Cyber Security Pros Are Feeling The Pressure

Security is now one of the most important functions in the enterprise. It’s also an area that is increasingly vulnerable to evolving cyber threats; ones that include AI and automation, for example.  It is a case of when, not if an organisation is breached.

This inevitability does not alleviate pressure, it enhances it. And, it is no wonder that cyber security professionals are feeling the pressure. 

To find out the extent of this pressure Nominet commissioned a survey of 408 CISOs in the UK and US; each overseeing the cyber security of businesses that have an average of just under 9,000 employees.

Increasing Stress Levels

Stress is a normal part of any job, to an extent. The report found that almost every CISO suffers moderate or high stress, with 60% saying that they rarely disconnect from their job. They are also working long hours, again, there’s nothing wrong with this: to an extent.

An overwhelming, 88% of those CISOs surveyed are working more than forty hours a week, while 22% said they are available 24/7. The US CISO is particularly bad at disconnecting: 89% said they never have a break for two weeks or more from work.

All of this is causing a physical response to a very digital problem. Over a quarter of those questioned said stress is impacting their mental or physical health, while 23% said the job is eroding their personal relationships.

Most concerning is the 17% of CISOs who admitted to turning to medication or alcohol to deal with job stress.

Dr Dimitrios Tsivrikos, a business psychologist and lecturer at University College London, said: “It is of paramount importance that we address organisational stress and extra emphasis ought to be paid to CISOs. As a group of employees, they are faced with overwhelming pressure. Errors in their judgment, caused by excessive work-related stress, can indeed have detrimental effects upon business and personal data.

“In addition, individuals who are stressed at work are oftentimes not living their best lives privately, either. Most of us find it difficult to suppress the pressures from work, and they do indeed spill over into our private life. This poses significant health-related threats to personal well-being as individuals rely on alcohol and other non-constructive behaviours in order to relax and find relief from those pressures.”

Internal Pressures

Security has always had a strained relationship with the c-suite or board. It wasn’t that long ago that security was not even taken that seriously, and now it should be a top priority from the top. Naturally, this has caused tensions and perhaps, is a reason why the relationship is strained.

Indeed, the report highlighted that 18% of CISOs believed their board members are indifferent to the security team, or see them as an inconvenience. This lack of engagement is troubling, as only 60% of CISOs said that their CEO/president agrees a breach is inevitable.

Further, nearly a third of all those questioned believed that, in the event of a breach, they would either lose their job or receive an official warning, what a wonderful company to work for!

This is worse in the UK, as 37% of CISOs said they would receive a warning or be fired, compared with 28% in the US.

Resource Conundrum

Despite awareness about the pervasiveness of cyber threats, 60% of CISOs questioned admitted having found malware on their infrastructure (which had been there for an unknown period of time). More than half of CISOs (57%) said a lack of resources is what holds back an effective security posture, while 63% said they were struggling to recruit the right people.

Echoing the internal pressures, CISOs also stated that a lack of senior buy-in was the issue, with 65% claiming this as a barrier within their organisation.Budget constraint was identified as a growing challenge. Fewer than half of respondents said that they have adequate, or very adequate budget to tackle cyber-attacks. Only half said they had adequate or very adequate technology.

Modern Cyber Security Professional

The heightened cyber threat facing organisations is having some very physical effects on the cyber security professional.

Russell Haworth, CEO, Nominet said: “CISOs around the world are facing mounting pressures amid a rapidly shifting cyber landscape. Criminals are forever finding ways to exploit vulnerabilities, and do not discriminate against the businesses they attack. Everyone is a target.

“It’s no surprise that CISOs are facing burnout. Many lack support from within their organisations, and senior business leaders need to face the facts: the threats are real, and CISOs need to be given the resources and support to tackle them. If not, the board must face the consequences.

“The risk is not only personal to a CISO, but a business’ hard-won reputation. The growing economic cost is also a worrying trend. And a recent report put the cost of global cybercrime at $600 billion in 2017.

“With that cost likely to rise in the future. We must all work harder, and cooperatively, to mitigate potential losses by having the right strategy, tools and resource in place to prevent breaches in the first place.”

Information Age

You Might Also Read: 

Meeting The Cyber Talent Challenge Head-On:

 

« Blockchain’s Newest Application Is Civil Aviation
What Is Data Fusion? »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

QMS International

QMS International

QMS is one of the leading ISO certification bodies in the UK and serves clients worldwide.

Cato Networks

Cato Networks

Cato connects your branch locations, physical and cloud datacenters, and mobile users into a secure and optimized global network in the cloud.

Compass Security

Compass Security

Compass Security is a specialist IT Security consultancy firm based in Switzerland. Services include pentesting, security assessments, digital forensics and security training.

ID Quantique (IDQ)

ID Quantique (IDQ)

ID Quantique is a world leader in quantum-safe crypto solutions, designed to protect data for the long-term future.

SparkLabs Cyber + Blockchain

SparkLabs Cyber + Blockchain

SparkLabs Cyber + Blockchain accelerator is located in Washington D.C. which is one of the world's top cybersecurity ecosystems.

Blu Venture Investors (BVI)

Blu Venture Investors (BVI)

Blu Venture Investors is a venture capital firm that supports early stage companies with a focus on technology in diverse domains including cybersecurity, IoT, defense and homeland security.

AlertSec

AlertSec

AlertSec Ensure is a U.S. patented technology that allows you to educate, verify and enforce encryption compliance of third-party devices.

oneclick

oneclick

oneclick is a central access and distribution platform in the cloud, enabling the management of the entire technology stack for application provisioning.

ditno

ditno

ditno uses machine learning to help you build a fully governed and micro-segmented network. Dramatically mitigate risk and prevent lateral movement across your organisation – all from one centralised

Thistle Technologies

Thistle Technologies

Thistle Technologies is building tools that help connected device manufacturers build security resiliency into devices.

Resolvo Systems

Resolvo Systems

Resolvo is provides comprehensive security assessment and testing services in Asia.

SOOS

SOOS

SOOS is the easy-to-integrate software security solution for your whole team. Build, catch, and fix vulnerabilities with SOOS Software Composition Analysis.

Sure Valley Ventures

Sure Valley Ventures

Sure Valley Ventures is an entrepreneur led venture capital fund focused on helping software entrepreneurs grow and scale businesses that will have a global impact.

Benchmark IT Services (BITS)

Benchmark IT Services (BITS)

BITS is a leading cyber security company in Australia. Our certified professionals work with you to keep your data assets safe and secure.

Security Discovery

Security Discovery

Stay ahead of cyber threats with Security Discovery. We offer expert consulting, comprehensive services, and a powerful vulnerability monitoring SaaS platform.

Kong

Kong

Kong - powering the API world. Increase developer productivity, security, and performance at scale with the unified platform for API management, service mesh, and ingress controller.