Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

7/17/2018
04:20 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

One-Third of Businesses Lack a Cybersecurity Expert

Alarming, yes, but it's actually an improvement over past years, a new Gartner survey of more than 3,000 CIOs reveals.

A survey of more than 3,000 CIOs found 95% of technology leaders expect cybersecurity threats to grow – but only 65% have a cybersecurity expert on staff, Gartner researchers report.

The "2018 CIO Agenda Survey" polled 3,160 CIOs across 98 countries and several major industries, which collectively represent $13 trillion in revenue and public-sector budgets, and $277 billion in IT spending. Despite the investments, security is a prime concern.

Gartner research director Rob McMillan and principal research analyst Sam Olyaei compiled the study of CIO perspectives. While this survey is conducted annually, this is the first time participants were polled on whether they have a dedicated cybersecurity pro on staff.

"I think it's alarming to point out that one-third don't have a dedicated resource," Olyaei tells Dark Reading. The researchers didn't ask about specific experts for different security functions; they wanted to know whether organizations had a security expert at all.

However, he explains, it's important to note that 65% is a "huge increase" over what the data has shown in previous years. Olyaei attributes the rise to new regulations dictating companies must have a security person on staff. The New York Department of Financial Services, for example, introduced a rule stating financial organizations must have security personnel.

There are a few reasons why businesses don't have security experts, and they primarily relate to culture, cost, and complex skill sets. In many industries, cybersecurity is still not given much scrutiny and falls under the responsibility of IT or networking employees on staff. Their cultural mindset doesn't prioritize security; as a result, they feel they don't need a dedicated expert.

"Then there are certain organizations that actually look at this and say, 'We need a security expert, but we can't find one,'" Olyaei continues. "They either can't afford a certain skill set or aren't willing to spend the type of money security experts command."

How much is that? The average salary for a CISO is $250,000, he points out, and nobody really has the money to spend on a CISO unless they're a major organization like a large bank or pharmaceutical company. Smaller institutions, such as local banks or credit unions, are stuck looking for employees with the same skill sets but will work for half the pay.

Finally, the ability to handle and secure emerging technologies, such as the cloud or artificial intelligence, is scarce. Companies can't hire those employees because the tech is so new, few people have developed expertise related to it.

"Even with a blank check, those skills don't exist," Olyaei says.

While they may not be able to afford advanced cyber expertise, companies are investing more in security tech. Thirty-five percent of respondents say their organizations have already invested in, and deployed, some aspect of digital security, researchers found. An additional 36% are experimenting or planning to introduce capabilities in the short term: Gartner anticipates 60% of security budgets will support threat detection and response by 2020.

Those investing in new technologies are generally more mature respondents in financial services, Olyaei and McMillan found. They're investing in threat hunting, deception technologies, open source intelligence, and other tools they can use to scour the Dark Web to see whether they've been exposed, Olyaei says. Third-party risk management is also a popular area.

"You have to start to manage not just yourself, but your business partners, vendors, and regulators," he advises.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
Is Zero Trust the Best Answer to the COVID-19 Lockdown?
Dan Blum, Cybersecurity & Risk Management Strategist,  5/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13616
PUBLISHED: 2020-05-26
The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
CVE-2020-13614
PUBLISHED: 2020-05-26
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
CVE-2020-13615
PUBLISHED: 2020-05-26
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
CVE-2020-9046
PUBLISHED: 2020-05-26
A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.
CVE-2020-12388
PUBLISHED: 2020-05-26
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.