Chris Garrett argues that registered providers should give cyber security governance the priority the risks warrant
The increase in cyberattacks across the social housing sector is giving housing providers plenty to reflect on, particularly in light of new regulatory obligations requiring them to hold more data than ever before, including, perhaps most significantly, about their tenants.
The inevitable consequence of holding more data is that housing providers will be bigger targets for cyberattacks. As a result, providers need to ensure their cyber security is up to scratch to protect themselves against this increased risk exposure.
Part of this is ensuring that cyber security governance is given the priority the risks warrant.
It is essential that housing providers have robust systems and processes in place to mitigate the evolving threats and risks of cyberattacks.
A provider’s first line of defence is its technical controls. These should be kept up to date, and maintained and operated by an appropriately resourced and expert information-security function.
This function should be alert and responsive to the ever-changing cyber-threat landscape.
Staff training is also very important, so housing providers should ensure they have accessible policies and procedures, such as incident response plans and communication strategies, that are understood, followed and enforced across the organisation.
Consideration should also be given to where third parties, such as agents, contractors and suppliers, have been given access to data.
Over the past few years, there has been a significant increase in cyber security attacks resulting from vulnerabilities within the supply chain, which can have expensive and long-lasting implications for those affected.
Effective governance structures are a key part of this.
It is essential that boards have access to relevant expertise. This can be on the board itself, as part of the executive, or on a separate IT steering committee, with a clear chain of accountability and oversight in relation to who is managing data security and how they report back to the board.
Cyber security governance – how an organisation controls and directs its approach to cyber security – is an issue that the leaders of all organisations should have grappled with already.
Effective cyber security governance will assist the coordination of the activities of an organisation. At the other end of the spectrum, when implemented poorly, the result will be ineffective and delay cyber-security risk decisions being taken.
From a legal perspective, effective cyber security governance assists an organisation in ensuring it complies with is obligations under data protection legislation to implement adequate technical and organisational measures to keep personal data secure.
It also ensures it complies with contractual and other legal obligations to protect confidential information.
Security decision-making can happen at all levels. To achieve this, an organisation’s senior leadership should use security governance. Guidance from the National Cyber Security Centre offers useful advice on what good cyber security governance looks like. It includes:
Part of any organisation’s compliance plans should be the document which you turn to when things go wrong, often referred to as the incident response plan.
This will ensure that effective and consistent decisions are taken at a time which may be challenging for all involved.
While the nature of a cyber security breach cannot necessarily be predicted, the framework for how an organisation will respond, who will be involved in decision-making and who has authority to take action, can (and should) be thought through in advance.
Playing out hypothetical data-breach scenarios in advance can provide confidence that these plans are workable, or identify areas where governance is unclear and needs to be addressed.
Chris Garrett is a partner at Winckworth Sherwood
New to Social Housing? Click here to register and sign up to our comment newsletter
The comment newsletter brings you a fortnightly selection of specialist opinion, guidance, and political and economic commentary, from a unique range of leading experts.
Already have an account? Click here to manage your newsletters.
RELATED