CISOs face constant dilemmas to avoid drowning in their ‘security debt’

Outgunned security executives navigate complex obstacles to keep rising attacks from turning into more breaches.

  • 3 years ago Posted in

CISOs face a rising ‘security debt’ to secure their organizations against an increasing volume of attacks by well-armed criminals. Yet despite going up against a criminal industry that enjoys advantages when it comes to speed and shared weaponry, CISOs and their teams report turning away increasing volume of attacks and preventing more of them from becoming breaches or compromises, according to a new report from cyber security provider F-Secure in conjunction with Omnisperience.



In addition to the lure of successful high-profile ransomware attacks, service and affiliate models are making threat groups more effective. The sharing of tooling and offensive knowledge makes it easier to conduct more attacks against more targets.


An overwhelming percentage of the CISOs - 96% - acknowledge that they face a well-organized criminal industry motivated by financial gain. Furthermore, about seven out of 10 CISOs (72%) say adversaries are moving faster than they are, and a similar number (69%) say their adversaries have improved their attack capabilities in the last 12-18 months.


“Despite pervasive ‘security debt’ and reporting a rising number of cyber attacks, CISOs say that say the number of incidents, which includes a breach or unauthorized access to a system, they faced remained pretty much the same,” says F-Secure’s Michael Greaves, security advisor for Managed Detection and Response. “This could be because CISOs have made the right investments. However, it is the incidents that haven’t been discovered which worry us most. Because of the sophisticated nature of some of these attacks, organizations may not have the technology or people to identify they are in the middle of a compromise that, for example, may result in a ransomware deployment months down the road.”


The report covers numerous aspects of the complex dilemmas CISOs face on a daily basis, including:

  • Employees are the primary attack vector, according to 71% of the CISOs interviewed, as attackers take advantage of social channels to launch more sophisticated targeted attacks.
  • The top three threats CISOs and their teams face are phishing, ransomware and business email compromise (BEC).
  • Securing the mobile or remote workforce, which has exploded during the pandemic, presents a number of risks, particularly where employees and devices are separated from traditional controls that could prevent their compromise.
  • A vast majority of CISOs - 71% - report that their ideas about what constitutes “good security” has evolved recently.

 

“Too often, cyber security is seen as ‘risk mitigation’ instead as a ‘business enabler’ by C-level executives. CISOs are tasked with overcoming that perception and their ‘security debt.’ To do this they must call on every ounce of their abilities, including emotional intelligence, to persuade their peers and deny attackers,” says Royce K. Markose, Chief Information Security Officer at RewardStyle.com.

Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Atos has launched Atos OneCloud Sovereign Shield, a set of solutions, methodologies, and...
New distribution agreement set to bolster Westcon-Comstor’s Zero Trust offering in more markets...
Research from Avast has found that employees in almost a third (31%) of Small and Medium...
This year, over half of MSPs or their end customers have been attacked by ransomware but only 53%...
Trend Micro has published new research revealing that 90% of IT decision makers claim their...
Cyber consultants call on businesses to act now, or risk budgets shrinking further in ‘real...