Добавить новость
123ru.net
BusinessInsider.com
Октябрь
2015
1 2 3 4 5 6 7 8 9 10
11
12
13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31

CIOs reporting directly to CFOs can create massive cybersecurity headaches

0

West Midlands Police officer using computers

Many companies need technology upgrades but are "starving" for the cash necessary to upgrade critical systems. That's the message from the author of a new study sponsored by the Georgia Tech Information Security Center.

Study author Jody Westby, the chief executive officer of consulting firm Global Cyber Risk, tells CFO.com, "When you start looking at why [a] company had a weak security program, it usually comes down to allocation of resources."

"The CFO should be very concerned, because often it's the security programs that have been starved for cash," she says.

Westby explains that many complaints about malfunctioning computer security systems never reach the CFO because the chief information officer (CIO) intercepts those messages and tables them. CFOs are often viewed to be "cost obsessed" and more willing to ditch projects that will cost the company money, she says.

Regardless of the chain of reporting, Westby says finance chiefs must include security programs — and the material and human resources they require — in the company's annual budget review. This allows the board to directly examine the cost of security risks and assign the necessary resources to stop cyber threats as they occur. 

"If a security team is starved for funding, that always comes back to the CFO," Westby tells CFO.com.

Confusing the issue is the reporting structure. Chief information security officers (CISOs) and chief security officers (CSOs) most often report to the CIO (40%). However, they also sometimes report to a CEO (22%), and 8% of the time they report to the CFO. That reporting structure has remained fairly consistent from 2010 through 2015. 

Cyber Security Reporting

If the CIO reports directly to the CFO, Westby says it's important that the CFO "really tries to understand the cyber risk and tries to ensure there is adequate funding — within reason."

The study lists four major cybersecurity challenges:

  • Lack of focus on cyber breach prevention puts critical assets at risk. Building security that simply detects threats, with no other option than incident response, is too little, too late.
  • Security has been categorized as simply an IT problem for too long. Cyber risks are too important not to discuss in the boardroom — this is an existential issue for the entire enterprise.
  • Too many point security products leave gaping holes in security postures. Piecemeal security systems and point products that don't share context across the entire cyberattack life cycle are inadequate.
  • Too many manual steps and cycles impede prevention and can't scale. Most enterprise security teams are not resourced to manually handle thousands of daily alerts.

Half of the cybersecurity issue clearly focuses on boardroom and funding considerations. 

There is, however, some good news for CFOs and their boards. The 2015 survey found that most boards have finally established "risk committees and shifted risk oversight from the audit committee to the risk committee. Additionally, boards are now undertaking key oversight activities related to governance of cybersecurity."

By removing the cybersecurity equation from the auditing department, a company can settle on must-have cybersecurity needs before passing that information along for financial approval.

Perhaps the most useful tip from the survey is to remove a single point of contact from making the final decision on security. "Evaluate the existing organizational structure and establish a cross-organizational team that is required to meet at least monthly to coordinate and communicate on privacy and security issues," Westby writes.  

"This team should include senior management from human resources, public relations, legal, and procurement, as well as the CFO, the CIO, CISO/CSO, CRO, the CPO, and business line executives," she says.

SEE ALSO: Verizon CFO: For Millennials, this is the thing in wireless 'that frustrates them the most'

Join the conversation about this story »

NOW WATCH: This US president would become 'irrational' and 'pass out' after one or two drinks















Загрузка...


Губернаторы России
Москва

Собянин: Москва и Пекин подписали программу сотрудничества на 2024-2026 годы


Спорт в России и мире
Москва

Красногорск первым встретил участников международного супермарафона Москва-Минск


Загрузка...

Все новости спорта сегодня


Новости тенниса
Уимблдон

Экс-теннисист Ольховский: россияне могут хорошо выступить на Уимблдоне


Загрузка...


123ru.net – это самые свежие новости из регионов и со всего мира в прямом эфире 24 часа в сутки 7 дней в неделю на всех языках мира без цензуры и предвзятости редактора. Не новости делают нас, а мы – делаем новости. Наши новости опубликованы живыми людьми в формате онлайн. Вы всегда можете добавить свои новости сиюминутно – здесь и прочитать их тут же и – сейчас в России, в Украине и в мире по темам в режиме 24/7 ежесекундно. А теперь ещё - регионы, Крым, Москва и Россия.


Загрузка...

Загрузка...

Экология в России и мире
Москва

Бизнес-омбудсмен Москвы оказывает поддержку НМСП





Путин в России и мире
Москва

ЯНДЕКС, АЛЕКСАНДР ПУШКИН, АНАТОЛИЙ ГОЛОД И "СВЯТОЙ ЛЕНИН" ВЕДУТ СЛЕДСТВИЕ ВЕКА! ВАЖНЫЕ СЕРЬЁЗНЫЕ ДАННЫЕ.


Лукашенко в Беларуси и мире



123ru.netмеждународная интерактивная информационная сеть (ежеминутные новости с ежедневным интелектуальным архивом). Только у нас — все главные новости дня без политической цензуры. "123 Новости" — абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Smi24.net — облегчённая версия старейшего обозревателя новостей 123ru.net.

Мы не навязываем Вам своё видение, мы даём Вам объективный срез событий дня без цензуры и без купюр. Новости, какие они есть — онлайн (с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии).

123ru.net — живые новости в прямом эфире!

В любую минуту Вы можете добавить свою новость мгновенно — здесь.





Зеленский в Украине и мире

Навальный в России и мире


Здоровье в России и мире


Частные объявления в Вашем городе, в Вашем регионе и в России






Загрузка...

Загрузка...



Metallica

Группа Metallica даст виртуальный концерт в Fortnite 22 июня



Москва

МВД Германии: правительство создало отдел по борьбе с дезинформацией из-за рубежа

Друзья 123ru.net


Информационные партнёры 123ru.net



Спонсоры 123ru.net