{"id":70540,"date":"2022-06-13T09:37:55","date_gmt":"2022-06-13T08:37:55","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=70540"},"modified":"2023-06-14T09:33:19","modified_gmt":"2023-06-14T08:33:19","slug":"research-reveals-40-of-companies-believe-their-cyber-strategy-will-be-outdated-in-under-two-years","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2022\/06\/13\/research-reveals-40-of-companies-believe-their-cyber-strategy-will-be-outdated-in-under-two-years\/","title":{"rendered":"Research reveals 40% of companies believe their cyber strategy will be outdated in under two years"},"content":{"rendered":"\n<p><strong><em>A perfect storm of escalating cyberattacks and global tech innovation leaves 61% of Chief Information Security Officers (CISO) only \u2018fairly confident\u2019 of managing their current threat exposure. A recent report from Crossword Cybersecurity Plc explores the findings in more depth.<\/em><\/strong><\/p>\n\n\n\n<p>Crossword Cybersecurity Plc, the cybersecurity solutions company focused on cyber strategy and risk, has released a new report based on the findings of a survey of over 200 CISOs and senior UK cybersecurity professionals.&nbsp;The report, <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__www.crosswordcybersecurity.com_crossword-2Dreport&amp;d=DwMFAg&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=JqYTqmC723Z8lpzWww7e61by3WK1UZ_7p03lmzHCZ3E&amp;m=MZydYiXfUZZdsbA7k64T9jMqyEHWz9fP4l0SJgqcz2w&amp;s=F5VnxXmrSvn9UBNxVCQLijpC0L-sUdg-Sj89XSax0YY&amp;e=\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Strategy and collaboration: a better way forward for effective cybersecurity<\/em><\/a><em>,<\/em> reveals companies are more concerned and exposed to cyberthreats than ever before, with almost two-thirds (61%) describing themselves as at best only \u2018fairly confident\u2019 at managing their current cybersecurity threat exposure, which should raise some eyebrows around the boardroom.<\/p>\n\n\n\n<p>Respondents also feared their cyber strategy would not keep pace with the rate of tech innovation and changes in the threat landscape.&nbsp;Just under half (40%) believe their existing cyber strategy will be outdated in two years and a further 37% within three years.&nbsp;Additional investment is needed to address longer term planning, with 44% saying they only have sufficient resources in their organisation to focus on the immediate and mid-term cyberthreats and tech trends.<\/p>\n\n\n\n<p><strong>The daily firefight<\/strong><\/p>\n\n\n\n<p>CISOs and cyber professionals report struggling to manage today\u2019s cybersecurity risks across the board.&nbsp; Asked about the day-to-day aspects of securing their businesses on a scale including \u2018a little, somewhat, or very challenging\u2019, the following areas were ranked highest as at least somewhat challenging by respondents: (total challenging figures in brackets)<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Detecting or identifying the occurrence of a cybersecurity event or threat \u2013 56% (85%)<\/li><li>Third-parties disclosing breaches in good time \u2013 55% (85%)<\/li><li>Understanding and anticipating new or potential future strategies used by threat actors \u2013 55% (84%)<\/li><li>Ensuring that the entire supply chain is water-tight in its ability to defend and recover against threat actors \u2013 52% (83%)<\/li><\/ul>\n\n\n\n<p><strong>Juggling cybersecurity priorities<\/strong><\/p>\n\n\n\n<p>Not only do organisations feel they are chasing their next cyber strategy, but they are struggling to deliver on the one they have now. CISOs highlighted the following key priorities over the next 12 months:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>The<\/strong> <strong>cyber skills gap within organisations is the highest strategic priority (31%).<\/strong>&nbsp;This has been a perpetual problem facing the IT industry and cybersecurity teams can become quickly overwhelmed if the right expertise isn\u2019t in place to manage the load.&nbsp;The effects of this can be devastating, creating risk vectors that can be exploited and may lead to human error under pressure, or a missed threat.&nbsp;Rather than hunting new people, the gap could in part be addressed by putting more resources into training and upskilling, but this is difficult when team capacity is already stretched.&nbsp;<\/li><li>The next most important priority highlighted by CISOs is the challenge of <strong>gaining consistent and reliable \u2018threat intelligence\u2019 (28%)<\/strong>, with many reporting they rely on informal information sharing networks.&nbsp;<\/li><li><strong>Securing digital identity (27%)<\/strong> was also identified as key given the risks posed by hackers gaining credentials and impersonating users to access data and systems.<\/li><\/ul>\n\n\n\n<p>\u201cThe picture painted by our research shows CISOs are in urgent need of a strategic rethink,\u201d said Stuart Jubb, Group Managing Director at Crossword Cybersecurity plc.