CISOs are more on edge than other C-suite execs, as fresh research from EY reveals that two-thirds (66%) of chief information security officers are worried that evolving cybersecurity threats are more advanced than their firm’s defences.
According to EY’s latest study, Bridging the C-suite Disconnect, just 56% of other C-suite executives are concerned that their current security measures can withstand the rapid escalation of threats, and more likely to treat cybersecurity as a ‘cost centre’ rather than a strategic investment.
EY’s survey, which polled 500 C-suite leaders and 300 CISOs across large enterprises, uncovered an alarming divide between security and business leaders on exposure levels, threat sources, and planning, a disconnect which is leaving firms open to risk.
For example, CISOs were more likely than the rest of the C-suite to express concern about senior leaders underestimating cybersecurity threats (68% vs. 57%), highlighting a lack of understanding among C-suites about the danger of minimising ongoing threats.
The survey also found a divide between CISOs and the rest of the C-suite on the origin of cybersecurity incidents and the malicious actors responsible.
Nearly half of CISOs (47%) reported that their organisation had suffered a cybersecurity incident caused by insider threats, such as employees deliberately stealing or leaking sensitive data, compared to just 31% of other C-suite leaders.
Meanwhile, CISOs were also more likely to attribute breaches to cybercriminal attacks, with 57% citing them as the primary cause versus 47% of their executive peers, with EY pointing out this gap in understanding about the source of incidents is problematic for building future defences.
Another concerning disconnect is that CISOs are the most likely to attribute decreased cyber incidents to investment in new tech and security tools.
Three-quarters of CISOs said their organisation experienced a decrease in cybersecurity incidents following investment in AI, compared to just 68% among the rest of the C-suite. By contrast, other C-suite execs (77%) were more likely than CISOs (69%) to attribute success in lowering cybersecurity incidents to investments in employee cybersecurity training.
There is a silver lining here, however, with investments on the rise. While currently only 21% of C-suite leaders say they invest more than 10% of their IT budget in cybersecurity, this number is expected to roughly double to 38% next year.
“It’s time to take the bull by the horns and push for not just the resources but the authority for cyber leaders to build truly resilient organisations,” said Jim Guinn, EY cybersecurity leader.
“CISOs see escalating threats and vulnerabilities, while the C-suite appears to often believe cybersecurity is handled.
“Cybersecurity incidents carry significant and far-reaching financial repercussions beyond immediate recovery costs.
“Our research reinforces the urgent need for leaders to come together and develop a comprehensive cybersecurity strategy that addresses the evolving threat landscape and includes clear communication, a shared understanding of the risks and opportunities, and priority areas for investment.”
Recommended reading
- Two-thirds of CISOs Have Had Budgets Slashed Due to AI
- Half of Cybersecurity Professionals Expect to Burnout Within the Next Year
- Cyber Leaders Reveal Compliance and Boardroom Struggles
EY’s research follows multiple other studies providing ample evidence of not just a widening disconnect in the boardroom, but also a worrying trend of underappreciation for the vital role CISOs play.
Earlier this year, a report from Splunk found that a gap in the perception of the work CISOs do and the everyday reality, with 52% of boards thinking that CISOs spend most of their time on business enablement, even though only 34% of CISOs agree.
Meanwhile, 52% of CISOs reported wanting to focus more on innovating with emerging technologies, but only 33% of boards agreed that it should be a priority.
Research from Proofpoint found that despite CISOs place in the boardroom solidifying over the past few years, with 84% now saying they see ‘eye-to-eye’ with their boards, two-thirds said that the expectations placed on them are excessive, leading more than half to experience burnout.





