
When assessing the importance of an information security program for an organization, it is imperative to consider more than just the organization's internal health. Digital technology is used by most businesses today to reach out to the public and cultivate a positive image. Websites and mobile applications are two of the most common intersections between business technology and the external world.
As part of planning an information security program, organizations should conduct a PESTLE Analysis to identify external factors that could affect company cybersecurity or be influenced by it. A PESTLE Analysis is a strategic business framework used to evaluate major external factors affecting an organization: Political, Economic, Social, Technological, Legal, and Environmental. These are not internal business processes that can be directly changed or shaped by senior management; rather, they are external forces that impact every organization and must be navigated accordingly.
Organizations generally produce PESTLE Analyses for a variety of business topics, but for the purposes of this documentation, the analysis will focus on factors as they relate to cybersecurity objectives.
• Political: Changes in political leadership at the state and federal levels can affect the threat landscape and security posture of organizations within a given geographic region. Some political leaders may make cybersecurity a high priority and provide resources such as national threat intelligence, funding initiatives, and updated security standards for businesses. Conversely, other leaders may reduce funding for cybersecurity programs and institutions. Political activities can also make nations more vulnerable to attacks by nation-state actors, creating a trickle-down effect in which these threat actors pivot toward attacking businesses and supply chains.
• Economic: One of the most common reasons for inadequate cybersecurity within businesses is cost. Therefore, monitoring economic changes that specifically impact the technology sector can be extremely useful. For example, the recent rise in AI data center construction has increased demand for computing resources and hardware. Likewise, future disruptions involving Taiwanese sovereignty could significantly increase the cost of electronic devices and components. Organizations should closely monitor economic fluctuations alongside political developments to better understand how accessible new cybersecurity technologies and services will be.
• Social: The social landscape can change rapidly or gradually depending on the culture and political environment of an organization's location. One of the most relevant social factors involving technology is changing attitudes toward privacy and data collection. Organizations that make heavy use of public-facing platforms should closely monitor public sentiment regarding various platform features and practices. Other social trends can create new demands on how IT assets are used by employees. For example, since the COVID-19 pandemic, remote work has become a widespread trend, affecting how business networks are designed and managed. Changing attitudes toward workplace flexibility have also influenced the adoption of practices such as Bring Your Own Device (BYOD) policies, which require their own set of cybersecurity controls.
• Technological: Since cybersecurity is inherently technology-focused, organizations should closely monitor major trends in the technology landscape. Artificial intelligence serves as a prime example. As generative AI continues to grow in sophistication, adversaries have improved the quality and efficiency of their tactics, techniques, and procedures (TTPs) through its use. Another technological trend to monitor is quantum computing, as future advances in the field are expected to render some currently secure cryptographic algorithms ineffective. Of all the PESTLE categories, technological factors are arguably the most relevant to cybersecurity.
• Legal: New laws and regulations governing data, privacy, and technology are introduced every year, many of which directly affect businesses. These requirements may exist at the federal, state, or local level. Some legislation can fundamentally change how organizations operate. For example, the implementation of the GDPR in the European Union required many organizations to significantly alter how they collect, store, and process customer data. Every organization should remain aware of new legal requirements and assess whether compliance obligations apply.
• Environmental: While environmental factors may initially seem less relevant to cybersecurity, they can have a significant impact on an organization's operations and resilience. Depending on geographic location, facilities may be vulnerable to a variety of natural disasters. Management should assess the likelihood and potential impact of these events and incorporate them into cybersecurity risk assessments, business continuity planning, and disaster recovery efforts. Other environmental considerations include regulations governing the disposal of electronic equipment, as well as the impact of geography on internet access, connectivity, and infrastructure reliability.
A PESTLE Analysis makes the development of future components of the information security framework easier by providing a more holistic view of the organization's operating environment. Its findings can help create threat scenarios for risk assessments and influence incident response, disaster recovery, and business continuity planning. Organizations should conduct PESTLE Analyses on a regular basis to stay informed about emerging trends and external developments. At a minimum, an analysis should be conducted annually. Data for the analysis can be gathered from a variety of sources, with particular attention given to news outlets, social media, industry newsletters, regulatory announcements, and upcoming political elections.
