Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
10/19/2017
09:00 AM
Mike Convertino
Mike Convertino
Partner Perspectives
Connect Directly
LinkedIn
RSS
100%
0%

CISOs: Striving Toward Proactive Security Strategies

A new survey paints a compelling picture of the modern security executive, how they succeed, and how much power they wield.

Chief Information Security Officers are in a tough spot. Organizations are squeezed by cyber criminals, new compliance requirements, and bleeding-edge technologies that erode privacy and stability. The team that leads defense efforts is becoming a more and more vital player in the long-term survival of any organization that sells, uses, or produces information technology — that is to say, everyone. But what do we really know about CISOs and how they operate?

Many surveys talk about CISO salaries and job prospects, but we felt that the industry as a whole needed to fully understand what goes into the day-to-day job of a CISO. F5 and research firm Ponemon teamed to directly survey CISOs. Our goal: to draw as complete a picture as we could on the modern security executive. In the report, "The Evolving Role of CISOS and Their Importance to the Business," we focus on key areas like budgetary control, organizational influence, decision rationale, and strategic methodology. In other words, how do CISOs succeed, and how much power do they wield? We also delve into the background of CISOs and their experience, both in terms of technical capability and business savvy.

To cast a wide net, we interviewed senior level IT security professionals from 184 organizations in seven countries, tracking nearly 70 questions. We wanted a deep, unbiased look at the contemporary CISO. The results are eye-opening, and both encouraging and worrisome.

First, the discouraging news: security programs appear to be reactive: 60% of respondents say material data breaches and cybersecurity exploits are the primary drivers of change in security programs. A mere 22% of respondents say their organizations’ security function is integrated with other business functions. Perhaps most concerning, only 51% say their organization has an IT security strategy and, of those, only 43% say that the company strategy is reviewed, approved, and supported by C-level executives.

Now the is good news. A full 77% of respondents say their IT security operations are aligned with IT operations, although fewer respondents (60%) say they have achieved alignment of IT security operations with business objectives.

Furthermore, there are some promising trends in the day-to-day responsibilities CISOs hold. Most CISOs (67%) believe they should be responsible for setting security strategy, and the majority are influential in managing their companies’ cybersecurity risks, with 65% reporting to senior executives (meaning, no more than three steps below the CEO on the organization chart). Over half (61%) set the security mission and are responsible for informing the organization about new threats, technologies, practices, and compliance requirements (60%). In the event of a serious security incident, more than half (60%) have a direct channel to the CEO.

These findings indicate both the challenges and the progress CISOs are making in today’s complex environment. I invite you to reflect on and discuss these findings with your peers and in the comment section below. My hope is that we now have a foundation for more meaningful conversations with one another, and have a greater impact on our organizations. I also hope the broader discussions we are driving here at F5 Labs are providing CISOs and future CISOs the tools to tackle this challenge.

There's a lot there. You can read the full report here

Get the latest application threat intelligence from F5 Labs.

Mike Convertino has nearly 30 years of experience in providing enterprise-level information security, cloud-grade information systems solutions, and advanced cyber capability development. His professional experience spans security leadership and product development at a wide ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Now, we come here to play Paw-ke Man Go!"
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6497
PUBLISHED: 2019-01-20
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.
CVE-2018-18908
PUBLISHED: 2019-01-20
The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) attacks, whereby an attacker would be able to obtain the data sent in these requests. Some of the requ...
CVE-2019-6496
PUBLISHED: 2019-01-20
The ThreadX-based firmware on Marvell Avastar Wi-Fi devices allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of...
CVE-2019-3773
PUBLISHED: 2019-01-18
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
CVE-2019-3774
PUBLISHED: 2019-01-18
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.