Slowly the leaders at the top of organizations within business, government and industry are coming to the realization that they will be held accountable if and when they experience a cyber incident or data breach. That is not technology execs, but the heads of the organizations.
Many attribute this to the Target breach that resulted in the CEO resigning, a very public incident. Others point to the report by management consulting firm McKinsey that projected earlier this year that the implications of cyber attacks could cost the global economy $3 trillion by 2020.
To put that in context, that is just over 1.7 times the global defense spending ($1.75 trillion) last year. This is causing some changes in behavior that are considered a double edge sword for all of those in the information security department all the way to the Chief Information Security Officer.
Executive involvement in information security has been on the increase for years. This time it is different. Not only are they actively engaged and expecting regular updates about cyber incidents they are pushing proactive measures – not the run of the mill cyber defenses either. That active involvement goes beyond being apprised of cyber threat activities. The executive suite is now part of the cyber security decision making process. Some CISOs welcome of this involvement while others see it as just another draw on their time. In fact one CISO commented he spends most of the time explaining cyber security basics not the incidents themselves. Another CISO comments that “neither the security department nor the IT department are in charge of cyber incident/data breach response and recovery any longer.” It now falls under the business side of the organization and greatly influenced by the legal department.
CISOs had better accept the idea that cyber incidents and defenses have grown well beyond a technology issue that is handled by the technology department! Given they are being held accountable, executives are taking the driver’s seat in the face of growing cyber threats. They want this addressed now and CISOs’ will be held accountable. This could make CISO stand for Career Is Seriously Over!




