AI News Feed
Market watch
Cybersecurity

FireMon exec: Security policy environment should be treated as critical infrastructure

A FireMon executive argues in a TechRadar piece that security policy environments must be governed like critical infrastructure, warning that accumulated rules often fail regulatory resilience tests.

The article by the senior vice president for international business at FireMon argues that in banking and utilities, regulators classify certain systems as essential, carrying the highest governance obligations such as continuous monitoring, validated change control and demonstrable resilience. The policy environment determines which systems can reach each other and which connections are blocked, so when that environment fails, the critical services it governs fail with it.

A misconfigured segmentation rule during a cloud migration can sever a payment service from its settlement platform, the article says, while a temporary rule granting broad access from a development subnet into production can remain in place months after go-live because no one owns the removal.

Despite this, many regulated organizations manage policy environments as operational tasks rather than as critical infrastructure. Rules are added through change requests, the resulting state is rarely compared with what was intended, and ownership disperses as leaders change roles. The article describes this as “infrastructure-grade consequence with housekeeping-grade governance,” noting that a CISO who would never accept a payment platform running without continuous monitoring may accept the absence of both in the policy environment determining whether that platform is reachable.

The piece points to UK regulatory expectations that support the same conclusion. The Financial Conduct Authority’s operational resilience regime requires firms to identify important business services and demonstrate that supporting infrastructure remains within defined impact tolerances. Ofgem assesses essential-service operators against the National Cyber Security Centre’s Cyber Assessment Framework with a focus on sustained achievement of security outcomes. The planned Cyber Security and Resilience Bill, expected to become law later this year, would extend similar obligations to data centers, managed service providers and critical suppliers.

Those frameworks, the article notes, are not prescriptive about which rules organizations should have. They require proof that what the policy environment permits is what was intended, on an ongoing basis, rather than evidence reconstructed for each assessment.

Most policy environments were never built to meet such a standard, the FireMon executive argues. Policy tends to accumulate as a by-product of project delivery: every project adds rules and almost none removes them. Over time, the policy surface grows larger than the group of people who understand it, and the estate can be operated but not explained. That was sustainable under earlier control-based audit regimes that asked whether controls existed rather than whether they were effective, but is no longer enough.