Lack of communication between management teams
As a recent Harvard Business Review article points out , there’s another disconnect: between the CISO and the board. According to a survey of board members, only 69% feel they are on the same page as their CISO. And less than half interact with them on a regular basis. According to Neil Jones, chief cybersecurity officer at Egnyte, this is often the result of “a lax approach to cybersecurity by management that views IT security spending as a project expense rather than an investment in brand protection.”
“Cybersecurity never gets the investment it deserves because it doesn’t generate revenue,” Williams adds. “It doesn’t create value. It protects value. So one of the problems is underinvestment. It’s hard to build the talent you really need.”
Regular training for executives can help bridge this austria mobile database gap. Additionally, engaging executives who are more familiar with the current situation can help reinforce the importance of cybersecurity among senior management, even if the CISO is not part of the team.
Conversely, CISOs need to develop communication skills that allow them to convey this importance in understandable terms. People tune out when they don’t understand what’s being said. And executives can be particularly unresponsive. According to one study , nearly 30% of CEOs have strong narcissistic personality traits, suggesting that many may be unwilling to admit their own ignorance and ask for more information.
This is significant given that these executives themselves can be vulnerabilities within an organization. “We’ve seen CEOs or board members of large Fortune 500 companies practice very poor cyber hygiene,” Williams admits.
Complacency has been a common cause of cyber breaches. Organizations invest in expensive suites of tools that promise to protect data, and they assume that they will. Whether these are the right tools, and whether they are deployed correctly, is another matter.
Organizations should avoid “relying on disparate, piecemeal cybersecurity solutions that do not provide comprehensive protection against cyberattacks and malicious insiders,” Jones advises.
Overconfidence and negligence
-
relemedf5w023
- Posts: 940
- Joined: Sun Dec 22, 2024 7:15 am