News: 1643891105

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Execs keep flinging money at us instead of understanding security, moan infosec pros

(2022/02/03)


Fresh from years of complaining about underfunding and not having enough staff to deal with problems, infosec bods are now complaining that corporate execs merely firehose cash at them without getting their own hands dirty or engaging with the problem.

That's one conclusion that could be drawn from a Trend Micro study published yesterday. Around half of businesses surveyed are spending more on "cyber attacks" than they used to, it said, while a similar number reckon their C-suites don't know what "cyber risk management" means – possibly something about ensuring monitors are firmly bolted to desks.

"Low C-suite engagement combined with increased investment suggests a tendency to 'throw money' at the problem rather than develop an understanding of the cybersecurity challenges and invest appropriately," intoned Trend Micro.

[1]

The firm's survey of 5,000 "IT and business decision makers" from companies with more than 250 employees concluded that clueless captains of industry were still a problem, no matter how much money they threw at the IT security department.

[2]

[3]

"Most (77 per cent) want to hold more people in the organization responsible for managing and mitigating these risks, which would help to drive an enterprise-wide culture of 'security by design'." said Trend, adding that 38 per cent of respondents wanted the CEO's neck to be on the block for security failures.

While the notion that cybersecurity or even the wider IT department is overflowing with cash might seem a bit fanciful in many organisations, there's a serious point to be made about non-IT execs' awareness of today's risks.

[4]Google's VirusTotal reports that 95% of ransomware spotted targets Windows

[5]Who should be responsible for IT security?

[6]SolarWinds: Hey, only as many as 18,000 customers installed backdoored software linked to US govt hacks

[7]Business top brass are terrified their companies will simply be collateral damage in a future cyber-war

A couple of years ago Bitdefender found that just over a fifth of C-suite people lumped with the cyber security portfolio thought it was one of [8]the most challenging topics for their peers to take seriously. At the time the nation state cyber threat to ordinary domestic organisations seemed like overblown marketing FUD; [9]events at SolarWinds later that same year proved otherwise.

And then there's the indiscriminate, all-pervasive threat of a ransomware attack – especially if [10]yours is a Windows shop .

[11]

Back in the mid-2010s wider IT industry thinking was that there needed to be [12]a C-suite champion for security , rather than the CIO or CISO reporting upwards to actual executives. Now we've begun reaching that point perhaps what the world needs is for every C-suiter to think of security for their area of the business, not just whoever's had it dumped in their lap. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YfwKNRXK7Cl0Kg5VHjds-QAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfwKNRXK7Cl0Kg5VHjds-QAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YfwKNRXK7Cl0Kg5VHjds-QAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/10/14/googles_virustotal_malware/

[5] https://www.theregister.com/2015/08/18/responsibility_for_it_security/

[6] https://www.theregister.com/2020/12/15/solar_winds_update/

[7] https://www.theregister.com/2020/09/30/cyber_war_fears/

[8] https://www.theregister.com/2020/09/30/cyber_war_fears/

[9] https://www.theregister.com/2020/12/15/solar_winds_update/

[10] https://www.theregister.com/2021/10/14/googles_virustotal_malware/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfwKNRXK7Cl0Kg5VHjds-QAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2015/08/18/responsibility_for_it_security/

[13] https://whitepapers.theregister.com/



Brewster's Angle Grinder

KPI: [1]Nuts!

[1] https://www.theguardian.com/business/2022/feb/03/shortage-of-kp-nuts-and-hula-hoops-looms-after-cyber-attack

I get it though

emfiliane

Being handed £10 million and told "fix this problem, or your department's fired and we'll replace you with Accenture or Autonomy or you know one of those names," but also not being allowed to slap executive crybabies when they want to respond to their favorite 419er and read employees' mail. There's no amount of money the problem can shovel at the problem to fix it.

Re: I get it though

badflorist

Collective bargaining. When you're stuck between putting yourself at risk for doing the job or blackmailing the execs... collective bargaining.

Of course being threatened to do you job with a lump of cash isn't the worst threat. Just makes sure when your project is finally successful that you put the names that matter under a bright company wide statement, and the names that don't help in the exact same bright light.

"Thanks to Sarah's genius at cracking the problem while Steve applied the appropriate logic in a timely manner, with the help of clean working conditions maintained by the janitorial staff, nobody was hindered by Frank's faulty but extremely considerate corporate directive and thus we met our goal of XYZ."

msobkow

"...adding that 38 per cent of respondents wanted the CEO's neck to be on the block for security failures."

That is a nice sentiment, but management never takes responsibility for anything except a rising stock price or market share. They are a revolting creature, designed to collect glory and pay while downloading any and all responsibilities and efforts to the peons (as they think of the staff.) Note that they are talking "large" operations, not mom & pop shops where there are still human beings with ethics running the businesses, not hired zuits.

dafe

Liquidating BitCoins to pay off drive-by ransomware incurs a substantial opportunity cost. Throwing money at redundant arrays of inexpensive disks solves that problem at a fraction of the cost. Especially if the RAID is in The Cloud.

OpSec? That's in Morocco, isn't it?

Ah...."executives"......but what about their customers?

Anonymous Coward

Isn't it curious that this report makes ABSOLUTELY NO MENTION of the impact of security breaches on the customers of these "corporations"?

Take the Equifax hack.....which allegedly affected 143 million people......

....and all we get here is the useless opinions of of '...5,000 "IT and business decision makers" '......

....and that's JUST ONE HACK!!!!

Millions of people are put at risk.......and 5000 "executives" complain about "too much money coming their way".....

Am I missing something here?

Being Ymor's right-hand man was like being gently flogged to death with
scented bootlaces.
-- Terry Pratchett, "The Colour of Magic"