Security Market Segment LS
Friday, 09 October 2020 08:46

Thycotic study – what causes a board to invest in cyber security? Featured

By

Thycotic, a provider of privileged access management (PAM) solutions to more than 10,000 organisations, including 25 of the Fortune 100, today released its CISO Decisions survey, an independent global study that examines what most influences the board to invest in cyber security and the impact this has on CISO decision-making.

Thycotic, in conjunction with Sapio Research, conducted a survey in August 2020 that gathered responses from 908 Senior IT security decision-makers (102 in Australia) working within organizations of 500+ employees in these countries: US (22% of responses), UK (11%), Germany (11%), Australia (11%), New Zealand (11%), France (11%), Spain (11%), Malaysia (6%) and Singapore (5%). Of those, 31% claimed to be CEO/CSO/CISO/CIO, 37% head of IT or IT director and the remaining 32% were IT manager or security manager.

The research shows boardroom investments in cyber security are most commonly the result of an incident or fears of compliance audit failure. Because of this, the research found two thirds, or 66% of Australian respondents (58% globally) say their organisations plan to add more towards security budgets in the next 12 months.

There are positive signs that boards are stepping up with investment. Around 88% of Australian respondents (77% globally) have received boardroom investment for new security projects, either in response to a cyber incident at 59% of organisations (49% globally) or through fear of audit failure at 29% (28% globally).

Cyber threats have risen due to the work-from-home nature of the response to the COVID-19 crisis, and CISOs report that boards are listening and stepping up with increased budgets for cyber security, with the overwhelming majority in Australia, or 94% (91% globally) agreeing that the board adequately supports them with investment. Two thirds of Australian respondents (versus 58% globally) believe that in the next financial year they will have more security budget because of COVID-19.

However, CISOs have their work cut out to gain the support of boards. Around two fifths, or 41% of Australian participants' proposed investments (37% globally) were turned down because the threat was perceived as low risk. Around two in five, or 39% (37% globally) were turned down because the projects had a lack of demonstrable ROI. And 38% of Australian respondents (33% globally) believe senior management does not comprehend the scale of threats when making cyber security investment decisions, thus perpetuating the problem that many IT security officers have in "selling" to the board.

"Our study clearly shows that before CISOs can pursue technology innovation they must first educate their stakeholders about the value of cyber security," said James Legg, chief executive at Thycotic. "Securing boardroom investment requires them to strike a delicate balance between innovation and compliance."

CISOs' own approaches to buying decisions are forward looking as they try to keep up with industry developments and their sector peers. A large majority, or 74% of Australian respondents (75% globally) say they want to try out innovative new tools. However, in practice, many are guided by their industry peers, with two in five, or 40% (46% globally) benchmarking their buying decisions against other companies in their sector. This may lead CISOs to err on the side of proven, known technology rather than trying something new.

"While boards are definitely listening and stepping up with increased budget for cyber security, they tend to view any investment as a cost rather than adding business value," said Terence Jackson, CISO at Thycotic. "There are some encouraging signs, particularly in APAC where ROI is a leading factor in security investment decisions.

"However, there is still some way to go," he continued. "The fact that boards mainly approve investments after a security incident, or through fear of regulatory penalties for non-compliance, shows that cyber security investment decisions are more about insurance than about any desire to lead the field which, in the long run, limits the industry's ability to keep pace with the cyber criminals."

Read 3881 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




IDC WHITE PAPER: The Business Value of Aiven Data Cloud Solutions

According to IDC, Aiven enables your teams to perform more efficiently, reduce direct infrastructure costs, and provide improved database performance, agility and scalability.

Find out how Aiven makes teams 48% more efficient, allowing staff to focus on high-value activities that drive real business results:

340% 3-year ROI – break even in 5 months (average)

37% lower 3-year cost of operations

78% reduction in staff time for database deployments


Download the IDC White Paper now

DOWNLOAD WHITE PAPER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
David Heath

David Heath has had a long and varied career in the IT industry having worked as a Pre-sales Network Engineer (remember Novell NetWare?), General Manager of IT&T for the TV Shopping Network, as a Technical manager in the Biometrics industry, and as a Technical Trainer and Instructional Designer in the industrial control sector. In all aspects, security has been a driving focus. Throughout his career, David has sought to inform and educate people and has done that through his writings and in more formal educational environments.

Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown:

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments