Blog Posts Process Analysis

6 Principles for Cyber Risk Scores — and Why We Need Them

Blog: Enterprise Decision Management Blog

Cybersecurity risk score scale

The use of scores that rate a firm’s cybersecurity risk — such as the FICO® Enterprise Security Score — is picking up momentum. In an effort to ensure that these scores consistently add value, and to ensure that they help rather than harm businesses, a group of firms recently convened to develop industry standards for cybersecurity ratings. FICO joined this group, along with several Fortune 500 companies and a number of the country’s biggest banks, and I am proud of the principles we developed.

By creating these principles, we sought to:

Why were principles needed? One reason is that there is a potential for cybersecurity ratings to be used in ways that create damage rather than value.

We’ve seen a bit of this in the market already, where firms’ scores were publicly disclosed or compared to advance the marketing goals of the provider. This certainly seems like a bad idea, and one of the key goals of the principles is to ensure that the scores are distributed and used for the right purposes. The right purposes are those that advance actual security and encourage improvement in commercial infrastructure, both within individual firms, and collectively.

Another reason the principles are important is that they encourage quality in the ratings, and an understanding of quality by the users of the ratings. The ability to know which ratings are empirically derived and which are based on judgmental, subjective criteria is critical to knowing what you’re getting, and how you can put it to most effective use. Judgmental rankings may certainly have utility for specific use cases, but they should not pose as empirical scores derived from supervised modeling techniques that are statistically aligned with real, measured outcomes.

As more entities rely on these scores and ratings, their governing bodies and relevant regulatory agencies will care more about how these tools are used to drive decisions to mitigate risk. Establishing appropriate levels of transparency and responsible practices for model governance are equally important. These standards and practices are very well-developed in banking, for instance, but are not yet well understood across other vertical markets. Whether or not these kinds of decision management governance practices are part of the regulatory backdrop for a given user of the scores, establishing them as a best practice now will serve everyone well.

6 Principles for Security Ratings

Here are the principles we adopted as an industry group, and which the US Chamber of Commerce has now published:

These principles are no stranger to FICO — in fact, we follow the same principles with our FICO® Score, the industry standard for consumer credit risk assessment, as well as other analytics-forward scoring systems and software solutions that drive decisions for thousands of enterprises in banking, insurance, government, retail, telecommunications, logistics and government. They’re the principles that a score needs to follow if it’s going to serve as an industry standard serving all players in the ecosystem — not just a point solution serving its buyers.

Any business that buys the FICO Enterprise Security Score to rate its own operation, or its vendors and partners, can have full confidence that we stand by these principles. We see a big future for cybersecurity scores, and these industry-developed principles are an important step forward.

The post 6 Principles for Cyber Risk Scores — and Why We Need Them appeared first on FICO.

Leave a Comment

Get the BPI Web Feed

Using the HTML code below, you can display this Business Process Incubator page content with the current filter and sorting inside your web site for FREE.

Copy/Paste this code in your website html code:

<iframe src="https://www.businessprocessincubator.com/content/6-principles-for-cyber-risk-scores-and-why-we-need-them/?feed=html" frameborder="0" scrolling="auto" width="100%" height="700">

Customizing your BPI Web Feed

You can click on the Get the BPI Web Feed link on any of our page to create the best possible feed for your site. Here are a few tips to customize your BPI Web Feed.

Customizing the Content Filter
On any page, you can add filter criteria using the MORE FILTERS interface:

Customizing the Content Filter

Customizing the Content Sorting
Clicking on the sorting options will also change the way your BPI Web Feed will be ordered on your site:

Get the BPI Web Feed

Some integration examples

BPMN.org

XPDL.org

×