&nbsp;\u201cCISOs need to balance their cybersecurity operation\u2019s daily load with managing the organisation\u2019s long-term requirements. Boards must make sure CISOs have the budget necessary to get short-term issues under control and then begin planning a long-term business-wide strategy. Such a strategy should be supported by a standard operating model with robust processes and policies for the company\u2019s entire supply chain. Every month of delay leaves businesses open to potentially crippling cyberattacks.\u201d<\/p>\n\n\n\n<p><strong>The tech trends that matter to cyber professionals<\/strong><\/p>\n\n\n\n<p>CISOs were also asked about the technology trends they saw as being the most important and relevant over the next 12 months. Several technology categories stood out with cloud transition and cyber in the cloud leading the way (41%), followed by Cyber Security Mesh Architecture (CSMA \u2013 35%) and AI\/Machine Learning (31%).&nbsp;<\/p>\n\n\n\n<p>Deciding how each of these categories will fit into the short-term cyber goals and longer-term strategy of UK organisations will take serious consideration.&nbsp;However, respondents did report having a clear view on the most important technology components they want to address in their cybersecurity plans in the short term, compared to the next three or five years. Three-quarters (75%) said software verification, which helps to ensure a program is secure, 69% said cloud transition and 69% said dealing with ransomware escalation, will be a focus immediately or over the next 12 months. A similar number (65%) identified CSMA &#8211; a method for making cybersecurity products interoperable &#8211; as a key technology. Other technologies of note included:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Zero Trust and identity security (62%)<\/li><li>Quantum data stores \/ computing (55%)<\/li><li>AI \/ Machine Learning (55%)<\/li><\/ul>\n\n\n\n<p>Jubbconcluded: \u201cCybersecurity today is in a more tightly squeezed iterative cycle than it was in the past. It demands that organisations take a more strategic and collaborative approach \u2013 we recommend appointing a head of cybersecurity strategy, while leaving the CISO to deliver on the immediate challenges.&nbsp;Managing the day-to-day risks is a tough balancing act, but one that can be achieved if CISOs have the right resources to upskill their teams and tools that leverage AI to bring efficiency and automation to help protect their organisation and its supply chain against today\u2019s threats.\u201d<\/p>\n\n\n\n<p>Professor Tim Watson, Programme Director, Defence &amp; Security, The Alan Turing Institute and Director, WMG Cyber Security Centre, University of Warwick, commented:&nbsp;\u201cCollaboration is especially important when it comes to protecting critical national infrastructure because it&#8217;s rapidly becoming a whole new theatre of conflict between Nation States. It&#8217;s also not particularly easy because there are so many private and public stakeholders.\u201d<\/p>\n\n\n\n<p>Muttukrishnan Rajarajan (Raj), Professor of Security Engineering and Director, Institute for Cyber Security, City, University of London,commented: \u201cTackling ransomware is a huge area of focus in the world of research, so I\u2019m not surprised this scored highly in the survey. We are often commissioned to work on projects that focus just on this \u2013 an attack on one SME can cause a complete supply chain to grind to a halt as we saw with vulnerabilities introduced via the Log4J code libraries recently.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A perfect storm of escalating cyberattacks and global tech innovation leaves 61% of Chief Information Security Officers (CISO) only \u2018fairly confident\u2019 of managing their current threat exposure. A recent report from Crossword Cybersecurity Plc explores the findings in more depth. Crossword Cybersecurity Plc, the cybersecurity solutions company focused on cyber strategy and risk, has released [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":70541,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[51,17482,57,1489,6617,93,23,24],"tags":[10356,564,6852,7465],"class_list":["post-70540","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-study-newsletter","category-cybersecurity","category-enterprise-security","category-insights","category-research","category-top-stories","category-united-kingdom","category-used","tag-crossword-cybersecurity-plc","tag-cybersecurity","tag-research","tag-united-kingdom"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/70540","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=70540"}],"version-history":[{"count":10,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/70540\/revisions"}],"predecessor-version":[{"id":71162,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/70540\/revisions\/71162"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/70541"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=70540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=70540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=70540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}