70% of CISOs worry their org is at risk of a material cyber attack
- Reference: 1716471007
- News link: https://www.theregister.co.uk/2024/05/23/cisco_survey_2024/
- Source link:
This is compared to 68 percent the year prior, and 48 percent in 2022. Additionally, nearly a third (31 percent) believe a significant attack is "very likely," compared to 25 percent in 2023.
For its annual [1]Voice of the CISO report , Proofpoint polled CISOs from organizations with at least 1,000 employees across 16 countries: The US, Canada, UK, France, Germany, Italy, Spain, Sweden, the Netherlands, UAE, Saudi Arabia, Australia, Japan, Singapore, South Korea, and Brazil. Research firm Censuswide conducted the survey between January 20 and February 2, and interviewed 100 CISOs in each country, we're told.
[2]
Of those surveyed, we'd assume that CISOs in South Korea (91 percent), Canada (90 percent) and the US (87 percent) get the least sleep each night, as these are the three top percentages of chief infosec officers who are concerned about experiencing a material cyber attack.
[3]
[4]
Very closely tied to these worries: 43 percent report that their org is unprepared for an attack, which is at least an improvement on 61 percent last year.
Their reasons for sleeplessness were many. Forty-one percent of those surveyed rated [5]ransomware as the top threat over the next 12 months, followed by malware (38 percent), email fraud (36 percent), cloud account compromise (34 percent), insider threats (30 percent) and distributed denial of service attacks (30 percent).
[6]
In the case of a ransomware infection, 62 percent of CISOs revealed they would likely [7]pay to restore systems and/or prevent attackers from leaking stolen data. This remains the same as last year's survey – and comes amid [8]ongoing indicators that paying extortionists doesn't prevent sensitive information from being released.
As your humble vulture scoured this 2024 survey, she couldn't help but wonder: Why would anyone want this job?
And it appears that many CISOs feel this way, too – despite a short section on "encouraging trends" that Proofpoint has observed since it first started producing this annual report in 2021.
[9]
These include: "An increase in cyber security representation at the board level," along with "closer alignment between CISOs and board members" and a "growing acceptance of the need for human-centric security strategies."
Yay for encouraging trends.
[10]Canada's London Drugs confirms ransomware attack after LockBit demands $25M
[11]Confused by the SEC's IT security breach reporting rules? Read this
[12]SolarWinds slams SEC lawsuit against it as 'unprecedented' victim blaming
[13]AWS CISO tells The Reg: In the AI gold rush, folks are forgetting application security
However, also since 2021 a growing number of CISOs have lamented that there are "excessive expectations" put on them and chief security officers. This year, 66 percent of those surveyed cited unrealistic expectations, compared to 61 percent last year, 49 percent in 2022 and 21 percent in 2021.
More than half (53 percent) told the survey they have either personally experienced, or at least witnessed, burnout over the past 12 months.
Some of this can be attributed to high-profile legal battles involving CISOs and holding them accountable for companies' data breaches.
This included last year's [14]SEC charges against SolarWinds and its CISO Tim Brown – essentially accusing him of not doing his job ahead of the 2020 supply chain attack.
"With incidents like these top of mind, 66 percent of global CISOs are concerned about personal, financial and legal liability in their role," the report says, noting that figure is only slightly higher (62 percent) than last year. ®
Get our [15]Tech Resources
[1] https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zk9oLxcu22yZfvU05E1MkgAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk9oLxcu22yZfvU05E1MkgAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk9oLxcu22yZfvU05E1MkgAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2024/05/22/london_drugs_ransomware/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk9oLxcu22yZfvU05E1MkgAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/04/30/unitedhealth_ceo_ransom/
[8] https://www.theregister.com/2024/05/08/unitedhealths_egregious_negligence/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk9oLxcu22yZfvU05E1MkgAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2024/05/22/london_drugs_ransomware/
[11] https://www.theregister.com/2024/05/22/sec_cybersecurity_disclosure_clarification/
[12] https://www.theregister.com/2024/01/29/solarwinds_sec_lawsuit/
[13] https://www.theregister.com/2024/05/13/aws_ciso_ai_security/
[14] https://www.theregister.com/2024/01/29/solarwinds_sec_lawsuit/
[15] https://whitepapers.theregister.com/
"personal, financial and legal liability in their role"
That adds a frightening prospect to working in this field. Not only could you be fired if the scumbags gain access to the systems, you could also be facing fines and legal action by the authorities, maybe even prison time? Sounds like you need personal liability insurance as you would if you are surgeon etc. Wonder if it would even pay out though if the state imposed fines/punishment for perceived negligence? No wonder there is a high burnout in the field. Surprising anyone would want the job.
Its a similar huge liability in Digital Forensics around CSAM. Don't handle that poison correctly and you will be charged with possession and with the current laws as they stand convicted.
And the other 30%
70% of CISOs worry their org is at risk of a material cyber attack
The other 30% reckon they can be in Brazil along with a large chunk of the company pension plan assets in roughly 16 hours from the start of the cyber attack. There's more than one approach to dealing with this problem.
This is normal
Two thirds worry but one third are not worrying so that's how hacking moves ahead in today's world. These numbers don't make it happen, that's just the odds these days, unfortunately even if everyone is worried it doesn't prevent hacking from happening most of the time.