Security tech firm Ivanti has released the results of its 2024 State of Cybersecurity Report. With the increasing complexity of the threats and evolution of threat-actor tactics, cybersecurity professionals are facing a constant battle to keep pace with the ever-changing techniques used by malicious actors. This has led to a greater need for innovative and adaptive security measures.
Although IT and security professionals share goals and challenges, 72% report that their organisations’ security and IT data are siloed, leading to corporate misalignment and increased security risks.
Due to insufficient data integration, IT and security professionals face several issues: 63% say siloed data slows down security response times, 54% believe it weakens their organisation’s security posture, and 41% struggle with collaborative cybersecurity management.
Additionally, 47% find it difficult to make informed security decisions regarding employee-used software (including shadow IT), 42% struggle with managing devices accessing the network and corporate resources, and 41% have trouble identifying system vulnerabilities.
“While data silos can be a technology issue, resolving them and gaining a comprehensive understanding of an organisation’s risk landscape requires leadership. However, CIOs and CISOs are at odds. They face a tug-of-war challenge between enabling employee productivity while ensuring data security, which can lead to an increase in cyberattacks. To foster a more secure workplace, collaboration is essential,” said Jeff Abbott, CEO, Ivanti.
He added: “When there is CIO and CISO alignment, it helps both parties build consensus on organizational risk tolerance while promoting cross-functional security and IT data collaboration. This eliminates costly ripple effects and increases data accessibility for investments in AI.”
Data silos are a universal problem for CISOs and CIOs — and a particularly thorny one given the speed of investments in AI, which will require data integration and accessibility. To ultimately strengthen an organisation’s security posture and drive transformation, there needs to be CIO and CISO alignment and executive buy-in on security.
According to Ivanti’s research, cybersecurity is widely viewed as a top priority, even at the board level. Fully 80% of those surveyed say their boards include someone with security expertise, and 86% report it’s a topic of discussion at the board level. This is promising to hear in light of the various cybersecurity concerns raised by the study.
For instance, when it comes to a practice called BYOD (bring your own device), IT and security teams use tools that were designed for just in-office usage and have no effective way to track and manage employees’ personal devices at work.
- Just 63% can track BYOD alongside corporate-owned IT assets, yet 78% say employees use their personal devices at work even when it’s forbidden.
- 81% of office workers admit they are using some type of personal device for work.
- Of the 81%, half are logging in to networks and work-affiliated software on their personal devices. And 40% say their employers don’t know about their activities.
Another cause for concern – 54% of office workers were not aware that advanced AI could impersonate anyone’s voice. Ivanti’s research finds that 95% of IT and security professionals believe that security threats will be more dangerous due to AI. However, despite the elevated risk posed by AI, nearly one in three security and IT professionals have no documented strategy in place to address generative AI risks.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Comment | Cybersecurity Ethics in an Age of Evolving Cyber Risk
- Cyber Leaders Reveal Compliance and Boardroom Struggles
Taking these various concerns into account, the report emphasises the critical need for alignment between the CIO and CISO in their approach to security mandates. This alignment can help organisations identify areas of friction and make operational improvements, eliminate data silos that hinder response times and conceal crucial insights, and gain a thorough understanding of the software supply chain. Ultimately, this collaborative effort fosters mutual accountability and enhances overall security posture.





