Who is responsible for cyber security in the enterprise?

3 min read

Uncertainty is widespread across companies over who takes the lead on cyber security, according to Willis Towers Watson

Different organisations place the responsibility of cyber security at the feet of different roles. This depends on the type of organisation, its culture and size.

This idea is confirmed by a Global Economist Intelligence Unit survey, sponsored by Willis Towers Watson, which found that there is a variety of approaches on how leadership implements cyber resiliency across their organisations.

Stronger communication and collaboration is needed across all various cyber security functions and practices, including between the board and the CTO or CISO.

With the increase of more stringent data regulations – like GDPR and California Consumer Privacy Act – and the widespread media coverage of data breaches, the impetus on cyber security has never been so high. Poor security practice will now inevitably lead to a breach, which will in turn cause financial loss and reputational damage. Corporate heads will also roll.

The problem is that the majority of executives around the world feel they face a “specialist-generalist” dilemma as to whom leads on cyber resiliency, according to the survey from Willis Towers Watson. This is because, the challenge of security is company-wide, but whoever is in charge of it needs specific, up-to-date cyber training. Are these business-focused, cyber-savvy, “specialist-generalist” individuals in short supply?

Ultimately, there is a huge disparity across organisations as to who should be responsible for cyber security. The survey of over 450 companies found that almost 40% of executives felt that the board should oversee cyber, compared with 24% who felt it should be the role of a specialised cyber committee. This would presumably be overseen by the CTO or CISO. A small portion of respondents surveyed believed it should be the responsibility of audit, risk or some other subgroup.

“When you dig into the details of a breach you will find warnings from the information security team well before the problem is finally exposed,” said Stephen Moore, Chief Security Strategist at Exabeam. “Most of these warnings are ignored. The real question is why is that?”

“It’s often said that security is everyone’s responsibility and academically the CISO has the authority, both are lies. Organisationally, we should worry less about responsibility and more about barriers to success. The responsible owner is the person or team who can best enact the qualified recommendations of the security team. Often the threat isn’t the adversary, it’s the lack of internal support, warnings being buried, and even the fear of outages that creates the conditions for failure.”

“Recommendations should be tied observable failures to prevent, detect, or disrupt attacks – not things like workbook-based audit findings. The ownership and delivery of cyber security in an organisation must be owned outside of the IT department.”

Tim Brown, VP of Security at SolarWinds MSP, agreed and said that cyber security isn’t the responsibility of one department.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at information-age.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.