As part of a recent ESG research project, 340 enterprise cybersecurity, GRC, and IT professionals were asked to compare cyber risk management today with how it was two years ago. The data indicates that 39% of survey respondents believe that cyber risk management is significantly more difficult today than it was two years ago, while another 34% say that cyber risk management is somewhat more difficult today than it was two years ago.

Why do 73% of cybersecurity, GRC, and IT professionals believe cyber risk management is more problematic? Several issues stand out:
Think about this data from a CISO perspective. Your bosses are pushing you for more frequent updates on cyber risk management and they want it presented in a business context. Meanwhile, your staff, which is likely incrementally bigger than it was two years ago if at all, must collect, process, analyze, and report on risk management across an increasing and vulnerable attack surface, which is being targeted by more sophisticated cyber-adversaries.
Let’s face it, CISOs are being forced to bring knives to a cyber risk management gun fight. This model is completely broken. Fortunately, there is hope. Stay tuned for future blogs.
Jon Oltsik is an ESG senior principal analyst and the founder of the firm’s cybersecurity service. Read more ESG blogs here.