detection of cyber security event;

· Wireshark

· Nikto

This information is not in the documentation I provided. For this I was looking for any technology or services that help your organization detect cybersecurity events (Security Operations Center, Vulnerability scanning, Network & Log monitoring, etc.)

1. How could they improve their detection capabilities?

Detect/Respond – How does your organization detect incidents and respond?

· Nestle should conduct risk management assessment

· Nestle should implement automate threat detection

Your organization does conduct risk assessments. Please find examples using the documentation I provided.

1. Do you believe your organization has the documentation and plans in place to direct incident response activities in the event of a network security incident or data breach?

Detect/Respond – How does your organization detect incidents and respond?

In the case of a network security incident or data breach, yes, there is documentation and protocols in place to lead incident response efforts. Since it is one of the world's biggest organizations, it can handle any kind of crisis, cyber or otherwise.

Does your organization have an incident response plan in place? Please look at the sample cyber insurance application to find this answer.

1. Do you believe your organization would be prepared to restore and recover after a cybersecurity event? Please explain your response.

Recover – How prepared is your organization to recover and get back to normal operations after a cyber event?

In the past, Nestlé has had a cyber security breach, but the company has since made a full recovery. Employees get comprehensive training from third-party providers. They keep a close eye on the state of the IT world and make any necessary adjustments to make sure they're safe against cyberattacks.

See the last question in the Exposures section of the Description & Profile document to answer this question.

1. How could a cybersecurity or data privacy event impact the reputation of your organization?

Recover – How prepared is your organization to recover and get back to normal operations after a cyber event?

There are several ways in which a cyber security incident might affect Nestle. If Nestle were to suffer a cyberattack, it would not only face increased expenses due to disruptions in operations and new business procedures, but also face reputational damage. Reputational harm causes the greatest financial damages. Nestle might have compromised its customers' personal information, and the company has to spend millions to resolve lawsuits.

This answer is correct, but remember, this is not for Nestle but a hypothetical manufacturing company.

6

Assignment 2 – Cyber Risk Profile Worksheet