{"id":5001,"date":"2024-08-23T09:00:00","date_gmt":"2024-08-23T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service"},"modified":"2024-08-23T09:00:00","modified_gmt":"2024-08-23T14:00:00","slug":"c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/23\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service\/","title":{"rendered":"C-Suite Involvement in Cybersecurity Is Little More Than Lip Service"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7b2967b5a57dd953\/66c88389cba99c1ef72d44b7\/C-suite%281800%29_Iulian_Dragomir_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">No organization is immune to today&#8217;s looming cybersecurity threats. Whether a large enterprise or a small business, building proactive defenses is critical to day-to-day functions. It&#8217;s just as essential to manage cyber-risks as it is to manage other business risks, since successful attackers have the power to financially cripple businesses, damage reputation, and affect continuity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Amid today&#8217;s rising threats \u2014 from ransomware and data breaches to the impact of geopolitical and nation-state threats \u2014 true cyber preparedness requires the right internal collaboration and tools to bolster business resilience. The responsibility for managing cyber-risk is a collective effort, and everyone plays a role \u2014 especially the C-suite.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/hop.extrahop.com\/resources\/papers\/global-cyber-confidence-index-2024\/\" rel=\"noopener\">new report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from ExtraHop&nbsp;found that while four in 10 US organizations look to their executive management team to help assess their cyber-risk exposure, only one-fifth feel there is a high level of involvement and commitment from the C-suite. This raises the question: Are industrywide claims of cybersecurity as a board-level discussion little more than lip service to stakeholders?<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Lessons Learned From Previous Attacks\">Lessons Learned From Previous Attacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This information illustrates a worrying trend, especially as regulators are holding the C-suite accountable for data breaches. We saw this in action as the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\" rel=\"noopener\">SEC charged SolarWinds&#8217; chief information security officer (CISO)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;with fraud and internal control failures following a two-year-long cyberattack. And the recent hearings on the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/round-2-change-healthcare-targeted-second-ransomware-attack\" rel=\"noopener\">Change Healthcare ransomware attack<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;also exposed the burden placed on the CEO role, setting a precedent for these leaders to be questioned in-depth by the senate on wide-reaching cyber incidents.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Taking what we&#8217;ve learned from infamous, large-scale attacks and the resulting fallout, we can justify the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">real <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">problem affecting major companies, the C-suite and board, and security teams: overconfidence. The report found that a vast majority of IT decision-makers (88%) feel confident about their organization&#8217;s ability to manage cyber-risk. Yet, the findings show that this isn&#8217;t the case \u2014 many are ill-prepared to do so, and there&#8217;s a lack of direction and attention from the C-suite, which is contributing to the problem.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Take ransomware, for example: Despite their confidence, more than half (58%) of respondents experienced more than six ransomware incidents in the past year alone, while 40% experienced 10 or more. To highlight the points of failure, 51% claim more than half of their organization&#8217;s cyber incidents are related to poor cyber hygiene. Half of all organizations surveyed admitted to running at least one insecure network protocol that threat actors are known to exploit. A lack of preparedness and ability to reveal cyber-risk can play a significant role in the ransomware uptick we&#8217;re seeing globally.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cyber Preparedness Calls for Better Internal Alignment\">Cyber Preparedness Calls for Better Internal Alignment<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the same report, 15% of respondents cited a lack of alignment between the business and cybersecurity as the most significant barrier to managing risk, reflected in nearly a quarter of respondents indicating that they&#8217;d need a 26% to 50% increase in budget to mitigate threats effectively.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The disconnect between business plans and cybersecurity needs suggests that organizations must take cybersecurity more seriously. Leadership involvement is critical when it comes to meeting regulatory requirements, and prioritizing cyber-risk management across the leadership bench helps security and IT teams make better decisions and provide direction during an incident. Making cybersecurity a core company value, where the C-suite prioritizes time and investments in security solutions, is crucial.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Making cyber-risk management a staple topic during planning meetings and within the boardroom affirms alignment across the organization. It also ensures that cybersecurity fits into all strategic initiatives. At a basic level, this means establishing better cyber hygiene across all employees, security solutions, and workflows. The C-suite must lead by example and provide the resources and training necessary for all employees \u2014 not just security and IT teams \u2014 to understand their own personal security&#8217;s impact on the organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As it comes to investing in tools, C-suites should allow a budget for various methods to assess cyber-risk and ensure all stakeholders are involved. These include tools such as penetration testing, red-team exercises, and threat modeling assessments. In addition, having full network visibility can help detect and stop attacks in the early stages \u2014 long before threat actors can achieve their objectives and cause harm to an organization.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Successful Integration of Cybersecurity in Executive Strategies\">Successful Integration of Cybersecurity in Executive Strategies<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, what happens when cybersecurity becomes a key component of the C-suite and board&#8217;s day-to-day priorities? Several organizations have demonstrated exemplary integration of cybersecurity into their executive strategies, setting benchmarks for others to follow. One notable example is JPMorgan Chase, which significantly bolstered its cybersecurity defenses following&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cnn.com\/2024\/01\/17\/investing\/jpmorgan-fights-off-45-billion-hacking-attempts-each-day\/index.html\" rel=\"noopener\">high-profile breaches in the financial sector<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The company&#8217;s CEO, Jamie Dimon, took a proactive stance by prioritizing cybersecurity as a core business concern. JPMorgan Chase invested more than $600 million annually in cybersecurity, employed more than 3,000 IT security professionals, and established a dedicated cybersecurity operations center. This comprehensive approach, driven by top-level leadership, ensured robust protection against evolving threats and underscored the critical importance of executive involvement in cybersecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another example is Equifax, which undertook a significant transformation following its&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/7-takeaways-from-the-equifax-data-breach\" rel=\"noopener\">2017 data breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The company appointed a new CEO, Mark Begor, who prioritized cybersecurity as a top business imperative. Under his leadership, Equifax invested $1.5 billion in overhauling its cybersecurity infrastructure, including the adoption of advanced security technologies and the creation of a new chief information security officer (CISO) role. This strategic investment and executive commitment not only enhanced Equifax&#8217;s security posture but also restored trust with stakeholders and positioned the company as a leader in cybersecurity resilience.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">No organization wants to be the next Change Healthcare or SolarWinds. As an industry, the C-suite and organizational leaders hold the power when it comes to establishing companywide precautionary measures and defenses. Collaboration with security teams, making cybersecurity a core principle of business strategy, and investing in defenses ultimately better positions organizations to thwart threats and ensure business continuity.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY No organization is immune to today&#8217;s looming cybersecurity threats.<\/p>\n","protected":false},"author":12,"featured_media":5002,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5001","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/c-suite-involvement-in-cybersecurity-is-little-more-than-lip-service.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5001","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5001"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5001\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5002"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5001"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5001"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5001"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}