{"id":34262,"date":"2019-10-14T15:16:01","date_gmt":"2019-10-14T14:16:01","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/10\/14\/thycotic-research-reveals-security-pros-struggle-to-quantify-what-success-looks-like\/"},"modified":"2019-10-15T09:07:55","modified_gmt":"2019-10-15T08:07:55","slug":"thycotic-research-reveals-security-pros-struggle-to-quantify-what-success-looks-like","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/10\/14\/thycotic-research-reveals-security-pros-struggle-to-quantify-what-success-looks-like\/","title":{"rendered":"Thycotic research reveals security pros struggle to quantify what success looks like"},"content":{"rendered":"\n<p>The vast majority of IT security professionals work to a set of Key Performance Indicators (KPIs) yet struggle to align these metrics with overall business goals, according to a new study by Thycotic, a provider of privileged access management (PAM) solutions for&nbsp;more than 10,000&nbsp;organisations&nbsp;worldwide. <\/p>\n\n\n\n<p>More than four out of five (84%) respondents have KPIs and an even higher proportion (92%) say they review security in terms of its impact on the business. Even so, nearly half (44%), say their organisation struggles to align security initiatives with the business\u2019 overall goals while more than a third (35%) aren\u2019t clear what the business goals are.<\/p>\n\n\n\n<p>Following interviews with more than 100 IT security decision makers within the UK, the research shows the most popular performance metric is to count the number of security breaches (56%) followed by time taken to resolve a breach (51%). <\/p>\n\n\n\n<p>It appears, however, these criteria may not be that useful. Around two in five (39%) say they have no way of measuring what difference past security initiatives have made to the business. Furthermore, more than a third (36%) agree it\u2019s not a priority for them to measure security success once initiatives have been rolled out.<\/p>\n\n\n\n<p><strong>Opening the purse strings<\/strong><\/p>\n\n\n\n<p>Lack of clarity around metrics has a knock-on effect when it comes to obtaining budgets to fund further IT security initiatives. When asked what makes the biggest difference to how IT security budget is allocated, nearly half of the respondents (47%) point to evidence of the success and ROI of previous security initiatives. <\/p>\n\n\n\n<p>Other strategies include benchmarking levels of security spend against the competition (37%) while talking up the fear factor remains a favourite tactic (38%). Interestingly, more than a quarter (27%) of respondents look to evidence of past success as the most important way to justify security spend.<\/p>\n\n\n\n<p><strong>Disconnected from the business<\/strong><\/p>\n\n\n\n<p>There is evidence to suggest security teams\u2019\neveryday focus on responding to immediate threats and incidents leads them to\nbecome too disconnected from the business. Over a third (36%) have no clear\nvision of how other departments measure success while 38% agree business goals\nare not communicated to them. In consequence, security professionals feel\nremoved from the rest of the business. This is reflected in their relatively low\nopinion of the impact they are making. Asked if security teams are hitting a\nhome run or \u2018just par for the course\u2019, less than one fifth (17%) feel their\nrole\/team consistently meets expectations.<\/p>\n\n\n\n<p>Commenting on the findings, Joseph Carson, Chief Security Scientist and Advisory CISO at Thycotic, said: \u201cThe reactive nature of an IT security professional\u2019s work leaves them constantly looking to past achievements to demonstrate their value \u2013 a metric that bears no correlation to the organisation\u2019s current situation or success. This disconnect inevitably puts them at disadvantage and leaves them struggling to make a positive impression with the executive board or colleagues in other departments.\u201d<\/p>\n\n\n\n<p>\u201cOne way to counter this is to create a company-wide cybersecurity program and culture,\u201d he added. \u201cOrganisations should appoint cyber ambassadors who are both technically proficient and skilled communicators to enlist cross-departmental co-operation geared to early warning of any anomalous activity. This will have the twin benefit of putting IT security on a more proactive footing and reduce the potential impact of security issues on the business.\u201d<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1355\" height=\"3932\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/10\/CISO-Metrics-Report-Infographic-03.jpg\" alt=\"\" class=\"wp-image-34328\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/10\/CISO-Metrics-Report-Infographic-03.jpg 1355w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/10\/CISO-Metrics-Report-Infographic-03-103x300.jpg 103w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/10\/CISO-Metrics-Report-Infographic-03-768x2229.jpg 768w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/10\/CISO-Metrics-Report-Infographic-03-353x1024.jpg 353w\" sizes=\"auto, (max-width: 1355px) 100vw, 1355px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>The vast majority of IT security professionals work to a set of Key Performance Indicators (KPIs) yet struggle to align these metrics with overall business goals, according to a new study by Thycotic, a provider of privileged access management (PAM) solutions for&nbsp;more than 10,000&nbsp;organisations&nbsp;worldwide. More than four out of five (84%) respondents have KPIs and [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":34327,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,171,93],"tags":[10617,13593,10618,13594,701],"class_list":["post-34262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-infographics","category-top-stories","tag-chief-security-scientist-and-advisory-ciso","tag-cyber-ambassadors","tag-joseph-carson","tag-kpi","tag-roi"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=34262"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34262\/revisions"}],"predecessor-version":[{"id":34329,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34262\/revisions\/34329"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/34327"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=34262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=34262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=34262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}