Companies still lump cybersecurity into IT budget

The vast majority (89 per cent) of chief information security officers (CISO) are regularly summoned by the board of directors to provide recommendations for the business. This is a key finding from the latest global survey of information security heads commissioned by Kaspersky. The study also revealed that despite a ‘direct line’ with top bosses, it does not necessarily result in dedicated investments in security. In fact, 54 per cent of respondents admit having to share their organisation’s IT budget.

 In Q3 of 2019, 451 Research conducted an independent study, commissioned by Kaspersky, to explore the various factors shaping information security from the perspectives of enterprise security leaders. The study surveyed 305 respondents that have senior or executive responsibility for cybersecurity in enterprises worldwide, with the findings revealing how the nature of cybersecurity and security leadership has evolved.

According to the study, top management seek advice from IT security leaders regardless of the organisation’s reporting structure, with only 23 per cent reporting to the board. Business leaders need input from their CISO most often when an internal cybersecurity incident happens – as recognized by 60 per cent of respondents. However, it’s not all about breaches — executives also seem to be proactive and mindful about how to protect the company now and in the future. More than half (57 per cent) of the surveyed IT security chiefs schedule meetings with the board on a regular basis, and 56 per cent are requested to provide their expert opinions on future IT projects.

However, despite being visible and valuable to the board, CISOs still face difficulties when it comes to justifying necessary spending on IT security. Having to siphon their expenses from the broader IT budget, 43 per cent of those surveyed feel that they are in direct competition with other business and IT initiatives, making it one of the top three challenges they face in order to make the case for essential information security investment.

“As the study shows, boards of directors now understand that cybersecurity is an important part of business success,” Veniamin Levtsov, VP of corporate business, at Kaspersky, said. “Nevertheless, there’s still a challenge for CISOs to be able to convert this understanding into actual support. Speaking business language instead of using technical jargon, focusing on how to solve problems and bringing in third-party expertise to justify meaningful measures are all key components to win over directors.”

 

 

Related Posts
Others have also viewed

Businesses fail to achieve highly resilient connectivity as commodity IoT providers fail to deliver

A new State of IoT Adoption report launched today by Eseye, a leading global IoT ...
automation

AI-powered computer vision enhances safety in industrial workplaces

RoboK, a startup applying AI-powered computer vision to logistics and industrial workplaces, has announced $2.1 ...
university

2m UK university and research facility credentials hacked

2.2 million personal credentials are available on the dark web stolen from the top 100 ...
disaster recovery

Disaster recovery market worth $31.6bn by 2030

The disaster recovery-as-a-service market is projected to reach $31.6bn by 2030 according to a new ...