Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

The Accountability Gap: Getting Business to Understand Security

A new survey and report from Tanium and NASDAQ, using a research team from Goldsmiths, University of London, seeks to quantify organizations’ cyber security vulnerability.

A new survey and report from Tanium and NASDAQ, using a research team from Goldsmiths, University of London, seeks to quantify organizations’ cyber security vulnerability.

The resarch was done by first defining seven inherent challenges and then surveying 1,530 non-executive directors (NEDs), CISOs and CIOs from the US, UK, Germany, the Nordic countries, and Japan. The seven categories that comprise cybersecurity vulnerability are cyber literacy, risk appetite, threat intelligence, legislation & regulation, network resilience, response, and behavior.

The bottom-line conclusions from the response analysis will surprise no-one involved in cyber security – only 10% of respondents have a low level of vulnerability. The vast majority of organizations (80%) are deemed to have “a medium level of vulnerability.”

This is mirrored in the report detail. For example, only 13% of the most vulnerable NEDs are briefed regularly on cybersecurity legislation and regulation, and just 8% are regularly briefed on current threats. This compares to 100% and 96% respectively for the least vulnerable. There is a close correlation between poor information exchange between Business and Security and a poor security posture.

However, knowing there is a problem, and knowing what to do about it, are two different things.

The real difficulty is in getting Business to accept that it needs to understand Security. Writing in CityAM, Dr. Chris Brauer, director of innovation in the Institute of Management Studies at Goldsmiths, University of London, accepts the difficulty: “There is a marked hesitance to speak up among those NEDs who didn’t consider themselves knowledgeable about “cyber”. Most are not digital natives and there is a common culture of complacency – often a “leave that to the techies” spirit – and an over-reliance on specialist advice.”

Orion Hindawi, Co-founder & CEO at Tanium, agrees with this basic problem: the study found “a worrying gap between presumed and actual corporate readiness for data security incidents and a widespread lack of accountability at the top levels of organizations. That means that some of the world’s largest networks, holding some of our most precious data, are more vulnerable than their leaders believe.”

The report’s own primary conclusion is that organizations need to ‘create a culture of openness’. “Boards need to know what questions to ask in order to understand the state of cybersecurity of the business. These can be supplemented by detailed in-house or externally facilitated briefings for directors to ensure they have the skills to provide adequate oversight. Board members need to learn how to ask questions the same way they do for financial concerns and, in some cases, certain board members responsible for cyber should be given extended training.”

Advertisement. Scroll to continue reading.

How to get to that culture of openness is the problem. In general, Business has no wish to understand Security, that’s what it pays CIOs and CISOs to do. CISOs know and grapple with this problem all the time and the reality is that it will most likely be solved by Security learning to speak Business, rather than Business learning to speak Security.

Related: Learn More at SecurityWeek’s CISO Forum

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem