Cyber Security Pros Are Feeling The Pressure

Security is now one of the most important functions in the enterprise. It’s also an area that is increasingly vulnerable to evolving cyber threats; ones that include AI and automation, for example.  It is a case of when, not if an organisation is breached.

This inevitability does not alleviate pressure, it enhances it. And, it is no wonder that cyber security professionals are feeling the pressure. 

To find out the extent of this pressure Nominet commissioned a survey of 408 CISOs in the UK and US; each overseeing the cyber security of businesses that have an average of just under 9,000 employees.

Increasing Stress Levels

Stress is a normal part of any job, to an extent. The report found that almost every CISO suffers moderate or high stress, with 60% saying that they rarely disconnect from their job. They are also working long hours, again, there’s nothing wrong with this: to an extent.

An overwhelming, 88% of those CISOs surveyed are working more than forty hours a week, while 22% said they are available 24/7. The US CISO is particularly bad at disconnecting: 89% said they never have a break for two weeks or more from work.

All of this is causing a physical response to a very digital problem. Over a quarter of those questioned said stress is impacting their mental or physical health, while 23% said the job is eroding their personal relationships.

Most concerning is the 17% of CISOs who admitted to turning to medication or alcohol to deal with job stress.

Dr Dimitrios Tsivrikos, a business psychologist and lecturer at University College London, said: “It is of paramount importance that we address organisational stress and extra emphasis ought to be paid to CISOs. As a group of employees, they are faced with overwhelming pressure. Errors in their judgment, caused by excessive work-related stress, can indeed have detrimental effects upon business and personal data.

“In addition, individuals who are stressed at work are oftentimes not living their best lives privately, either. Most of us find it difficult to suppress the pressures from work, and they do indeed spill over into our private life. This poses significant health-related threats to personal well-being as individuals rely on alcohol and other non-constructive behaviours in order to relax and find relief from those pressures.”

Internal Pressures

Security has always had a strained relationship with the c-suite or board. It wasn’t that long ago that security was not even taken that seriously, and now it should be a top priority from the top. Naturally, this has caused tensions and perhaps, is a reason why the relationship is strained.

Indeed, the report highlighted that 18% of CISOs believed their board members are indifferent to the security team, or see them as an inconvenience. This lack of engagement is troubling, as only 60% of CISOs said that their CEO/president agrees a breach is inevitable.

Further, nearly a third of all those questioned believed that, in the event of a breach, they would either lose their job or receive an official warning, what a wonderful company to work for!

This is worse in the UK, as 37% of CISOs said they would receive a warning or be fired, compared with 28% in the US.

Resource Conundrum

Despite awareness about the pervasiveness of cyber threats, 60% of CISOs questioned admitted having found malware on their infrastructure (which had been there for an unknown period of time). More than half of CISOs (57%) said a lack of resources is what holds back an effective security posture, while 63% said they were struggling to recruit the right people.

Echoing the internal pressures, CISOs also stated that a lack of senior buy-in was the issue, with 65% claiming this as a barrier within their organisation.Budget constraint was identified as a growing challenge. Fewer than half of respondents said that they have adequate, or very adequate budget to tackle cyber-attacks. Only half said they had adequate or very adequate technology.

Modern Cyber Security Professional

The heightened cyber threat facing organisations is having some very physical effects on the cyber security professional.

Russell Haworth, CEO, Nominet said: “CISOs around the world are facing mounting pressures amid a rapidly shifting cyber landscape. Criminals are forever finding ways to exploit vulnerabilities, and do not discriminate against the businesses they attack. Everyone is a target.

“It’s no surprise that CISOs are facing burnout. Many lack support from within their organisations, and senior business leaders need to face the facts: the threats are real, and CISOs need to be given the resources and support to tackle them. If not, the board must face the consequences.

“The risk is not only personal to a CISO, but a business’ hard-won reputation. The growing economic cost is also a worrying trend. And a recent report put the cost of global cybercrime at $600 billion in 2017.

“With that cost likely to rise in the future. We must all work harder, and cooperatively, to mitigate potential losses by having the right strategy, tools and resource in place to prevent breaches in the first place.”

Information Age

You Might Also Read: 

Meeting The Cyber Talent Challenge Head-On:

 

« Blockchain’s Newest Application Is Civil Aviation
What Is Data Fusion? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

SecDev

SecDev

SecDev is a consulting firm working at the intersection of geopolitical, digital, urban, energy and cyber risk.

Logicalis

Logicalis

Logicalis are a leading provider of global IT solutions and managed services.

Security Weekly

Security Weekly

Security Weekly provides free content within the subject areas of IT security news, vulnerabilities, hacking, and research.

ShmooCon

ShmooCon

ShmooCon is an annual east coast hacker convention offering three days of demonstrations and discussions of critical infosec issues.

OPSWAT

OPSWAT

OPSWAT is a software company that provides solutions to secure and manage IT infrastructure.

Payload Security

Payload Security

Payload Security's VxStream Sandbox is a fully automated malware analysis system.

Pradeo

Pradeo

Pradeo Security offers a complete, automatic and seamless protection to mobile devices and applications, aligned with your organization security policy while preserving business agility.

VMRay

VMRay

VMRay delivers advanced threat analysis and detection that combines a unique agentless hypervisor-based network sandbox with a real-time reputation engine.

WizNucleus

WizNucleus

WizNucleus develops, markets and supports a software platform (Cyberwiz-Pro) that enables Critical Infrastructure enterprises to ensure the future state of their cybersecurity and remain compliant.

The Legal 500

The Legal 500

The Legal 500 Hall of Fame highlights, to clients, the law firm partners who are at the pinnacle of the profession. Practice areas covered include Data Protection, Privacy and Cybersecurity.

Dashlane

Dashlane

Dashlane puts all your passwords, payments, and personal info in one place that only you control. So you can use them instantly. Securely. Exactly when you need them.

Constella Intelligence

Constella Intelligence

Constella Intelligence provides digital risk protection services to quickly and efficiently disrupt cyber attacks and data breaches before they occur.

AgileBlue (Agile1)

AgileBlue (Agile1)

AgileBlue (formerly Agile1) is a managed breach detection company with an Autonomous SOC-as-a-Service for 24×7 monitoring, detection and guided response.

VC3

VC3

VC3 provides a full range of Information Technology Solutions and Services to hundreds of municipalities and organizations throughout the USA.

Elastio

Elastio

Elastio's cloud-native platform safeguards cloud data from the risks posed by ransomware, application failures and storage security vulnerabilities.

Nuke From Orbit

Nuke From Orbit

Nuke's mission is to put you back in control of your digital identity when your smartphone gets stolen.