
As business and technology become increasingly intertwined, organizations are being forced to rethink their view of digital security. Once overlooked or seen as just an afterthought, today they are a business imperative. As a result, organizations across industries are rushing to improve their security posture. The Chief Information Security Officer (CISO) is at the center of this transformation, leading the wave of proactive and forward-looking cybersecurity change while enabling her security-first innovation.
The latest Information Security Maturity Report 2022, published by ClubCISO, examines the hopes, challenges, opportunities and frustrations of information security leaders.
culture
Over the years, broader cybersecurity awareness has grown, and today’s executives and stakeholders see the value of instilling a security-first attitude at all levels. There has also been a noticeable positive change in security culture as organizations pay close attention to it. More than 65% of his CISOs surveyed this year report that their organization’s security culture is on track or on par with best practices. Leadership endorsements and simulated phishing have proven to be the most beneficial exercises for fostering this proactive security culture. Additionally, encourage employees to report errors such as clicking on malicious links Our “proactive (report) no responsibility” policy drives impressive progress, facilitating effortless and productive security progress.
The shift to remote/hybrid work caused by the pandemic is widely recognized as a milestone in digital security. The strategic value of the CISO has grown as organizations face many new security challenges. As such, the CISO maintains or expands its influence within the organization. Nearly half of CISOs report that the move has also resulted in a positive change in their security posture.
When security leaders were asked about the biggest challenges to achieving their goals, the most notable challenge was, unsurprisingly, the lack of sufficient staff. This was followed by speed of business change and budget issues.
technology
Cyber resilience, culture, cloud, and identity and access management (IIAM) are the top four most important technology topics that surveyed CISOs are paying attention to, reflecting historical trends. However, it is interesting to note that the global situation this year has made geopolitics a prominent topic of interest.
A majority of CISOs (67%) say their organizations’ security budgets have increased compared to last year. This underscores the fact that organizations understand the need to drive significant investments to achieve their security goals. Security Her leaders are also increasingly in control of the deployment of prescribed funds, allowing them to allocate resources as they see fit.
As well as the reported shortage of adequate staff, it is also not surprising that many of the organizations surveyed rely extensively on the cloud, either in hybrid or cloud-only configurations. There is none. And a significant number report that their reliance on the cloud will increase in the next few years. Unfortunately, progress in cloud security has been fairly sparse, and maturity has not kept up with the pace of evolution.
Security decision makers are clearly keen to regularly re-evaluate and fine-tune their investments to adapt to changes in the industry, but all areas need to be equally focused. It does not mean. IAM and security information and event management (SIEM) are the highest priority areas for security investment. Governance, risk and compliance, and vulnerability management tools lag behind.
dangerous
Reflecting progress at the ground level, 68% of CISOs surveyed feel their organization has achieved its key security goals, demonstrating impressive progress. At the board level, however, management appears to be primarily concerned with regulatory compliance and maintaining overall maturity. This could be the result of widespread pressure from regulatory bodies as security and privacy concerns grow around the world and boards tend to focus more on maintaining operational competence.
Firms have only marginally improved their management of third-party risk, but overall their risk management programs are fairly mature. Nearly twice as many (35%) of respondents reported a ‘managed’ or ‘optimized’ posture compared to last year. CISOs are also more confident than ever in their organization’s security posture, with 46% of them positive in this regard.
Perhaps one of the most important risk indicators is the dramatic decrease in the number of major breach incidents over the last 12 months. said period. However, we found that the most common attack vectors among those attacks were benign insider attacks and social engineering attacks. Insidious threats from malicious insiders remain a significant concern.
Most security leaders report that cyber insurance is an important part of their overall risk management toolkit. However, despite satisfactory results in nearly all claim cases, renewal pricing and coverage criteria remain significant obstacles to further adoption.
people
Recent developments in the human dimension of cybersecurity paint a multifaceted picture. Organizations still have a long way to go in tackling and managing stress, but significant progress has been made in many areas. Perhaps most notably, quite a few of his CISOs are hiring people from diverse backgrounds to build more capable and balanced teams. And as organizations strive to attract and retain talent, morale and team building exercises play a central role. Activities that address the most pressing employee concerns, such as providing flexible working hours, building a strong team culture, and even promoting an open environment, produce the most beneficial results.
At the same time, an industry-wide shortage of skilled professionals has forced CISOs to look inward. Organizations are investing more in their existing talent, whether supporting apprentices or developing talent within existing teams. As far as CISOs themselves are concerned, the opportunity to influence and drive change and be valued by the organization is the most important factor in motivating them to stay in their existing jobs. The CISO is the most important strategic leader in security, so when recruiting and retaining top talent is a concern, it is up to him to build an engaging team while championing a proactive security culture. It’s no surprise that it’s at stake.
Conclusion
The role and importance of the CISO has increased significantly as the perimeter of the enterprise rapidly expands and attackers evolve. By 2022, an overwhelming majority of security leaders believe they will add value to their business. It is a matter of course. The overall security posture has significantly improved this year, and the organization’s risk management has also improved. This impressive progress is only made possible by a CISO-led security charge. However, there is still a long way to go as security gaps in areas such as cloud maturity, insider threats and third-party risks are concerned.
To be truly effective, CISOs must help organizations leverage proactive security advances to deliver better overall business outcomes.
About the author: Srikar Sai is a technology writer with a business background. He primarily specializes in breaking down complex cybersecurity topics to a broader business audience, aiming to raise awareness about the latest happenings in the digital world. In his work with , he has helped create content across multiple channels. Deeply passionate about technology, he enjoys learning and writing about how technology affects and shapes the world around us.
Editor’s note: The opinions expressed in this and other contributor articles are those of the contributor only and do not necessarily reflect the opinions of Tripwire, Inc.
Comments
Post a Comment