A new report has suggested that CISOs are gaining influence and organisational cybersecurity has significantly improved over the last year.
According to research, the number of CISOs reporting that ‘no material incident occurred’ at their organisation had increased in the past year, reaching 54% compared to 27% in 2021.
The findings were revealed in the latest Information Security Maturity Report from ClubCISO and Telstra Purple. They were based on a survey of over 100 information security leaders from both private and public organisations around the world.
Material incidents are those that caused significant changes to financial position, operational disturbances, or compromised data.
In addition, it noted a fundamental shift in security culture with 45% of CISOs noted positive change in attitudes to security from increased remote/hybrid working. CISOs are becoming more important within their respective groups as 46% suggested they had extended their organisational influence.
A further 67% of CISOs responding to the survey said their organisations had increased their information security budgets compared with last year, and for one-fifth of respondents, budgets had increased by more than 50%.
However, ‘non-malicious insider’ was reported as the most common threat vector for those who faced a material incident, with 17% of respondents citing it. This was higher than social engineering attacks (11%) and incidents that came as a result of compromised credentials (10%).
Stephen Khan, Chair of the ClubCISO Advisory Board said: “As we move further away from the pandemic, what this report makes clear is that much of the groundwork to bolster security has been done. Collectively, CISOs have made security a company-wide concern and the business case for it, not only in our respective businesses but also across our supply chains, has never been stronger.”
He added: “Our findings show that CISOs are now in the driving seat with extended influence and increased budgets, and are better positioned to deal with an increasingly complex and dynamic threat landscape.”
Recommended
- The state of tech opportunities in Aberdeen and the Northeast
- Second AND Digital club opens in Edinburgh
- Is the Meta-Giphy purchase finally dead?
Against the backdrop of heightened security concerns from state actors and emboldened cyber-criminals, 91% of the CISOs surveyed said they had accelerated their cyber-security tactics in the last year. Of note, the number of organisations now actively working on third-party (i.e., supply chain) management nearly doubled compared with 2021.
Physical security programmes, enabling remote access and additional outsourcing ranked the lowest in this regard, whilst 52% of CISOs suggested they were focusing on policies, governance and frameworks to accelerate their cyber security strategies.
As the industry gets on the front foot to deal with an ever-evolving macro-environment, talent continues to be a priority for CISOs. A total of 65% suggested that they are actively seeking to recruit from diverse backgrounds. And whilst the ‘best recruits’ continue to come from ‘technology or engineering’ and ‘other infosec industry sources’, 42% felt their best recruits came from ‘risk management’ and 31% answered ‘other non-infosec sources’, not including security graduates or apprenticeships.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





