Despite the growing cyber crime that’s causing havoc on the businesses worldwide, there seems to be a confusion in the boardroom. CISOs or IT security leaders who should be the person most accountable for preventing or mitigating the consequences of a cyberattack feel they are not treated as valued members or influencers in the C-suite. In fact, most businesses continue to follow the traditional reporting structure, where the security leader does not report to the CEO.
According to LogRythm-Ponemon Institute’s study, while most organizations have experienced a cyberattack in the last two years (60%) and spend approximately USD 38 million on security activities, only 7% of security leaders are reporting to the CEO, Yet, 42% of respondents say the CISO or IT security leader should be the person most accountable for preventing or mitigating the consequences of a cyberattack.
CISOs should Shoulder More Responsibility and Risk
In the global survey of 1,426 CIOs and CISOs, cybersecurity leaders shared they have assumed more accountability and risk, but struggle to achieve the desired security posture, because they are not seen as influential or valued members of their peer group. 60% of respondents say the CISO or cybersecurity leader should report directly to the CEO because it would create greater awareness of security issues throughout the organization. However, because the majority of security leaders are three steps away from the CEO, only 37% of respondents say their organization values and effectively leverages the expertise of the cybersecurity leader.
“While security leaders are assuming more responsibility than ever before, they lack the necessary organizational visibility and influence to effectively build and mature their security programs,” said James Carder, chief security officer of LogRhythm. “Comprehensive cybersecurity programs are integral to the success of an organization. This research should spur CEOs to take accountability for safeguarding their organization’s sensitive information, prioritize the security program by elevating the security leader and ensure inroads between security decision-makers, the C-suite and the board.”
New Security Pitfalls Stem From the COVID-19 Pandemic
The significant increase in employees working remotely due to COVID-19 has created the biggest security challenge for CISOs or IT security leaders, according to the research. These challenges are here to stay as enterprises adopt a hybrid work strategy to accommodate a distributed workforce, creating increased risk to sensitive and confidential information. Below are noteworthy findings about survey respondents’ newfound security issues resulting from remote work practices.
- 73% of respondents say less secure home networks are used by employees in their organization.
- 68% of respondents say employees and contractors believe the organization is not monitoring their activities.
- 67% say a family member uses a work device.
Amid these challenges, 54% of respondents are worried about their job security, with 63% citing insufficient budget to invest in the right technologies as a main culprit. Further, more than half (53%) of respondents claim senior leadership does not understand their role, and another 51% of respondents believe that they lack executive support.