Share this article
It is one of the toughest jobs in the business world today: no wonder finding top class individuals to fill the role of Chief Information Security Officer (CISO) has long been a challenge. But as 2021 unfolds and the extent of the Covid-accelerated digital transformation becomes apparent, the challenges for CISOs are stacking up and the job just became a whole lot harder.
With more businesses migrating to the Cloud and remote-working becoming a viable longer-term option for many, the task of managing cyber security across networks and systems has never been more challenging. And, as we roll on into 2021 and technology continues to be the glue that holds a geographically-spread organisation together, CISOs will undoubtedly come under greater scrutiny than ever.
Statistics from the US reveal that home networks are 7.5 times more likely to have at least five distinct families of malware. In addition, more than 25% of all devices have one or more services exposed on the Internet. Ensuring home office networks are secure is therefore a priority going forward. One of the key tasks for any CISO in 2021 is to make a strong case for investment in additional security to protect against breaches, viruses, ransomware and DDoS attacks. This may include additional firewalls, endpoint security and the setting up of Virtual Private Networks, if one is not already in place.
In addition, more organisations will be looking to build information security into all aspects of their operations – from organisational structure and company policies, to processes and CRM. CISOs will be required to have relevant top-level skills in this area, including a good knowledge of security hardware and software, analysis of organisational needs, and the ability to manage cybersecurity risks in the context of organisational policies and industry standards.
With the broader Business Continuity Plan, organisations must have a robust Incident Response Plan (IRP) in place. This has been in the CISO’s remit for some time, but as businesses increasingly move to remote working models, rely on new technologies within the Cloud and incorporate the Internet of Things into their organisation, existing IRPs will need to evolve constantly.
Perhaps the greatest challenge faced by CISOs is getting the rest of the C-Suite behind what they are doing and provide adequate budget. A CISO who can convey risk clearly and provide the board with a suitable overview of the consequences of not taking proactive steps, will command the attention of the rest of the C-Suite better than one who talks purely in technical terms.
BT Security recently carried out a survey of over 7,000 business leaders, employees, and consumers from around the world. The survey identified that the role of CISO is expanding in both scope and responsibilities, particularly as cybersecurity becomes a top priority for businesses adapting to remote working. Yet fewer than half of executives and respondents could name their CISO or equivalent, and a similar number said that their CISO does not actively engage with the rest of the organisation.
Communication is, however, not just a matter of being seen. It is about being heard. To facilitate genuinely good communication, the CISO needs to be skilled at explaining exactly what the threat landscape looks like and put a financial perspective on that risk.
Cynet announced the findings of a new survey titled “2021 CISO Survey of Small Cyber Security Teams” which examined the issues facing CISOs in companies employing 500 – 10,000 people. It found that 47% of CISOs thought their teams lacked the security skills to protect against cyberattacks. To add to the problem, there is also the issue of the global shortage of skilled practitioners with the experience and expertise required. It is not surprising therefore that 56% now outsource some aspects of the function and fill staffing gaps by engaging with an expert professional team.
At SRM we understand that finding the right Chief Information Security Officer can be a significant challenge for organisations – particularly in smaller enterprises where finances may be tight. We also know that many in-house CISOs lack the resource or support they would ideally require to implement proactive changes and improvements, which is why our Virtual CISO service can be the perfect solution.
From facilitating engagement at board level to the practical execution of plans, tests and training, SRM’s team of senior IS consultants can take both a leading or supporting role in helping to improve risk posture and create a more resilient organisation.
To find out more about how we can help organisations tackle the challenges for CISOs, why not get in touch with SRM today?