January 3, 2018 By Rick M Robinson 2 min read

By and large, the news in 2017 was not good on the cybersecurity front. Whether you follow media headlines or industry studies, attacks are up, breaches are larger and threat actors are more sophisticated than ever. Unfortunately, many organizations fail to take basic precautions to mitigate these risks. As a result, breaches often go unreported, leaving millions of customers unaware that their personal data is exposed.

The technical challenges are growing, but technical solutions are also increasingly available. However, many of these tools go unused or unnoticed by organizations. The real issue here is cybersecurity leadership — or a lack thereof.

Staying Out of the Spotlight

CIO Insight detailed some of 2017’s most noteworthy breaches and the blunders that put those companies in a negative media spotlight. Failures at the leadership level included negligence in risk management and poor handling of incidents after they occurred. These lapses ran the gamut from embarrassing to infuriating.

For example, a cybersecurity consulting firm failed to implement basic protections on its network and took months to discover that its most confidential customer discussions were exposed. Similarly, a financial firm failed to notify millions of consumers that their data had been compromised and even endeavored to mislead them once the breach went public.

Study results may not be quite as vivid, but they are just as alarming. According to the Identity Theft Resource Center (ITRC), the total number of breaches rose 40 percent in 2016, and a midyear report by the same firm predicted another 37 percent jump by the end of 2017. Furthermore, a recent Ponemon study revealed that 56 percent of companies experienced a breach due to third-party error last year, a 7 percent increase over 2016.

At least we can conclude that false confidence is not the problem. Only 17 percent of respondents to the Ponemon survey said their organizations were effective in minimizing third-party risk, down from 22 percent a year ago. In addition, only 35 percent said they expected their third-party partners to promptly notify them of a breach. When it comes to fourth parties and beyond, that number fell to just 11 percent.

The Cybersecurity Leadership Deficit

All of these failures, CIO Insight noted, point to “a completely broken mindset and haphazard approach” to cybersecurity. This attitude is shaped from the top, if only passively, through inaction. As such, it can only be changed from the top. That’s why security leaders must help executives understand the organization’s risk posture from both a security standpoint and a business perspective. For their part, top leadership must become more involved in cybersecurity initiatives and budget accordingly.

The essential element of leadership is not in the particulars, but in active engagement with security challenges. Attackers are out there, but effective defense measures are available to help organizations protect their most sensitive data. Cybersecurity leadership consists of recognizing the dangers and taking them on, not reacting with passivity and evading responsibility.

Listen to the podcast series: Take Back Control of Your Cybersecurity now

More from CISO

CISO vs. CEO: Making a case for cybersecurity investments

4 min read - Ask CISOs why they think there is a cyber skills shortage in their organization, what keeps them up at night or what the most important issue facing the industry is — at some point, even if not the first response, they will bring up budgets.For example, at RSA Conference 2024, a roundtable discussion about issues facing the cybersecurity industry, one CISO stated bluntly that budgets — or lack thereof — are the biggest problem. At a time when everything is…

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today