88% of Boards of Directors view cybersecurity as a business risk
Techsense team I 3:59 pm, 19th November
88% of Boards of Directors (BoDs) view cybersecurity as a business risk, as opposed to a technology risk, according to a new survey from Gartner. However, only 12% of BoDs have a dedicated board-level cybersecurity committee.
"It’s time for executives outside of IT to take responsibility for securing the enterprise", said Paul Proctor, distinguished research vice president at Gartner. "The influx of ransomware and supply chain attacks seen throughout 2021, many of which targeted operation and mission-critical environments, should be a wake-up call that security is a business issue, and not just another problem for IT to solve", he added.
CIOs and CISOs must rebalance cybersecurity accountability
Even as business leaders are aware of the need to secure the enterprise against new and evolving threats, responsibility for security mostly lies with IT leadership. A recent Gartner survey found that in 85% of organisations, the CIO, CISO or their equivalent was the top person held accountable for cybersecurity. Just 10% of organisations held non-IT senior managers accountable (see Figure 1).
"IT and security leaders are often considered the ultimate authorities for protecting the company from threats", said Paul Proctor. "Yet, business leaders make decisions every day, without consulting the CIO or CISO, that impact the organisation’s security".
CIOs and CISOs must rebalance accountability for cybersecurity so that it is shared with business and enterprise leaders. Gartner recommends that IT and security leaders work with executives and BoDs to establish governance that shares responsibility for business decisions that affect enterprise security.
Reframe cybersecurity investments from a business lens
Recent research has found that 66% of CIOs intend to increase cybersecurity investments in the coming year. However, Gartner projections show that overall growth in cybersecurity spend will slow through 2023.
"After years of such heavy investment in security, Boards are now pushing back and asking what their dollars have achieved", said Gartner analyst.
As security budgets shrink, CIOs and CISOs will need to collaborate closely with executive leadership to reframe cybersecurity investment in a business context. For example, CISOs can offer a range of protection options to business leaders with the costs and risks of each choice clearly outlined.
According to Paul Proctor, "CIOs and CISOs must leverage their expertise to increase transparency around investment and risk, to drive shared accountability for security across the business".
Subscribe to our Newsletters

Stay up to date with our latest news
more news

ESET HOME Security : une protection consommateurs renforcée contre les escroqueries avancées
by ESET I 4:10 pm, 21st October
ESET, un leader mondial en solutions de cybersécurité, annonce la mise à niveau d’ESET HOME Security (ESET HOME Security), son offre grand public, et d’ESET Small Business Security (ESET Small Business Security), son offre pour les petites entreprises et les bureaux à domicile (SOHO). Cette mise à niveau introduit de nouvelles fonctionnalités, dont la Suppression des ransomwares, ainsi que des améliorations à des fonctionnalités existantes, comme la surveillance microphone et l'Inspecteur de sécurité de sites web. Ce lancement souligne aussi le rôle essentiel du VPN dans la cybersécurité. Pour cela, ESET a mis ESET VPN à la disposition des utilisateurs d'ESET HOME Security Ultimate et d'ESET HOME Security Premium.
GhostRedirector, nouveau groupe de menaces chinois, manipule Google et empoisonne les serveurs Windows – une découverte d’ESET
by ESET I 2:00 pm, 9th September
• ESET Research a découvert au moins 65 serveurs Windows compromis, d'après une analyse Internet réalisée en juin dernier.• ESET estime qu'un acteur malveillant et jusqu'alors inconnu, lié à la Chine, est probablement à l'origine de ces attaques. Il a été baptisé GhostRedirector par les chercheurs.• Les victimes se trouvent principalement aux États-Unis, au Brésil, en Thaïlande et au Vietnam.• Les victimes ne sont pas liées à un secteur spécifique, mais à divers secteurs, dont l'assurance, la santé, la vente au détail, les transports, la technologie et l'éducation.• GhostRedirector a développé Rungan, une nouvelle porte dérobée C++, capable d'exécuter des commandes sur le serveur de la victime.• GhostRedirector a aussi développé Gamshen, un module malveillant natif IIS, capable de perturber le référencement naturel (SEO - Search Engine Optimization).
load more