ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Aligning organisational perceptions of cyber-security

Amita Potnis at CyberArk explains why leadership perception is negatively impacting organisational security

 

Historically, cyber-security was never an issue leaders had to overly concern themselves with. It was dealt with but at lower levels of the organisation. But as technology and threat actors have evolved, cyber-security has risen to the top of the board’s priority list, with senior execs taking greater responsibility for it.

 

While an issue that absolutely should be board-level, this change in responsibility has ultimately altered the role of the CISO.

 

In fact, CISOs are no longer technical subject matter experts. Instead, they have become executive risk managers sharing a responsibility matrix with the board, CEOs, and other executives. The issue with this? At the highest level, CISOs should be in charge of the security decisions. They need to take back the subject matter expert name if they are to ensure the security of their business.

 

Reality and perception are different

Our latest research, Identity Security State of the Market Survey, indicates C-level executives are bullish about their organisation’s ability to mitigate identity security-related risk – more so than other personnel deemed technically astute and aware of the complexities of their organisation’s IT environment.

 

This is already a concerning trend, but the changing CISO role makes this disconnect dangerous, and one of the catalysts of identity-related cyber-security incidents.

 

Our research also found that, in 2023, 81% of 1,500 respondents will exponentially increase their spending on identity security as part of their cyber-security budget. This will drive varied perceptions across C-level executives and is where the need for a robust identity security strategy comes to the fore.

 

Increasing consequences

It’ll come as no surprise that executive perception being misaligned with reality is dangerous, especially when it comes to the cyber-security of an organisation. Our aforementioned research proves this, indicating that, in 2022, 58% of exec respondents believed they made the right identity security decisions.

 

This didn’t reflect the facts though, with 63% indicating they suffered at least one successful identity-related attack that year.

 

We’re dubbing this trend the ‘perception gap’. And it indicates a very real problem within organisations security programs: a lack of understanding of what a robust identity security strategy means beyond investment into tools and solutions.

 

The real-world impact

Of the 63% of respondents who fell victim last year to an identity-related cyber-attack, 27% experienced more than one attack. The impact of this is multi-fold.

 

In the short term, projects may be delayed due to the significant manpower and time allocated to resolving the issue. Products and services may also be affected, causing issues such as customer experience degradation and potentially lost revenues, compliance fines, and extensive audits.

 

With cyber-security being a board-level issue then, security teams can’t afford for these impacts to come to fruition. While allocating line-item budgets to procure identity tools is the first step in stopping attacks, additional measures need to be implemented, and identities secured correctly.

 

The four tenets

IDC predicts that by 2025, 45% of CEOs - fatigued by security spending without predictable ROI - will demand security metrics and results measurement to access and validate investments made by their security program. When looking at our research in conjunction with this forecast, we believe this situation has the potential to materialise sooner.

 

The proliferation of identities and endpoints and increased vulnerabilities from inadequately secured identities are a significant cause for concern, especially in conjunction with the fact that respondents reported the use of over 70 security vendors on average. If organisations are to continue on this path, the picture is bleak.

 

Changes need to be made, and the perception gap reduced.

 

To do this, the four key tenets foundational to a robust identity security strategy need to be implemented – tools, integration, automation and continuous threat detection and response.

 

Adopting all of these created a holistic approach able to mature identity security strategies while lessening the perception gap of executives. All in all, it’s a must for organisations wanting to stay secure well into the future.

 


 

Amita Potnis is director of thought leadership marketing at CyberArk

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543