Crossword Cybersecurity PLC (AIM:CCS) said three-fifths of chief information security officers (CISO) it surveyed are only “fairly confident” of managing their current cyberthreat exposure.
The Aim-listed cybersecurity solutions company released details of a new report based on a survey of more than 200 CISOs and senior UK security professionals that it said “should raise some eyebrows around the boardroom”.
Survey respondents said they are firefighting on a daily basis and many fear their cyber strategy will not keep pace with the rate of tech innovation in the cybercriminal community.
Two-fifths, or 40%, believe their existing cyber strategy will be outdated in two years, and a further 37% believe it will be past its use-by date within three years. Additional investment is needed to address longer term planning, the report concluded, with 44% of respondents saying they only have sufficient resources in their organisation to focus on the immediate and mid-term cyber threats and tech trends.
CISOs highlighted the following key priorities over the next 12 months:
The cyber skills gap within organisations is the highest strategic priority (31%). Cybersecurity teams can become quickly overwhelmed if the right expertise is not in place to manage the load, the report noted. The gap could in part be addressed by putting more resources into training and upskilling, but this is difficult when team capacity is already stretched.
The next most important priority highlighted by CISOs is the challenge of gaining consistent and reliable 'threat intelligence' (28%), with many reporting they rely on informal information sharing networks.
Securing digital identity (27%) was also identified as key given the risks posed by hackers gaining credentials and impersonating users to access data and systems.
“The picture painted by our research shows CISOs are in urgent need of a strategic rethink. CISOs need to balance their cybersecurity operation's daily load with managing the organisation's long-term requirements,” said Stuart Jubb, the group managing director at Crossword Cybersecurity.
“Boards must make sure CISOs have the budget necessary to get short-term issues under control and then begin planning a long-term business wide strategy. Such a strategy should be supported by a standard operating model with robust processes and policies for the company's entire supply chain. Every month of delay leaves businesses open to potentially crippling cyber-attacks," he warned.
CISOs were also asked about the technology trends that they saw as being the most important and relevant over the next 12 months. Several technology categories stood out with cloud transition and cyber in the cloud leading the way (41%), followed by cyber security mesh architecture (35%), and artificial intelligence (AI)/Machine Learning (31%).
“Cybersecurity today is in a more tightly squeezed iterative cycle than it was in the past. It demands that organisations take a more strategic and collaborative approach - we recommend appointing a head of cyber security strategy, while leaving the CISO to deliver on the immediate challenges,” Jubb said.
“Managing the day to day risks is a tough balancing act, but one that can be achieved if CISOs have the right resources to upskill their teams and tools that leverage AI to bring efficiency and automation to help protect their organisation and its supply chain against today's threats," he concluded.
Muttukrishnan Rajarajan, professor of security engineering and the director of the Institute for Cyber Security at the University of London, said he was not surprised that tackling ransomware scored highly in the survey.
“We are often commissioned to work on projects that focus just on this - an attack on one SME [small or medium-sized enterprise] can cause a complete supply chain to grind to a halt as we saw with vulnerabilities introduced via the Log4J code libraries recently,” the professor said.
Hybridan, the boutique broker, said the report demonstrates Crossword’s standing as a thought leader in the cybersecurity industry, as well as its deep relationships with cybersecurity budget holders.
"It shows how professionals are struggling to develop the next stage of their cybersecurity strategy in the face of an exponentially evolving threat, as well as delivering their current strategies," the broker said.
"Crossword is well placed to help navigate this landscape and offers a range of cyber security solutions to help companies understand and reduce cyber security risk. Crossword’s areas of emphasis are cyber security strategy and risk, supply chain cyber, threat detection and response, and digital identity," it added.
--- adds broker comment ---