More than 50% of IT security decision makers do not see cybersecurity as a business priority and regard it as important only for compliance and regulatory requirements, according to a new study.
61% "Overlook" Cybersecurity
Delinea, a privileged access management provider, surveyed 2,000 security decision makers, 61% of whom believe that their company’s leadership “overlooks” the role of cybersecurity in business success. Only 39% of them think that their board of directors and C-suite has a “sound understanding” of cybersecurity’s role as a business enabler.
The survey results underscore the impact of “misalignment” between cybersecurity function and wider business, Delinea said.
Here are more findings from the report:
Joseph Carson, chief security scientist and advisory chief information security officer at Delinea, explained the research reflects that is still some work to be done at the board level to shift mindsets:
“Executive leaders need to think of cybersecurity not only in terms of ticking the compliance box or protecting the company, but also in terms of the value it can deliver at a more strategic level. Building out business skillsets may provide the path to better alignment. However, respondents listed technical skills as the most valuable for cybersecurity leaders to possess. These are rated above skills such as communication, collaboration, business acumen, and managing people.”
Aligning Cybersecurity with Business Goals
Commenting on the importance of aligning cybersecurity with business goals, Carson said:
“Alignment between cybersecurity and business goals is essential for success. This research clearly highlights the negative consequences when teams’ objectives aren’t fully in sync. Ensuring common agreement across business functions is vital and there is a real value in metrics that not only measure security activity, but which also demonstrate the impact on business outcomes."