Research reveals security lacks attention at board-level

Research reveals security lacks attention at board-level

Adam Philpott, Chief Revenue Officer at Trellix

New research from Trellix, a cybersecurity company delivering the future of extended detection and response (XDR), reveals a disconnect between cybersecurity professionals and senior management. 

Despite widespread board-level ownership of cyber-risk, almost half (42%) of UAE cybersecurity professionals say the board doesn’t pay sufficient attention to digital security. This points to a concerning trend that cybersecurity is being treated as a tick-box exercise.

In the UAE, a huge majority (89%) of cybersecurity professionals agree that there is a well-defined ownership of cyber-risk at the board and management level, whether that sits with one individual (38%) or a committee/taskforce (51%). Yet, about a quarter (26%) of respondents highlighted that cybersecurity is not being considered a priority by C-suite/board level which has become a significant challenge for the business.

With ownership not equating to prioritisation in cyberspace, it’s no surprise that 44% of UAE cyber professionals call out feeling undervalued by their business and 36% call out feeling undervalued by their boss as two of their biggest frustrations.

“Ownership is not enough if it doesn’t translate into action. Creating a culture of cybersecurity across the organisation needs to be a priority on the board’s agenda,” said Adam Philpott, Chief Revenue Officer at Trellix. “The tone from the top must be conducive to robust cybersecurity management and so the board and cybersecurity experts need to find a common data language to understand and discuss cyber-risks, how to manage them and the board’s role in prioritising a strong security posture across the business.”

Fortunately, cybersecurity conversations are taking place in an organisation, with little over two-thirds (67%) confirming that regular discussions on cybersecurity and compliance are held with management and the senior leadership team. Cyber-resilience comes from collaboration and communication, yet these vary from business to business when a significant cybersecurity incident or cyberattack occurs. 

For example, while a third (34%) of UAE cybersecurity professionals confirm that it is typically reported to the board within one hour, 19% admit it takes at least a couple of days or longer to report it to senior management. This delay can mean the difference between successfully mitigating an attack and being faced with difficult consequences.

“As a CISO, CIO or CTO, this means clearly setting out what the top cybersecurity risks for the organisation are and the business impact if the organisation’s cybersecurity architecture is not fit-for-purpose to defend against sophisticated and evolving attacks,” added Philpott. 

“Clear communication is vital to creating a resilient organisation with adaptive security through an interconnected XDR architecture which is able to give the board – and wider business – confidence.”

Browse our latest issue

Intelligent CISO

View Magazine Archive