Cyber Security Toolkit for Boards
Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.
Pages
Page 6 of 27
Identifying the critical assets in your organisation

Introduction
Effective cyber security risk management depends upon your organisation:
- having a good understanding of its technical estate (the various systems, data, services and networks that are used by the organisation)
- being able to identify which are the critical assets upon which your key business objectives depend
The board will therefore need to communicate key objectives (one might be 'providing a good service to customers and clients', for example) in order for the technical experts to focus on protecting the things that ensure these objectives are fulfilled.
Understanding your technical estate is important because:
- it helps to mitigate cyber security risks (for example, if you’re not aware of the entirety of your technical estate during a malware attack, forgotten systems may re-infect the estate when the system is brought back up)
- knowing which systems are connected (their dependencies, who has access, and who manages which component) are all critical to setting good defences and recovering from cyber incidents
- many incidents are the result of vulnerabilities in acquisitions, or in older legacy systems that can be defended against; these are often low-value assets that are overlooked
- by documenting each IT asset and its critical dependencies, IT teams gain greater insight into the security controls needed to meet business, legal and regulatory requirements
This may seem like a daunting task, especially for organisations whose networks and systems have grown organically, but even a basic understanding of your estate will help. Identifying the critical assets can give you a starting point, from which you can identify dependencies.
Note: Some organisations will also need to consider controls on their Operational Technology (OT) systems (which can be complex due to the intricacies of legacy assets, or even be spread over multiple sites).
Essential activities
Work out where you’re starting from
Ensuring your organisation understands its assets (such as including hardware, software, peripheral devices and removeable media) is a precursor to being able to address the resulting risks. Records should include who is responsible for each asset, where it is stored and what it is used for. This can help you identify critical technology assets and where vulnerabilities may exist in your environment. It should also include those belonging to any third parties which your organisation depends (for instance Software as a Service providers or cloud hosted applications) that are crucial for day-to-day operation. Ideally, your inventory should also include a set of reference architectures for all the systems you depend on.
Maintain a comprehensive inventory
Larger organisations with complex estates may want to invest in an IT asset management solution to help you do this, for both physical and virtual assets. Your approach will need to adapt to conditions, for instance company acquisitions and mergers can create additional complexity.
Prioritise mission critical activities
The board should take a holistic approach when considering what is critical to the organisation. For example, the board might know that a specific partner is vital, and that a compromise of their data would be catastrophic. This should be communicated to technical teams, so that they can prioritise protecting these 'crown jewels' (ie the things most valuable to your organisation). They could be valuable because you simply couldn't function without them, or because their compromise would cause reputational damage, or it would incur financial loss. Some examples could be:
- bulk personal data
- intellectual property
- your public-facing website
- industrial control systems
Collaborate with other teams
Identifying critical assets upon which your core objectives depend cannot be done by your technical team alone. It requires strong collaboration between business and technology functions, and a thorough understanding of the assets themselves as well as the core business objectives. Your baseline and understanding of critical assets should be cross referenced by other key strategic plans, such as your business continuity plan, or plans for remediation of legacy systems. For organisations with cyber-physical estates, it will require the collaboration of operational technology teams. It should not just be an inventory ‘by your IT team of those assets under their control’, but should span the entire organisation, and your wider supply chain where necessary.
Indicators of success
If sample checks on the accuracy of the asset inventory are carried out monthly and MI is shared with the board, any gaps will be identified. Independent audits should also take place to ensure the data is accurate and up to date.
This is essential in mitigating potential risks that any undocumented systems might pose.
This information is essential to ensure that measures are in place to protect those assets from being compromised. Some information assets will have to be protected in line with regulations and laws and the board needs to be aware of these and have assurance that the systems and processes that the regulations may require are being met.
If your critical assets can each be cross referenced to a clearly stated core business objective, this is a sign that your organisation is taking the right approach. For example, if a promise to customers about their privacy is a priority then you might identify what could jeopardise this promise (eg the loss of their credit card details) and what technical assets are required to secure those details (ie an access management system)? This would allow you to prioritise defending these assets when implementing cyber security measures.


