'Despite pervasive 'security debt' and reporting a rising number of cyber attacks, CISOs say that say the number of incidents, which includes a breach or unauthorized access to a system, they faced remained pretty much the same,' says F-Secure's Michael Greaves, security advisor for Managed Detection and Response. 'This could be because CISOs have made the right investments. However, it is the incidents that haven't been discovered which worry us most. Because of the sophisticated nature of some of these attacks, organizations may not have the technology or people to identify they are in the middle of a compromise that, for example, may result in a ransomware deployment months down the road.'

The report covers numerous aspects of the complex dilemmas CISOs face on a daily basis, including:

· Employees are the primary attack vector, according to 71% of the CISOs interviewed, as attackers take advantage of social channels to launch more sophisticated targeted attacks.

· The top three threats CISOs and their teams face are phishing, ransomware and business email compromise (BEC).

· Securing the mobile or remote workforce, which has exploded during the pandemic, presents a number of risks, particularly where employees and devices are separated from traditional controls that could prevent their compromise.

· A vast majority of CISOs - 71% - report that their ideas about what constitutes 'good security' has evolved recently.

'Too often, cyber security is seen as 'risk mitigation' instead as a 'business enabler' by C-level executives. CISOs are tasked with overcoming that perception and their 'security debt.' To do this they must call on every ounce of their abilities, including emotional intelligence, to persuade their peers and deny attackers,' says Royce K. Markose, Chief Information Security Officer at RewardStyle.com.

The report, CISOs' New Dawn, is based on in-depth interviews with 28 CISOs from the US, UK, and other European countries. Find out more about what the attack landscape looks like according to top corporate cyber security professionals: https://blog.f-secure.com/the-cisos-dilemma/.

Read the full report here: https://www.f-secure.com/en/business/resources/an-effective-security-leader/publication.

Attachments

  • Original document
  • Permalink

Disclaimer

F-Secure Oyj published this content on 15 April 2021 and is solely responsible for the information contained therein. Distributed by Public, unedited and unaltered, on 15 April 2021 08:10:09 UTC.