Change Management: The Overlooked Control Behind Most Security Incidents

Change Management is often an overlooked aspect of cyber security, but its impacts can be just as serious as a ransomware attack.

Change management is often an overlooked aspect of cyber security, but its impacts can be just as serious as a ransomware attack.

Security tends to focus more on external threats to an organisation, such as phishing or ransomware and puts processes and defences to deal with them. Yet something as simple as an unapproved change, misconfigured firewall rule, or even untested software deployment all have the potential to create huge disruption, including compliance failures, unauthorised access and system outages.

That places extra emphasis on having effective change management processes in place. By design, they can assist organisations in reducing operational risk, demonstrating governance compliance, preventing security vulnerabilities from being introduced into the business, and maintaining service availability.

Change Management – what does good look like?

Good change management hinges on the processes it’s made up of and how effective they are. That effectiveness is measured by how consistently they’re used within a business and if the overall structure behind it provides sufficient governance.

So, how do we get there? Take a look at our suggested 8-step change management roadmap below.

1. Change Request

Your starting point.All changes, if they’re significant to business function, should begin with a documented request. A change request form is a great way of ensuring all changes are documented and reviewed. Here’s what should be on it:

  • The change being requested

  • The justification for the request

  • The systems that the change will affect

  • Benefits for the change

  • Implementation dates

  • Roles and responsibilities of individuals included in the change

2. Risk Assess Changes

Before implementation, the potential impact of the change should be considered. Think about whether it expose sensitive data, impact service availability, any impacts to security controls, or whether customer services may be impacted. This stage is particularly important when dealing with changes that are critical to the business.

3. Formal Approval of Changes

Changes should be reviewed and approved by a member of senior leadership. Criticality, business impact, security implications and regulatory requirements should be considered before approval from a member of staff with the appropriate authority.

4. Testing and Validation

One of the most common causes of system/service outages is implementing untested changes in production environments. Testing changes prior to deployment should ensure that the change is effective, existing functionality remains unaffected, security controls continue operating, and recovery processes are established.

5. Rollback Planning

Have a process in place to establish how services will be restored if the implementation fails. This should cover who is responsible for recovery, estimated timescales for recovery, and dependencies. The plan can also help to determine how long an organisation can take to recover from any change-related issues.

6. Communication

Relevant parties should be informed before significant changes are implemented, including IT teams, service or system owners, security teams, third-party suppliers and where necessary, customers.

7. Emergency Changes

Changes that need to be implemented with immediate effect can’t always follow standard approval processes. An emergency change process should allow for immediate implementation but still ensure appropriate authorisation is sought, justification is documented, evidence of the change is captured, and a review is completed after the change is made.

8. Post-change Review

After the implementation is completed, a review should be carried out to ensure the change has lived up to its intended purpose. Consideration of whether objectives have been met, unexpected issues encountered, lessons learned and opportunities for improvement.

Ensuring your processes work

After building your roadmap, the next step is ensuring your processes are fit for purpose. Review the existing process (if any) and ensure they align with your existing governance processes and identify any gaps. Then, we’d advise creating simple templates for:

  • Change requests

  • Risk assessments

  • Approval records

  • Rollback plans

  • Post-change reviews

Beyond that, you can strengthen your processes by:

  • Ensuring approval routes are clear, ensuring higher-risk changes are mentioned.

  • Introducing emergency change controls to ensure prioritisation.

  • Retain auditable records for approvals, testing results, security assessments, communications and review outcomes.

How can we help?

Having a well-defined and structured change management process will ultimately reduce disruption and demonstrate that an organisation can control its environment. For organisations seeking to strengthen cyber resilience, improve audit readiness and support compliance initiatives, reviewing change management processes is often one of the highest-value improvements available. Get in touch with our PureCyber professionals for the help you need.

Next
Next

AI Governance for CISOs: How to Manage Risk Without Blocking Innovation