Threat Intelligence

7/17/2018
04:20 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

One-Third of Businesses Lack a Cybersecurity Expert

Alarming, yes, but it's actually an improvement over past years, a new Gartner survey of more than 3,000 CIOs reveals.

A survey of more than 3,000 CIOs found 95% of technology leaders expect cybersecurity threats to grow – but only 65% have a cybersecurity expert on staff, Gartner researchers report.

The "2018 CIO Agenda Survey" polled 3,160 CIOs across 98 countries and several major industries, which collectively represent $13 trillion in revenue and public-sector budgets, and $277 billion in IT spending. Despite the investments, security is a prime concern.

Gartner research director Rob McMillan and principal research analyst Sam Olyaei compiled the study of CIO perspectives. While this survey is conducted annually, this is the first time participants were polled on whether they have a dedicated cybersecurity pro on staff.

"I think it's alarming to point out that one-third don't have a dedicated resource," Olyaei tells Dark Reading. The researchers didn't ask about specific experts for different security functions; they wanted to know whether organizations had a security expert at all.

However, he explains, it's important to note that 65% is a "huge increase" over what the data has shown in previous years. Olyaei attributes the rise to new regulations dictating companies must have a security person on staff. The New York Department of Financial Services, for example, introduced a rule stating financial organizations must have security personnel.

There are a few reasons why businesses don't have security experts, and they primarily relate to culture, cost, and complex skill sets. In many industries, cybersecurity is still not given much scrutiny and falls under the responsibility of IT or networking employees on staff. Their cultural mindset doesn't prioritize security; as a result, they feel they don't need a dedicated expert.

"Then there are certain organizations that actually look at this and say, 'We need a security expert, but we can't find one,'" Olyaei continues. "They either can't afford a certain skill set or aren't willing to spend the type of money security experts command."

How much is that? The average salary for a CISO is $250,000, he points out, and nobody really has the money to spend on a CISO unless they're a major organization like a large bank or pharmaceutical company. Smaller institutions, such as local banks or credit unions, are stuck looking for employees with the same skill sets but will work for half the pay.

Finally, the ability to handle and secure emerging technologies, such as the cloud or artificial intelligence, is scarce. Companies can't hire those employees because the tech is so new, few people have developed expertise related to it.

"Even with a blank check, those skills don't exist," Olyaei says.

While they may not be able to afford advanced cyber expertise, companies are investing more in security tech. Thirty-five percent of respondents say their organizations have already invested in, and deployed, some aspect of digital security, researchers found. An additional 36% are experimenting or planning to introduce capabilities in the short term: Gartner anticipates 60% of security budgets will support threat detection and response by 2020.

Those investing in new technologies are generally more mature respondents in financial services, Olyaei and McMillan found. They're investing in threat hunting, deception technologies, open source intelligence, and other tools they can use to scour the Dark Web to see whether they've been exposed, Olyaei says. Third-party risk management is also a popular area.

"You have to start to manage not just yourself, but your business partners, vendors, and regulators," he advises.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
Data Privacy Careers Are Helping to Close the IT Gender Gap
Dana Simberkoff, Chief Compliance and Risk Management Officer, AvePoint, Inc,  8/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12579
PUBLISHED: 2018-08-20
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attac...
CVE-2018-14020
PUBLISHED: 2018-08-20
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one tha...
CVE-2018-14023
PUBLISHED: 2018-08-20
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
CVE-2018-1394
PUBLISHED: 2018-08-20
Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.
CVE-2018-1517
PUBLISHED: 2018-08-20
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.