Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/17/2018
04:20 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

One-Third of Businesses Lack a Cybersecurity Expert

Alarming, yes, but it's actually an improvement over past years, a new Gartner survey of more than 3,000 CIOs reveals.

A survey of more than 3,000 CIOs found 95% of technology leaders expect cybersecurity threats to grow – but only 65% have a cybersecurity expert on staff, Gartner researchers report.

The "2018 CIO Agenda Survey" polled 3,160 CIOs across 98 countries and several major industries, which collectively represent $13 trillion in revenue and public-sector budgets, and $277 billion in IT spending. Despite the investments, security is a prime concern.

Gartner research director Rob McMillan and principal research analyst Sam Olyaei compiled the study of CIO perspectives. While this survey is conducted annually, this is the first time participants were polled on whether they have a dedicated cybersecurity pro on staff.

"I think it's alarming to point out that one-third don't have a dedicated resource," Olyaei tells Dark Reading. The researchers didn't ask about specific experts for different security functions; they wanted to know whether organizations had a security expert at all.

However, he explains, it's important to note that 65% is a "huge increase" over what the data has shown in previous years. Olyaei attributes the rise to new regulations dictating companies must have a security person on staff. The New York Department of Financial Services, for example, introduced a rule stating financial organizations must have security personnel.

There are a few reasons why businesses don't have security experts, and they primarily relate to culture, cost, and complex skill sets. In many industries, cybersecurity is still not given much scrutiny and falls under the responsibility of IT or networking employees on staff. Their cultural mindset doesn't prioritize security; as a result, they feel they don't need a dedicated expert.

"Then there are certain organizations that actually look at this and say, 'We need a security expert, but we can't find one,'" Olyaei continues. "They either can't afford a certain skill set or aren't willing to spend the type of money security experts command."

How much is that? The average salary for a CISO is $250,000, he points out, and nobody really has the money to spend on a CISO unless they're a major organization like a large bank or pharmaceutical company. Smaller institutions, such as local banks or credit unions, are stuck looking for employees with the same skill sets but will work for half the pay.

Finally, the ability to handle and secure emerging technologies, such as the cloud or artificial intelligence, is scarce. Companies can't hire those employees because the tech is so new, few people have developed expertise related to it.

"Even with a blank check, those skills don't exist," Olyaei says.

While they may not be able to afford advanced cyber expertise, companies are investing more in security tech. Thirty-five percent of respondents say their organizations have already invested in, and deployed, some aspect of digital security, researchers found. An additional 36% are experimenting or planning to introduce capabilities in the short term: Gartner anticipates 60% of security budgets will support threat detection and response by 2020.

Those investing in new technologies are generally more mature respondents in financial services, Olyaei and McMillan found. They're investing in threat hunting, deception technologies, open source intelligence, and other tools they can use to scour the Dark Web to see whether they've been exposed, Olyaei says. Third-party risk management is also a popular area.

"You have to start to manage not just yourself, but your business partners, vendors, and regulators," he advises.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Zero Trust doesn't have to break your budget!
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31476
PUBLISHED: 2021-06-16
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the han...
CVE-2021-31477
PUBLISHED: 2021-06-16
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and filesystem contain hard-...
CVE-2021-32690
PUBLISHED: 2021-06-16
Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This...
CVE-2021-32691
PUBLISHED: 2021-06-16
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within th...
CVE-2021-32243
PUBLISHED: 2021-06-16
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).