Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Global CISOs Concerned About Business’ Cybersecurity Readiness

by The Gurus
November 6, 2017
in Editor's News
Share on FacebookShare on Twitter

Research by the Ponemon Institute focusing on Chief Information Officers (CISO) worldwide has found worrying levels of business readiness for cybersecurity threats.
Drawing on insights from 184 global CISOs, a new F5-comissioned report has highlighted the latest challenges encountered in the increasingly influential role.
“This new research provides a unique view into how CISOs are operating in today’s challenging environment,” said Mike Convertino, CISO, F5 Networks.
“It’s clear CISOs are making progress in how they drive the security function and the leadership role they are assuming within companies. Yet in many organisations, IT security is not yet playing the strategic, proactive role necessary to fully protect assets and defend against increasingly sophisticated and frequent attacks.”
 
Businesses exposed
The Ponemon Institute noted that today’s IT security strategies and tactics are shifting away from a focus on strong perimeters to smart data, networks, devices and applications.
According to 60 per cent of CISOs, material data breaches and cybersecurity exploits are driving change in organisations’ attitudes to security programs. 60 per cent of respondents currently believe security is considered a business priority.
Yet, while awareness levels are clearly growing, the report’s clear message is that there is plenty of room for improvement.
80 per cent of respondents say the Internet of Things (IoT) will cause “significant” or “some change” to their practices and requirements. However, most companies are not hiring or engaging IoT security experts (41 per cent) or purchasing and deploying new security technologies to deal with potential new risks (32 per cent).
Finding the right talent is also a significant hurdle, with 56 per cent struggling to identify and recruit qualified candidates. Almost half of surveyed CISOs branded their staffing as inadequate (42 per cent).
Interestingly, 50 per cent consider computer learning and artificial intelligence important to address staffing shortages. In two years, 70 per cent say these technologies will be important to their IT security functions.
 
Trouble at the top
60 per cent of CISOs claimed to have a direct channel to the CEO in the event of a serious security incident. However, only 19 per cent reported all data breaches to the CEO and board of directors. Only 45 per cent have emergency funds to deal with a serious security incident
that may require additional resources.
The report also found an alarming disconnect between IT and other business departments.
58 per cent of the CISOs’ companies had IT security as a standalone function, meaning most lack an IT security strategy spanning the entire enterprise. Only 22 per cent said security is integrated with other business teams and 45 per cent had security functions without clearly defined lines of responsibility. 75 per cent reported that a lack of integration concerning business functions, turf and silo issues exerted a significant influence (36 per cent) or some influence (39 per cent) on IT security tactics and strategies.
Communication is another pressing issue. While 65 per cent of CISOs communicate directly with senior executives, it is rarely to strategically discuss all organisational threats. 46 per cent admitted CEO and board of directors’ communication only happens in the event of material data breaches and material cyber-attacks. Only 19 per cent report all data breaches to the CEO and board of directors.
Security program change remains largely reactive, with material data breaches (45 per cent) and cyber security exploits (43 per cent) garnering the most senior executive attention.
 
The challenge ahead
Most CISOs agree cybersecurity threats are here to stay. Organisations represented in the study experienced an average of two data breaches in the past 24 months. 83 per cent say the frequency of data breach will increase or stay the same. 87 per cent believe the severity of data breach incidents will increase or stay the same.
On average, respondents also experienced three cyber exploits or attacks in the past 24 months. 89 nine percent of respondents said cyber exploits will increase or stay the same. 91 per cent predicted the severity of cyber exploits or attacks would increase or stay the same.
Advanced persistent threats (APTs) were ranked the top threat to the security system followed by DDoS, data exfiltration, insecure apps (including SQL injection), credential takeover, malicious
insiders and social engineering.
Another major challenge for CISOs are legislative changes, particularly the European Union’s imminent General Data Protection Regulation (GDPR), which affects any company doing business with member states. 72 per cent of respondents agreed that cultural differences among people and business operations around the globe have a direct influence on local security requirements.
“Cybersecurity challenges are intensifying worldwide and we need CISOs to step up and be more influential at the top,” added Convertino.
“We also need business-leaders to recognise the growing threat cybersecurity poses in its many shifting forms. The measure of an organisation is how it pre-empts and responds to risk and – more than ever before – CISOs must lead the charge in this respect.”

Tags: CISOsCybercybersecurityPonemontechThreats
ShareTweet
Previous Post

Avanan Selects Lastline to Boost Malware Detection and Visibility for Endpoint and Web Gateway Security

Next Post

Cyber Pros Point to “Perfect Storm” as Security Fundamentals Face Crisis

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol