Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Predicting 2015 – The year the board actually care?

by The Gurus
January 16, 2015
in Opinions & Analysis
Share on FacebookShare on Twitter

Following our look at the common prediction trends for 2015, and identifying both major flaws and expanding ransomware as trends worth looking at, the next timely trend looks at the boardroom.
 
Today, research of the FTSE 350 by PwC found that 88 per cent say that cyber security is on the board’s agenda, yet only 29 per cent of companies thought cyber was a “top risk”. So perhaps strides are being made forward in terms of getting the board’s attention, or perhaps CISO can thank a greater focus on the CIO and headlines surrounding Target, ebay and Sony Pictures
 
So after a year where security was very much in the spotlight, is this year set to be a step forward for security in the boardroom? Nicholas J. Percoco, vice president of strategic services at Rapid7, claimed that in 2015, CISOs will spend 100 per cent more time with their boards and executives than previously.
 
“With the number of high profile data breaches announced in 2014, board members and senior executives will seek more clarity and assurance that their company’s security programmes are aligned for success,” he said. “In 2015, we’ll see more time for CISOs in the board room presenting metrics and relevant data points to highlight security programme effectiveness. CISOs will be seen spending more time outside of compliance and regulators discussions and more time focusing on mitigating actual risks to data loss.”
 
Likewise. Rajiv Gupta, CEO of Skyhigh Networks claimed that as security breaches are no longer the sole responsibility of the CISO, especially with the Target fallout proving that CEOs are also being held to account, he expected CEOs to develop closer and better working relationships with the CISO in the next twelve months.
 
He said: “Whether it’s in negotiating security budgets, managing risk, or briefing the board of directors –  I’d go so far as to say that the two will be joined at the hip in many organisations next year.”
 
So the board room is taking notice. It is still a sweeping statement to say that all boardrooms and CEOs are interested in cyber security, but the Target situation should show how the top of a company can be impacted by something supposedly dealt with by those in the basement.
 
Rob Lay, solutions architect for enterprise and cyber security, UK & Ireland for Fujitsu said that security should be more of a business than IT challenge, as it sitting outside of the IT department isn’t something which businesses should be worried about, in fact it represents a positive change.
 
He encouraged businesses to develop an enterprise security model that is flexible and can change as the IT environment, and threat landscape change around it. “In order to do this, and ensure that security efforts are focused in the right areas, businesses should ensure that their security model places risk management at the centre,” he said. “This way the business can assess and prioritise its enterprise security efforts in the way which will best benefit the business.”
 
So how will this change come about? After all, the change is partly down to the CEO adopting security, and partly also down to the CISO being adaptable to work at
the board level. Mark Barrenechea, CEO at OpenText, said that one way is the emergence of the chief data officer and the chief digital officer. He predicted that these two C-level roles will find themselves at the executive table as the enterprise is guided on its journey to digital transformation.
 
“While their roles are unique, both will focus on the strategic importance of information in a digital economy,” he said. “The chief digital officer will be the executive advocate for the digital customer and will emerge to oversee both the strategy and the technology for a seamless and satisfying digital customer experience. According to Gartner, 25 per cent of businesses will have a chief digital officer by the end of 2015.
 
“The chief data officer will emerge as the executive advocate for data management – using the exploding volumes of data and analytics to improve decision making and identify new revenue opportunities. Across the organisation, every function will want access to data and insights about their operations. The chief data officer will make this possible by optimising the management of data (integrating, deploying, securing, governing) and mobilising their organisation around an Enterprise Information Management (EIM) strategy.”
 
So; new interest and new jobs, it all sounds pretty positive. Remove the threats altogether and you have no real problem right? To round off, I got some interesting comments regarding risk and the changes there.
 
Jason Polancich, founder and chief architect of SurfWatch Labs, said that there will be a renewed focus in the practice of risk management, but this is more for cyber risk than cyber threats. He said that the security industry continues to focus on identifying threats, and this mind set needs to shift as cyber threats represent an overwhelming flood of data that is hard to correlate.
 
“Organisational cyber risk (not threats) must be quantified and assigned a process for inventorying, monitoring and mitigating,” he said. “While admittedly a little pie-in-the-sky, I do believe organisations will start to realise this and consider detailed risk management programs for their cyber risk.”
 
The consistent theme of these predictions seems to be that there is an interest from the whole organisation, and security is not confined to the IT or security (or both) team. Obviously this is something that is different from company to company, and a hard one to prove whether it worked or not, but if security reaches the upper echelons of the top global businesses then maybe there will be more hiring, more money spent and better success for all.
 
Join our next webcast, taking place at 3pm GMT on Thursday 22nd January where we will discuss effective spending to help defend against modern threats. We will be joined by Bromium’s Ian Pratt, CISO Paul Swarbrick and the Information Security Forum’s Steve Durbin – https://www.brighttalk.com/webcast/11399/140339

Tags: BoardCEOCISO
ShareTweet
Previous Post

USA and UK prepare "war games" – industry views

Next Post

British man arrested in connection with investigation into PlayStation and Xbox DDoS

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol