AIS Logo
← Back to Library
Adopt Agile Cybersecurity Policymaking to Counter Emerging Digital Risks

Adopt Agile Cybersecurity Policymaking to Counter Emerging Digital Risks

Masoud Afshari-Mofrad, Alireza Amrollahi, Babak Abedin
This study investigates the need for flexibility and speed in creating and updating cybersecurity rules within organizations. Through in-depth interviews with cybersecurity professionals, the research identifies key areas of digital risk and provides practical recommendations for businesses to develop more agile and adaptive security policies.

Problem In the face of rapidly evolving cyber threats, many organizations rely on static, outdated cybersecurity policies that are only updated after a security breach occurs. This reactive approach leaves them vulnerable to new attack methods, risks from new technologies, and threats from business partners, creating a significant security gap.

Outcome - Update cybersecurity policies to address risks from outdated legacy systems by implementing modern digital asset and vulnerability management.
- Adapt policies to address emerging technologies like AI by enhancing technology scouting and establishing a resilient cyber risk management framework.
- Strengthen policies for third-party vendors by conducting agile risk assessments and regularly reviewing security controls in contracts.
- Build flexible policies for disruptive external events (like pandemics or geopolitical tensions) through continuous employee training and robust business continuity plans.
agile cybersecurity, cybersecurity policymaking, digital risk, adaptive security, risk management, third-party risk, legacy systems