Site navigation

Report: CISO’s Greatest Challenges are Data-centric

Michael Edgar

,

CISO data
Report shows the top concern shared by CISOs is inaccurate data in regards to their organisation’s security posture. 

In its annual Security Leaders Peer Report, Panaseer shed light on the challenges facing chief information security officers (CISOs) in terms of managing security controls, data and the impact it has on business decisions. 

The fourth annual report looked at senior cybersecurity decision makers from organisations employing over 1,000 people in the UK along with the US. It found that over half (54%) of respondents said their most significant concern when taking over the CISO role was an inaccurate audit of the company’s security posture. 

This issue of data quality was ranked higher among the CISO’s worries compared to concerns over the security budget or fear of getting blamed for the breach at 44%. This underscores the fact that unreliable security data can conceal vulnerabilities and lead to the insufficient utilisation of existing resources. 

On top of this, the report highlighted other challenges security leaders encounter when starting a new CISO role. The top concern was just about half who said they were worried about being unclear about the organisation’s security posture, while 45% said they were worried more about understanding the landscape in general, and 43% said they worried about getting the right data to make strategic decisions. 

Perhaps the most alarming stat was that only 36% of CISOs have full confidence in the accuracy of their security data to the point where they feel confident making strategic decisions with it. This could potentially hinder their ability to influence other senior business stakeholders, or ensure accountability in fixing security issues. 

“If you lose credibility, it’s the hardest thing to earn back from people. So when your data lacks credibility, that’s the same problem,” said Shawn Bowen, CISO of World Fuel Services.

A staggering 95% of respondents expressed high confidence that their security controls consistently work effectively, while 88% believed their security data was accurate. Yet, 79% of organizations admitted to being surprised by security incidents that bypassed their controls, suggesting either inaccurate data or a misinterpretation of the data.

Moreover, the report indicated that control data is not widely viewed as a strategic asset for cyber protection and risk mitigation. Approximately 38% of respondents were unable to provide evidence of control failure remediation, while a similar number (37%) deemed control failures as a low priority.


Recommended reading


Moving forward, the report reveals that 90% of security leaders are considering the improvement of the accuracy of cybersecurity data a priority in the next year. By achieving increased trust in their data, 84% of security leaders believe they can secure more resources to protect their organisation.

“The industry needs to change if we are to solve the CISO security controls conundrum, and Continuous Controls Monitoring (CCM) can be the catalyst. It isn’t a better reporting tool, it’s a way of knowing what to do next – making day-to-day cybersecurity firefighting easier and getting ahead of the game on strategic risk,” said Panaseer security evangelist, Marie Wilcox. 

“At the moment, many leaders don’t know that security controls data can help them do this. It’s understanding the value of a big picture view, and single source of truth rather than multiple siloed perspectives.”  

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data