Board members are increasingly aware of cybersecurity threats affecting their organisations, but a startling number of them also feel unprepared to handle these threats.
This is according to a new whitepaper from Proofpoint which tracked the perspective of board members and CISOs across the globe on the ever changing cybersecurity landscape.
While the survey found that most board members understood the myriad threats affecting them, a staggering 53% felt that their organisations were unequipped to handle a cyber attack in the next 12 months.
This rose when Proofpoint asked the same of CISOs, with a whopping 61% believing their organisation is unprepared to cope with a targeted cyber-attack in the next year.
Though unprepared, board members seemed to understand the cyber threat ecosystem.
Awareness Does Not Mean Preparedness
Malware (40%), cloud account compromise (36%) and insider threats (36%) were the top three biggest cybersecurity concerns listed by board members for the next 12 months.
Interestingly, ransomware came in fourth place, at 35%, despite the high-profile nature of these attacks.
Last year, board members were more concerned with email fraud, but worries here were likely stymied by increased effectiveness of inbox security tools. Further, high staff turnovers during the aftermath of the pandemic also increased fears of business email compromise, as new staff are not as trained in cybersecurity best practices, and may fall victim to fraud.
According to Proofpoint, insider threats are costing businesses over $15 million a year, and are only on the rise, so it is positive that board members are noticing the trend.
However, despite an increase in supply-chain attacks as noted by Proofpoint, only 26% of board members listed it as a top concern. Despite a previous finding from 2023 Voice of the CISO showing that 64% of CISOs think their organisations can mitigate supply-chain risks, these threats are not going anywhere. Supply chain attacks are projects to cost businesses nearly $46 billion by the end of this year.
When thinking about the damages these cyber attacks can cause, boardrooms have much the same opinion as they did in last year’s report.
Recommended
- Cybersecurity Advice for Law Firms From Arctic Wolf’s Dan Schiappa
- Top 4 Industries That Need Better Cybersecurity
- Less Than Half of C-suites Think Their Cybersecurity Budget Is Enough
Disruption to operations (36%), internal data becoming public (36%), and reputation damage (34%) all topped the list as the greatest concerns companies had regarding a cyber incident.
“It’s easy for board members to take their eyes off cybersecurity when current events take precedence and raise new concerns. Even if 72% of board members feel comfortable with their understanding of cyber risk today, the modern landscape is constantly introducing new complexities and cybercriminals are not standing still,” Lucia Milica Stacy said, a policy council and board member for the National Technology Security Coalition.
“Other priorities should not overshadow cybersecurity, especially in our deeply interconnected world where systemic risk is a growing problem.”
Confidence in the Board Room
Despite board members lacking confidence in their organisation’s cybersecurity posture, they have more faith in their own posture in the board room.
Most board members in the UK (57%) feel their board is comfortable making decisions about cybersecurity issues affecting the organisations.
This confidence, however, is dwarfed by the global average of 75%.
In the UK, confidence in cybersecurity investment has waned since last year.
According to the report, 84% of UK board members in 2022 thought that their organisation adequately invested in cybersecurity.
This dropped by 36% in 2023, to just 48% of UK boards thinking their company invested enough in cybersecurity.
Across the globe, however, most board members (84%) believe they will see an increase in their cybersecurity budget.
Proofpoint, however, pointed out that though 71% of board members believe they understand the systemic impact of cyber risk, this does not necessarily mean they do.
The complexity of cybersecurity, the interdependency of different supply chains and technology, continually transforms the needs of organisations to stay cybersafe. Changing regulations concerning data privacy and digital rights can also confound businesses attempting to dissuade attackers and evade hefty fines.
Overall, only 52% if board members surveyed in the UK agree that cybersecurity is a priority for their board, down from 80% last year. This may be due to a rise in other concerns, like economic insecurity, or a decrease in cyber concerns due to the ease of the pandemic’s effects and stressors on technology.





