Select your language

Disarticulation between security and management teams increases cyber risks

Desarticulación entre equipos de seguridad y dirección aumenta riesgos cibernéticos

International. Dynatrace released its annual CISO survey. This year, the global report reveals that organizations are struggling with internal communication barriers that hinder their ability to address cybersecurity threats.

The results indicate that CISOs find it difficult to drive alignment between security teams and senior management (C-level executives, Chief Officers), leaving gaps in the organization's understanding of cyber risk. As a result, they are more exposed to advanced cyber threats at a time when AI-driven attacks are on the rise.

The Mexican Market and Cybersecurity
The report, commissioned by Dynatrace and conducted by Coleman Parkes between March and April 2024, is based on a global survey of 1,300 CISOs and ten interviews with CEOs and CFOs of companies with more than 1,000 employees.

50% of CISOs in Mexico say there is a regular requirement to inform the CEO and board of directors about their cybersecurity risk and compliance posture. 66% of CISOs say their security tools have limited ability to generate insights that the CEO and board can use to understand business risks and prevent threats.

- Publicidad -

Mexican CISOs ranked their organizations' top priorities for cybersecurity management as follows:

  • Application security (i.e., vulnerability management).
  • Crisis management and response (i.e., data leakage and media focus).
  • Internal risk management/oversight (i.e., use of mobile devices).
  • 50% of organizations have experienced an application security incident in the last two years.
  • 90% of CISOs say application security is a blind spot at the CEO and board level.
  • 78% of CISOs say DevSecOps automation will be essential to their ability to stay on top of
  • emerging regulations such as the SEC's cybersecurity mandate such as NIS2 and DORA.
  • 92% of CISOs say DevSecOps automation is even more important for managing the risk of AI-introduced vulnerabilities.
  • 64% of CISOs struggle to drive DevSecOps automation due to their reliance on multiple application security tools.
  • Only 16% of CISOs say their organization has mature DevSecOps automation practices.

Findings from a global perspective
Lack of alignment between the C-level and the board of directors leads to cyber risks. CISOs struggle to drive alignment between security teams and C-suite; 87% of CISOs say application security is a blind spot at the CEO and board level.

Security teams are too technical. Seven out of ten C-suite executives interviewed say security teams speak in technical terms without providing business context. However, 75% of CISOs highlight that the problem stems from security tools that can't generate insights that C-level executives and boards can use to understand business risks and prevent threats.

AI is powering more advanced cyber threats. Addressing this technology and communications gap is becoming more critical as the rise of AI-driven attacks and cyber threats significantly increase business risk.

Against this backdrop, nearly three-quarters (72%) of CISOs say their organization has experienced an application security incident in the past two years. These incidents carry significant risk, and CISOs highlight the common consequences they've experienced including revenue impact (47%), regulatory fines (36%) and loss of market share (28%).

"Cybersecurity incidents can have devastating consequences for organizations and their customers, which is why the issue has rightly become a critical concern at the board level," said Bernd Greifeneder, CTO of Dynatrace. "However, many CISOs struggle to drive alignment between security teams and senior management because they can't bring bit-and-byte conversation to specific business risks. CISOs urgently need to find a way to overcome this barrier and create a culture of shared responsibility for cybersecurity. This will be critical to improving their ability to respond effectively to security incidents and minimizing their exposure to risk."

The report, 'The State of Application Security in 2024: The Imperative to Drive Greater Alignment Between the CISO, CEO, and Board', is available for download online.


No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Investing in Access Controllers: Why Eliminating Them Can Be a Strategic Mistake

Thanks to technological evolution, today there are smart readers with the capacity to process credentials, store information and even operate locks autonomously. This has led many organizations to...

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Case study: How did a retail chain in Costa Rica reduce fraud by 18%?

Almacenes El Rey is a rapidly expanding department store, with 18 branches nationwide and more than one million customers each year. Thanks to the Avigilon Unity Video solution, the retail chain...

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Is storing video no longer enough? Milestone's Sales Director for Latam speaks

Latin America. Johana Arias, an executive at Milestone Systems, discusses how the integration of AI, natural language, and open platforms are transforming video into actionable insights for...

Anti-intrusion system described as one of Ajax's largest in South America

Anti-intrusion system described as one of Ajax's largest in South America

Argentina. The Bayron company installed a protection system with more than 85 Ajax wireless devices in the new branch of Autos del Sur S.A., Toyota's official dealership in the country.

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Interview with Manuel Carlos, Senior Sales Director for Mexico at Hanwha Vision

Mexico. Manuel Carlos, an executive at Hanwha Vision, details how the company is revolutionizing electronic security by consolidating generative artificial intelligence and processing at the edge.

Prosegur presents new capabilities in cybersecurity and automation

Prosegur presents new capabilities in cybersecurity and automation

International. Prosegur Security has created two new modules, xCope and xEcute, which aim to provide companies and organizations with a new corporate digital surveillance service and another for...

Access and video platform

Access and video platform

Johnson Controls Designed to take the complexity out of legacy systems, the latest version of C•CURE IQ helps organizations achieve faster response, simplify workflows, and turn safety data into...

SIA presents the new directives of its International Relations Committee

SIA presents the new directives of its International Relations Committee

Latin America. Mariana Ramírez is the new president of the International Relations Committee of the Security Industry Association (SIA), while Vanesa Cabral assumed the role of vice president.

Access management and security in stadiums during the World Cup

Access management and security in stadiums during the World Cup

International. With the World Cup underway, stadium operation and the management of credentials and critical assets become key factors in ensuring security in high-demand environments.

Jovicard modernizes its headquarters with HID access control technology

Jovicard modernizes its headquarters with HID access control technology

Brazil. Jovicard, which specializes in physical access control, secure identity, biometrics and integrated electronic security, completed the modernization of its corporate headquarters with trusted...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter