{"id":24612,"date":"2018-04-17T09:57:48","date_gmt":"2018-04-17T08:57:48","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=24612"},"modified":"2018-04-19T08:05:20","modified_gmt":"2018-04-19T07:05:20","slug":"centrify-study-finds-ceo-disconnect-is-weakening-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2018\/04\/17\/centrify-study-finds-ceo-disconnect-is-weakening-cybersecurity\/","title":{"rendered":"Centrify study finds CEO disconnect is weakening cybersecurity"},"content":{"rendered":"<p><a href=\"https:\/\/www.centrify.com\/\">Centrify<\/a>, a leading provider of zero trust security through the power of Next-Gen Access, has announced the results of a new research study which reveals that a misalignment between CEOs and Technical Officers is weakening enterprise cybersecurity postures.<\/p>\n<p>The report, \u2018<a href=\"https:\/\/www.centrify.com\/resources\/ceo-disconnect-weakening-cybersecurity\/\"><em>CEO Disconnect is Weakening Cybersecurity<\/em><\/a><em>\u2019<\/em>, was conducted with Dow Jones Customer Intelligence and highlights that CEOs are incorrectly focused on malware, creating misalignment within the C-suite, resulting in undue risk exposure and preventing organisations from effectively stopping breaches.<\/p>\n<p>Technical Officers (CIOs, CTOs and CISOs) on the front lines of cybersecurity point to identity breaches \u2013 including privileged user identity attacks and default, stolen or weak passwords \u2013 as the biggest threat, not malware. As a result, cybersecurity strategies, project priorities and budget allocations don\u2019t always match up with the primary threats nor prepare companies to stop most breaches.<\/p>\n<p>The study\u00a0\u2013 a survey of 800 enterprise executives including CEOs, Technical Officers and CFOs \u2013 highlights that:<\/p>\n<ul>\n<li>Sixty-two percent of CEOs cite malware as the primary threat to cybersecurity, compared with only\u00a035% of Technical Officers<\/li>\n<li>Only\u00a08% of all executives stated that anti-malware endpoint security would have prevented the \u2018significant breaches with serious consequences\u2019 that they experienced<\/li>\n<li>Meanwhile, 68% of executives whose companies experienced significant breaches indicated it would most likely have been prevented by either privileged user identity and access management or user identity assurance<strong>\u00a0<\/strong><\/li>\n<\/ul>\n<p>Tom Kemp, CEO of Centrify, said: \u201cWhile the vast majority of CEOs view themselves as the primary owners of their cybersecurity strategies, this report makes a strong argument that companies need to listen more closely to their Technical Officers.<\/p>\n<p>&#8220;It\u2019s clear that the status quo isn\u2019t working. Business leaders need to rethink security with a \u2018zero trust security\u2019 approach that verifies every user, validates their devices and limits access and privilege.\u201d<strong>\u00a0<\/strong><\/p>\n<p><strong>CEOs are investing in the wrong cybersecurity solutions<\/strong><strong>\u00a0<\/strong><\/p>\n<p>The study also revealed that CEOs are investing in the wrong areas of cybersecurity. The 2017 Data Breach Investigation Report released by Verizon indicates that 81% of breaches involve weak, default or stolen passwords. Identity is the primary attack vector, not malware, yet the report reveals that malware is still the focus point for most CEOs.<\/p>\n<ul>\n<li>Sixty percent<strong>\u00a0<\/strong>of CEOs invest the most in malware prevention and\u00a093% indicate they already feel \u2018well-prepared\u2019 for malware risk<\/li>\n<li>Forty-nine percent<strong>\u00a0<\/strong>of CEOs say their companies will substantially reduce malware threats over the next two years, yet only\u00a028% of CTOs agree with this statement<\/li>\n<\/ul>\n<p>These investment decisions are frequently caused by misplaced confidence in the ability to protect against breaches, putting organisations at significant risk. While Technical Officers are more aware of the real risks, they are also frustrated by inadequate security budgets as spending is typically strongly aligned with CEO priorities rather than with actual threats.<\/p>\n<p><strong>\u00a0<\/strong><strong>Poor communication between CEOs and technical officers leads to misalignment<\/strong><\/p>\n<p>The study also exposed that the disconnect between CEOs and Technical Officers leads to misaligned security strategies and tension among executives.<\/p>\n<ul>\n<li>Eighty-one percent of CEOs say they are most accountable for their organisations\u2019 cybersecurity strategies, while\u00a078% of Technical Officers make the same ownership claim<\/li>\n<li>Only\u00a055% of CEOs say their organisation has experienced a breach, whereas\u00a079% of CTOs acknowledge they\u2019ve been breached. This indicates that\u00a024% of CEOs are not aware that they have experienced a breach<\/li>\n<\/ul>\n<p>Garrett Bekker, Principal Security Analyst at 451 Research, said: \u201cThe traditional security model of using well-defined perimeters between \u2018trusted\u2019 corporate insiders and \u2018untrusted outsiders\u2019 to protect assets has evolved with the advent of cloud, mobile and IoT.<\/p>\n<p>\u201cYet most enterprises continue to prioritise spending on traditional security tools and approaches.\u00a0 Centrify\u2019s research reveals that a primary reason for conflicting cybersecurity strategies and spending is that C-level executives and technical managers don\u2019t always see eye-to-eye regarding security priorities and a misaligned C-suite can put the organisation at risk.<\/p>\n<p>\u201cModern organisations need to rethink their approach and adopt a framework that relies on verifying identity rather than location as the primary means of controlling access to applications, endpoints and infrastructure.\u201d<\/p>\n<p><strong>Outdated thinking results in higher risk<\/strong><strong>\u00a0<\/strong><\/p>\n<p>CEOs also expressed frustration with security technologies that have a poor user experience and cause their employees to lose productivity.<\/p>\n<ul>\n<li>Sixty-two percent<strong>\u00a0<\/strong>of CEOs state that multi-factor authentication (MFA) is difficult to manage and is not user-friendly, while only\u00a041% of technical officers agree with this assessment<\/li>\n<\/ul>\n<p>This outdated perception has been resolved by significant innovation by identity security vendors in areas such as machine learning. These advances have substantially reduced the burden of deploying and managing authentication solutions and improved the user experience for a range of security technologies.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Centrify, a leading provider of zero trust security through the power of Next-Gen Access, has announced the results of a new research study which reveals that a misalignment between CEOs and Technical Officers is weakening enterprise cybersecurity postures. The report, \u2018CEO Disconnect is Weakening Cybersecurity\u2019, was conducted with Dow Jones Customer Intelligence and highlights that [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":24616,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[809,13],"tags":[3218,5314,1530,5315,5316,104,5317,5318,5319,2676,5320],"class_list":["post-24612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-more-news","category-top-stories","tag-centrify","tag-ceo-disconnect-is-weakening-cybersecurity","tag-cybersecurity","tag-data-breach-investigation-report","tag-dow-jones-customer-intelligence","tag-malware","tag-next-gen-access","tag-technical-officers","tag-tom-kemp","tag-verizon","tag-zero-trust-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/24612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=24612"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/24612\/revisions"}],"predecessor-version":[{"id":24635,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/24612\/revisions\/24635"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/24616"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=24612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=24612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=24612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}