Businesses lack consensus on who should shoulder responsibility for information security
- Published: Tuesday, 13 November 2018 09:19
Responsibility for information security is not falling to any one senior executive function, according to the 2018 Risk:Value report from NTT Security, which surveyed 1,800 senior decision makers from non-IT functions in global organizations.
At a global level, 22 percent of respondents believe the CIO is ‘ultimately responsible’ for managing security, compared to one in five (20 percent) for the CEO and 19 percent for the CISO. In the UK, fewer respondents point to the CIO (19 percent) and CISO (18 percent) while the CEO gets the biggest vote at 21 percent. The US (27 percent) and Norway (26 percent) buck the trend with more than a quarter of respondents suggesting the CEO is responsible, while in Singapore, one third say it is the role of the CISO – the highest figure across all 12 countries. Interestingly, around one in ten people in Switzerland believe the CFO is responsible for security.
“Responsibility for day-to-day security doesn’t seem to fall on any one particular person’s shoulders among our response base,” says Azeem Aleem, VP Consulting & UK&I Lead, NTT Security. “This narrow gap between the roles of CIO, CEO and CISO shows that no one executive function is stepping up to the plate. It could be a sign of unclear separation between the CIO and CISO though, as often they are the same or collaborate closely.
"On the other hand, should we be concerned that the CEO is not more involved in security matters, given the potentially damaging affects to the business, or should we be relieved that they are not managing a specialist task like this over and above other critical corporate responsibilities? The question is where do you draw the line?”
According to the 2018 Risk:Value report, although more people see the need for regular boardroom discussions about security, their organizations are failing to raise it sufficiently at the C-suite level. While 80 percent of all survey respondents agree that preventing a security attack should be a regular boardroom agenda item (up from 73 percent in last year’s report) only 61 percent say that it is, an increase of just 5 percent on last year.
Data security poor due to lack of cohesion at the top
NTT Security’s report also suggests that the lack of cohesion at the top of the organization means that many are struggling to secure their most important digital assets. Fewer than half (48 percent) of respondents globally – 53 percent in the UK – say they have fully secured all of their critical data. But with the General Data Protection Regulation (GDPR) now fully in effect, this is no longer an opportunity, but mandatory.
Companies are beginning to take control of their data as cloud computing best practices mature. Around a quarter (27 percent) report that the majority of their organization’s data is currently stored on premise or in data centres / centers (25 percent). However, in 12 months’ time, a similar proportion (25 percent) of respondents say that it will be stored in a cloud environment.