World-class cyber risk advisory and analytics delivered locally

dots

Astaara is an integrated risk management advisory business incorporating cyber risk advisory and analytics.

Astaara has an experienced team and an established set of products which help our clients understand their cyber posture against a number of standards and frameworks (CE+, NIST, CAF, CIS etc). We support our clients on their journey through compliance and ultimately to effective and efficient cyber risk management.

The regulatory burden of cyber security on firms is growing

The Guernsey Financial Services Commission issued specific guidance on 5th February 2021: Guernsey Financial Services Commission Cyber Security Rules, 2021

The rules came into operation in February, however transitional arrangements allow firms to implement changes to their internal controls to ensure compliance by 9 August 2021. Rules and guidance can be found here.

Under the new rules, all licensees must:

  • Be able to provide evidence to the GFSC, on request, that these rules have been considered and implemented in accordance with the size, nature and complexity of the licensee’s business
  • Have in place appropriate policies, procedures and controls to mitigate the risk posed by cyber security events
  • Ensure that any policies, procedures and controls adopted reflect these rules and take into consideration any guidance issued by the Commission
  • Adopt the framework for risk management around the NIST model of Identify, Protect, Detect, Respond and Recover

Cyber security is not just an IT problem; information security is different from information technology. It is a systemic risk potentially affecting the whole business.

Failure to act will be expensive. Being able to evidence you take cyber seriously is your best defence.

Contact us for a no obligation discussion about your requirements.

Robert Dorey
CEO

Where Astaara comes in...

Astaara is experienced in providing risk management solutions for businesses of any size. You want a specialist where specialisation is needed; you do not want to be baffled with IT and cyber jargon. We speak your language.

We have two services for the financial services industry.

FINANCIAL SERVICES
1. Risk Management

CyberStaart will include:

  • An initial review of your cyber posture
  • A review of your cyber insurances
  • An assessment of your policies and procedures
  • A vulnerability assessment of your website and other web-facing assets
  • A review of your training materials

Our Benchmarking offering includes all of the above plus:

  • A gap analysis of your cyber posture against the GFSC requirements
  • A route-map of priority actions for compliance

Cyber Essentials Plus, a government scheme widely promoted within the industry is a good start. But the GFSC requirements go further: you will need to demonstrate the measures you have adopted across all 5 of the cyber risk management themes: identify, protect, detect, respond and recover.

FINANCIAL SERVICES
2. Virtual Chief Information Security Officer (VCISO)

It is good practice for organisations to nominate someone at board level to be responsible for managing the company’s cyber security risks. In small and medium sized businesses, this responsibility can be found in a number of portfolios, including finance, legal, compliance, and IT.

A Chief Information Security Officer is not the same as Head of IT. It is a specialist role that impacts all areas of the business. The CISO should be independent of IT, providing assurance to the board that IT is doing what is necessary to identify and manage technology risk. Giving the role to the individual in charge of IT usually creates a conflict of interest.

In most cases, individuals with CISO responsibilities who are not in the IT function will not have the right experience or background to perform the role effectively. They will rely on the IT function and therefore be conflicted. This may prevent the CISO effectively discharging their function as the independent voice of risk management at board level.

A CISO is a key element of modern Enterprise Risk Management (ERM). Through our VCISO service, Astaara can support your CISO at a fraction of the cost of employing an additional FTE. We can help them prepare for board meetings pertinent to cyber, help them identify compliance gaps, and generate the evidence that you are complying with the new regulations. Our VCISO service also gives you access to multiple points of expertise, depending on your needs.

Key Contacts
  • Robert Dorey
    CEO
  • William Egerton
    Chief Cyber Officer
  • Phil Ponsford
    Deputy Chief Cyber Officer

Office Address

4th floor, 2 Cornet Street, St. Peter Port, Guernsey GY1 1BZ

enquiries@astaara.gg

Oops! We could not locate your form.