Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

6/22/2017
02:00 PM
Tony Buffomante
Tony Buffomante
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

KPMG: Cybersecurity Has Reached a ‘Tipping Point’ from Tech to CEO Business Issue

Still, a majority of US-based chief execs say they will be maintaining and not investing in security technology over the next three years, a recent study shows.

Generally, cybersecurity is thought of as a defensive strategy. Companies build defenses based on known vulnerabilities for future attacks and leverage forensic technology for clean-up in the wake of a breach. While defense is one hallmark of a sound cyber strategy, can cybersecurity be used offensively? Can we flip the old sports adage into "the best defense is a good offense?"

KPMG recently released our 2017 CEO Outlook Study of 400 US chief executives, which offers a roadmap of the three-year outlook of CEOs across the country. Take a dive into the report’s cybersecurity section and you’ll find an interesting statistic: 76% percent of US CEOs see investment in cybersecurity as an opportunity to innovate and find new revenue streams.

This statistic directly parallels insights that we derived from our 2016 KPMG Consumer Loss Barometer. We found that consumers would be more loyal and more likely to do business with a company that is more transparent about its cybersecurity offerings and provides clear communications about how the consumer would be protected, how consumers could better educate themselves on protecting their data/PII, and how the company would remediate any problems in the wake of a hack.

This means the tipping point of cybersecurity as a technology issue into a business issue has happened, both at the business/executive level as well as the consumer level.

So with more than two-thirds of CEOs saying that an investment in cybersecurity will open more doors to new business and innovation, how many of those CEOs are investing in cybersecurity in the next three years? Shockingly enough, the majority (44%) of CEOs say they will not be investing, or only maintaining their current investment in security technologies during this time. Even though 32% of CEOs state that they would be significantly investing in cyber security in the next three years, the majority won’t.

The response begets the question: Why would CEOs say that they know investing in cybersecurity will drive business by investing and then not invest? A few possible reasons come to mind:

  • They invest in cybersecurity as part of their new design/build so it doesn’t look like a new and different cyber program while the cyber component is actually being addressed.
  • They are not yet investing because they think maintenance of their programs (that they just spent several years hyperinvesting into) is all that is required.
  • They are just missing the boat.

Obviously, there is no one-size fits all rational for this behavior because every company faces different problems. The good news is that we can now envision a future where cybersecurity will drive business growth, where security will be baked in on the front end of the product lifecycle, and where marketing campaigns will tout cybersecurity capabilities as one of the main drivers of the product.

Based on the no-room-for-error environment that these companies operate in, I see about 32% of those companies thriving and 44% scrambling to catch up.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Related Content:

Tony Buffomante is the US cyber security services leader for KPMG based in Chicago. Over the past 16 years, he has managed and executed Information Technology (IT) security, audit and control reviews and implementations for some of the largest companies in the United States, ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
6/27/2017 | 11:18:52 AM
Methodology?
>  our 2016 KPMG Consumer Loss Barometer. We found that consumers would be more loyal and more likely to do business with a company

Can you shed some light on the methodology here? Was customer loyalty measured objectively over time across a sufficient sample size of various organizations -- one set of these organizations engaging in these methods, the other acting as a control? Or were customers merely surveyed as to their preferences and to speculate as to how they would behave in certain circumstances?
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industry’s conventional wisdom. Here’s a look at what they’re thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16863
PUBLISHED: 2019-11-14
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
CVE-2019-18949
PUBLISHED: 2019-11-14
SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.
CVE-2011-1930
PUBLISHED: 2019-11-14
In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.
CVE-2011-1145
PUBLISHED: 2019-11-14
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2011-1488
PUBLISHED: 2019-11-14
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service via a sequence of repeated log messages sent withi...