ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Doing more with less – managing cyber risk in 2023

teissTalk host Geoff White was joined by Michelle Griffey, Chief Risk Officer, Communisis; and Steve McKeaveney, Head of Customer Success, ITC Secure.

 

 

Views on news

 

Pressure is rising on budgets amid concerns about an economic downturn and CISOs will need to convince board members and the C-suite that cyber resilience will help improve the bottom line, according to Forrester.  The original Forrester report points out that businesses can’t take their foot off the pedal, as threat actors won’t stop attacking them for lack of money in an economic downturn.

 

Pitches to increase the security budget sound like a no-win conversation – you need to invest a lot of money and the best you can get out of it is not being hacked. The article emphasises that CISOs need to make the case that cyber resilience boosts customer trust and loyalty. Moreover, the right security posture can also give a business an edge over competitors.

 

Managing cyber risk in conjunction with MSSPs

 

Cyber risk is inextricably intertwined with data protection, and change risk is another area for Chief Risk Officers to keep an eye on.

 

If all other risks are managed well, financial risk will follow naturally without being addressed separately. Cyber risk is an important component of RFPs and the company providing the service must also evidence the questions they are asked and do so in a manner that’s understandable for the client’s procurement or operations teams. 

 

According to an international survey, less than half of companies across the globe get adequate budget allocation to support their cyber security needs. However, while budgets are getting tighter, a high number of businesses prioritise money into security. 

 

PWC’s report, for example, talks about three areas – investment in cyber security and data privacy, adapting the supply chain and expanding the company’s geographic footprint, which are growth-focussed elements that cyber security can support. According to Gartner’s review in 2020, 78 % of CISOs have got 16 or more security tools, thanks to the practice of buying best-of-breed point solutions, which often don’t work in a cohesive manner. 

 

Managed Security Service Providers (MSSPs) can help with dealing with the complexities of cyber security by providing an integrated dashboard instead of 16 different ones. Outsourcing some of the aspects of cyber security – such as a 24/7 service – allows internal staff to deal with DLP and other strategic issues. Responding to false positives is a good way of preparing for real incidents. Although with cloud services you have some level of security thrown in, it shouldn’t give you a false sense of security, as bad actors can also buy cloud services the way your company does and use it for breaching corporate systems. 

 

The panel’s advice

 

Don’t strive for perfection. Establish what are the critical cyber risk areas that need to be covered immediately, as well as what is good enough.

 

A high number of best-of-breed solutions creates more confusion than value and clarity. If you buy a holistic tool, there is the danger of putting all your eggs in one basket, but it can be a very effective “basket”, where you can get all the capabilities at a lower price point. 

 

Incident response is often overlooked, but it’s key to mitigating damage.

 

When dealing with vendors, always ask yourself what you want to protect there, and how much value the tool they are trying to sell you will add.

 

Find a provider that has the “we are in this together” mindset.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543