Cyber Security Pros Are Feeling The Pressure

Security is now one of the most important functions in the enterprise. It’s also an area that is increasingly vulnerable to evolving cyber threats; ones that include AI and automation, for example.  It is a case of when, not if an organisation is breached.

This inevitability does not alleviate pressure, it enhances it. And, it is no wonder that cyber security professionals are feeling the pressure. 

To find out the extent of this pressure Nominet commissioned a survey of 408 CISOs in the UK and US; each overseeing the cyber security of businesses that have an average of just under 9,000 employees.

Increasing Stress Levels

Stress is a normal part of any job, to an extent. The report found that almost every CISO suffers moderate or high stress, with 60% saying that they rarely disconnect from their job. They are also working long hours, again, there’s nothing wrong with this: to an extent.

An overwhelming, 88% of those CISOs surveyed are working more than forty hours a week, while 22% said they are available 24/7. The US CISO is particularly bad at disconnecting: 89% said they never have a break for two weeks or more from work.

All of this is causing a physical response to a very digital problem. Over a quarter of those questioned said stress is impacting their mental or physical health, while 23% said the job is eroding their personal relationships.

Most concerning is the 17% of CISOs who admitted to turning to medication or alcohol to deal with job stress.

Dr Dimitrios Tsivrikos, a business psychologist and lecturer at University College London, said: “It is of paramount importance that we address organisational stress and extra emphasis ought to be paid to CISOs. As a group of employees, they are faced with overwhelming pressure. Errors in their judgment, caused by excessive work-related stress, can indeed have detrimental effects upon business and personal data.

“In addition, individuals who are stressed at work are oftentimes not living their best lives privately, either. Most of us find it difficult to suppress the pressures from work, and they do indeed spill over into our private life. This poses significant health-related threats to personal well-being as individuals rely on alcohol and other non-constructive behaviours in order to relax and find relief from those pressures.”

Internal Pressures

Security has always had a strained relationship with the c-suite or board. It wasn’t that long ago that security was not even taken that seriously, and now it should be a top priority from the top. Naturally, this has caused tensions and perhaps, is a reason why the relationship is strained.

Indeed, the report highlighted that 18% of CISOs believed their board members are indifferent to the security team, or see them as an inconvenience. This lack of engagement is troubling, as only 60% of CISOs said that their CEO/president agrees a breach is inevitable.

Further, nearly a third of all those questioned believed that, in the event of a breach, they would either lose their job or receive an official warning, what a wonderful company to work for!

This is worse in the UK, as 37% of CISOs said they would receive a warning or be fired, compared with 28% in the US.

Resource Conundrum

Despite awareness about the pervasiveness of cyber threats, 60% of CISOs questioned admitted having found malware on their infrastructure (which had been there for an unknown period of time). More than half of CISOs (57%) said a lack of resources is what holds back an effective security posture, while 63% said they were struggling to recruit the right people.

Echoing the internal pressures, CISOs also stated that a lack of senior buy-in was the issue, with 65% claiming this as a barrier within their organisation.Budget constraint was identified as a growing challenge. Fewer than half of respondents said that they have adequate, or very adequate budget to tackle cyber-attacks. Only half said they had adequate or very adequate technology.

Modern Cyber Security Professional

The heightened cyber threat facing organisations is having some very physical effects on the cyber security professional.

Russell Haworth, CEO, Nominet said: “CISOs around the world are facing mounting pressures amid a rapidly shifting cyber landscape. Criminals are forever finding ways to exploit vulnerabilities, and do not discriminate against the businesses they attack. Everyone is a target.

“It’s no surprise that CISOs are facing burnout. Many lack support from within their organisations, and senior business leaders need to face the facts: the threats are real, and CISOs need to be given the resources and support to tackle them. If not, the board must face the consequences.

“The risk is not only personal to a CISO, but a business’ hard-won reputation. The growing economic cost is also a worrying trend. And a recent report put the cost of global cybercrime at $600 billion in 2017.

“With that cost likely to rise in the future. We must all work harder, and cooperatively, to mitigate potential losses by having the right strategy, tools and resource in place to prevent breaches in the first place.”

Information Age

You Might Also Read: 

Meeting The Cyber Talent Challenge Head-On:

 

« Blockchain’s Newest Application Is Civil Aviation
What Is Data Fusion? »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

SSL247

SSL247

SSL247 is Europe's leading Web Security Consultancy Firm. We enjoy long-standing partnerships with Certificate Authorities including Symantec, GlobalSign, Entrust Datacard, Comodo, Thales and Qualys.

Spambrella

Spambrella

Spambrella provides email security with real-time threat protection. 100% SaaS (nothing to install)

CIRCL

CIRCL

CIRCL is the national Computer Incident Response Center of Luxembourg

Athena Forensics

Athena Forensics

Athena Forensics is one of the UK's leading providers of Computer Forensics, Mobile Phone Forensics, Cell Site Analysis and Expert Witness Services.

CCL Solutions Group

CCL Solutions Group

CCL is one of Europe’s leading digital investigation specialists, supporting law enforcement, government and organisations across both public and private sectors.

Global Learning Systems (GLS)

Global Learning Systems (GLS)

Global Learning Systems provides security awareness and compliance training programs for employees that effectively promote behavior change and protect your organization.

Cipher Tooth

Cipher Tooth

CipherTooth is a superior system for delivering secure content over the Internet.

NetGuardians

NetGuardians

NetGuardians is a leading Fintech company recognized for its unique approach to fraud and risk assurance solutions.

ES2

ES2

ES2 is a consulting organisation specialising in Enterprise Security and Solutions Services.

e-End

e-End

e-End provides hard drive shredding, degaussing and data destruction solutions validated by the highest electronic certifcations to keep you compliant with GLB, SOX, FACTA, FISMA, HIPAA, COPPA, ITAR.

Palantir

Palantir

Palantir software empowers entire organizations to answer complex questions quickly by bringing the right data to the people who need it.

Open Quantum Safe (OQS)

Open Quantum Safe (OQS)

The Open Quantum Safe (OQS) project is an open-source project that aims to support the development and prototyping of quantum-resistant cryptography.

People Driven Technology

People Driven Technology

People Driven Technology is a customer-obsessed organization. We leverage our decades of business, technology, and engineering experience to deliver outcomes for our clients.

Three Wire Systems

Three Wire Systems

Three Wire is a leader in innovative and efficient technology solutions for government agencies and large enterprise corporations.

Hunt & Hackett

Hunt & Hackett

Hunt & Hackett helps European companies prevent, detect and respond to today’s most advanced adversaries, safeguarding them against cyberthreats and espionage.

Heritage Cyber World

Heritage Cyber World

Heritage Cyber World is a one stop solution for all your security needs that brings together a team of security experts and analysts to deliver high-class security services.