Headlines

“Overlooking Cybersecurity: A Critical Oversight for Business Success According to 61% of IT Security Decision Makers”

"Overlooking Cybersecurity: A Critical Oversight for Business Success According to 61% of IT Security Decision Makers"cybersecurity,ITsecurity,businesssuccess,criticaloversight,decisionmakers
A recent global survey by Delinea, a leading provider of Privileged Access Management solutions, has revealed the negative impact of misalignment between cybersecurity and business goals in organizations. The survey was conducted on over 2,000 IT Security Decision Makers (ITSDMs) in 23 countries during March 2023. The results showed that only 39% of ITSDMs considered their company’s leadership to have a sound understanding of cybersecurity‘s role as a business enabler, while over a third (36%) believed that cybersecurity was important only in terms of compliance and regulatory demands. This disconnect between business and security goals resulted in delays in investments (35%), delays in strategic decision making (34%), and unnecessary increases in spending (27%). Additionally, the survey highlighted that nearly a quarter (26%) of respondents encountered an increased number of successful cyber-attacks at their companies due to misalignment of business and security goals.

The report suggests that structural processes are key to aligning goals, and most security teams (62%) already meet regularly with their business counterparts at the highest level. Furthermore, 54% of companies have embedded security team members within business functions. Despite this, more than a third (33%) of respondents reported that alignment is ad hoc and only ‘happens when needed.’ The report shows that less than half (48%) of organizations document policies and procedures to facilitate alignment, and this shows that, while some organizations have good security programs in place, there is still room for improvement.

The survey has revealed that metrics used to measure and demonstrate the value that cybersecurity delivers are still primarily linked to technical or activity-based figures. The number of prevented attacks (31%) was cited as the most important measure of success, followed by meeting compliance objectives (29%) and reducing costs of security incidents (29%). The report suggests that executive leaders need to think of cybersecurity not only in terms of ticking the compliance box or protecting the company but also in terms of the value it can deliver at a more strategic level. Communication between business and security teams is vital in this regard.

The report highlights the importance of building out business skillsets in security teams. Technical skills were rated above skills such as communication, collaboration, business acumen, and managing people. However, nearly a third (31%) believed that making the business case to the Board and C-Suite was a gap in their own skillset. Communication skills were also identified as an area for improvement by 30% of respondents.

The report concludes that alignment between cybersecurity and business goals is essential for success. Ensuring common agreement across business functions is vital, and metrics that demonstrate the impact on business outcomes should be used. While strong technical skills are still important, security leaders need the ability to communicate, influence, and present the value they add to business outcomes more frequently than ever. Security leaders that demonstrate a mix of skills and have the same end goal in sight as the business are a force to be reckoned with.

In conclusion, the report highlights how misaligned goals between business and security teams can result in negative consequences, including increased cyber-attacks, delays in investments, and unnecessary increases in spending. To achieve better alignment between cybersecurity and business goals, organizations should build out business skillsets in security teams and focus on common agreement across business functions, where metrics are used to demonstrate impact on business outcomes. Ultimately, communication between business and security teams is key to successful cybersecurity, and security leaders need the ability to communicate, influence, and present the value they add to business outcomes.

Cybersecuritycybersecurity,ITsecurity,businesssuccess,criticaloversight,decisionmakers


"Overlooking Cybersecurity: A Critical Oversight for Business Success According to 61% of IT Security Decision Makers"
<< photo by Dan Nelson >>

You might want to read !