Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Study calls for more C-level involvement in cybersecurity

Cyberbreaches can cost organizations millions of dollars, a new report says

Organizations with top executives who aren't involved in cybersecurity decisions face a serious problem -- a major hit to their bottom lines, according to a report released Wednesday.

"Many organizations see cybersecurity as solely an IT problem," said Karen Hughes, director of homeland security standards programs at the American National Standards Institute (ANSI), one of the major sponsors of the new report. "We are directing a wake-up call to executives nationwide. The message is, this is a very serious issue, and it's costing you a lot of money."

The report, called "The Financial Management of Cyber Risk," recommends how C-level executives can implement cybersecurity risk management programs at their companies. Part of the goal is to get executives such as chief financial officers directly involved in cybersecurity efforts, said Larry Clinton, president of the Internet Security Alliance (ISA), the other major sponsor of the report.

The report cites a cyberpolicy review released by President Barack Obama's administration last May saying that U.S. businesses lost US$1 trillion worth of intellectual property to cyberattacks between 2008 and 2009. That number doesn't include losses due to theft of personal information and loss of customers, the report said.

The total cost of a typical breach of 10,000 personal records held by an organization would be about $2 million, the report said.

"We believe if we can educate American organizations about how much they're actually losing, we can move to the next step, which is solving the problem," Clinton said. Eighty to 90 percent of cybersecurity problems can be avoided by a combination of best practices, standards and security technology, but some organizations need to understand the financial problems associated with poor security practices before they will make changes, Clinton said.

A small percentage of company CFOs are directly involved in cybersecurity plans at their companies, and at many companies, most employees don't see cybersecurity as part of their jobs, Clinton said. "In American organizations, everybody has data," he said. "Generally, people don't think it's their responsibility to secure their own data. They think that's the job of the IT guys down at the end of the hall."

IT departments at many U.S. companies and organizations are viewed as cost centers, not profit centers, and are "starved for resources," Clinton added. Many employees don't understand, or are intimidated by, the cybersecurity tools their companies have, the report said.

U.S. organizations need to understand that in today's connected world, their lack of security can hurt their customers, their partners and national security, Clinton and other cybersecurity experts said at a press conference.

Cybersecurity product vendor Symantec released 2.7 million signatures to fight malicious code in 2009, more signatures than in the previous 25 years combined, said Justin Somaini, the company's chief information security officer. The majority of that malicious code was in the form of Trojans targeting intellectual property and personal information, he said.

Somaini called the ISA/ANSI report a "call to arms" for U.S. organizations.

"Most information security organizations struggle with implementing even the most basic solutions," Somaini said. "Most of the struggle comes from resistance within the organization."

The report recommends ways companies can deal with cyberrisk. Among the recommendations for top executives: Appoint a cyberrisk team, develop a cyberrisk management plan across all departments and develop a total cyberrisk budget.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Internet Security Alliance, Symantec
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: cybersecurity, executive, security
Latest Blog Posts
Whitepapers
  • OVUM Report: Governance Risk and Compliance-- GRC usage and buying trends in the ANZ markets
    The existence of an established and stable governance risk and compliance strategy is extremely important to public and private sector organisations as they strive to meet an evergrowing range of regulatory demands. Given the current constraints, it is one of the few areas where the vast majority of organisations intend to either maintain or in many cases increase spending. Read more.
    Learn more »
  • Transforming Software Delivery: An IBM Rational Case Study
    The IBM Rational® software development organization consists of more than 2000 analysts, architects, project managers, developers, and quality professionals distributed over 15 locations on six continents. Our mission is to ensure the success of our customers through the development of a robust portfolio of software and systems delivery products. We create and maintain 57 product families that span distributed, System z®, and Power® operating environments.
    Learn more »
  • Workshifting: How IT is Changing the Way Business is Done
    While workshifting delivers powerful benefits, from increased productivity and improved cost-efficiency for both business and IT, to improved recruitment and retention, to business continuity and security, it also poses significant challenges for IT. The following discussion examines the forces driving the rapid rise of workshifting, the forms it can take, the IT challenges that must be addressed to enable it, the technologies now available to unlock its full value and the resulting benefits for the business.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments