Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
10/19/2017
09:00 AM
Mike Convertino
Mike Convertino
Partner Perspectives
Connect Directly
LinkedIn
RSS
100%
0%

CISOs: Striving Toward Proactive Security Strategies

A new survey paints a compelling picture of the modern security executive, how they succeed, and how much power they wield.

Chief Information Security Officers are in a tough spot. Organizations are squeezed by cyber criminals, new compliance requirements, and bleeding-edge technologies that erode privacy and stability. The team that leads defense efforts is becoming a more and more vital player in the long-term survival of any organization that sells, uses, or produces information technology — that is to say, everyone. But what do we really know about CISOs and how they operate?

Many surveys talk about CISO salaries and job prospects, but we felt that the industry as a whole needed to fully understand what goes into the day-to-day job of a CISO. F5 and research firm Ponemon teamed to directly survey CISOs. Our goal: to draw as complete a picture as we could on the modern security executive. In the report, "The Evolving Role of CISOS and Their Importance to the Business," we focus on key areas like budgetary control, organizational influence, decision rationale, and strategic methodology. In other words, how do CISOs succeed, and how much power do they wield? We also delve into the background of CISOs and their experience, both in terms of technical capability and business savvy.

To cast a wide net, we interviewed senior level IT security professionals from 184 organizations in seven countries, tracking nearly 70 questions. We wanted a deep, unbiased look at the contemporary CISO. The results are eye-opening, and both encouraging and worrisome.

First, the discouraging news: security programs appear to be reactive: 60% of respondents say material data breaches and cybersecurity exploits are the primary drivers of change in security programs. A mere 22% of respondents say their organizations’ security function is integrated with other business functions. Perhaps most concerning, only 51% say their organization has an IT security strategy and, of those, only 43% say that the company strategy is reviewed, approved, and supported by C-level executives.

Now the is good news. A full 77% of respondents say their IT security operations are aligned with IT operations, although fewer respondents (60%) say they have achieved alignment of IT security operations with business objectives.

Furthermore, there are some promising trends in the day-to-day responsibilities CISOs hold. Most CISOs (67%) believe they should be responsible for setting security strategy, and the majority are influential in managing their companies’ cybersecurity risks, with 65% reporting to senior executives (meaning, no more than three steps below the CEO on the organization chart). Over half (61%) set the security mission and are responsible for informing the organization about new threats, technologies, practices, and compliance requirements (60%). In the event of a serious security incident, more than half (60%) have a direct channel to the CEO.

These findings indicate both the challenges and the progress CISOs are making in today’s complex environment. I invite you to reflect on and discuss these findings with your peers and in the comment section below. My hope is that we now have a foundation for more meaningful conversations with one another, and have a greater impact on our organizations. I also hope the broader discussions we are driving here at F5 Labs are providing CISOs and future CISOs the tools to tackle this challenge.

There's a lot there. You can read the full report here

Get the latest application threat intelligence from F5 Labs.

Mike Convertino is the chief security officer at Arceo.ai, a leading data analytics company using AI to dynamically assess risk for the cyber insurance industry. He is an experienced executive, leading both information security and product development at multiple leading ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15208
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can ...
CVE-2020-15209
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one....
CVE-2020-15210
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and ...
CVE-2020-15211
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices f...
CVE-2020-15212
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `outpu...