One-third of organizations changed leadership due to a cyberattack, while CISOs are more likely to consider paying a ransom than CIOs, a recent Rubrik report showed.
The State of Data Security report was conducted by Wakefield Research and commissioned by Rubrik. It surveyed 1,625 IT and security leaders including CISOs, CIOs, VPs, and directors across 10 countries.
It found that both the volume and impact of cyberattacks continue to rise as nearly all respondents stated their organizations experienced at least one attack over the past year and an average of 47, which means almost one attack per week. Plus, 52% of those surveyed reported at least one data breach, and 51% suffered at least one ransomware attack in the same timeframe.
Those experiences are taking a toll on the leadership teams, Rubrik noted. The vast majority (96%) of surveyed leaders stated they experienced significant emotional or psychological consequences as a result of a cyberattack, including worries over job security (43%) and loss of trust from colleagues (37%).
In fact, nearly one-third of those organizations were forced to change leadership because of the attacks.
“The individuals on the front lines are taking a psychological hit on their well-being. Trust is down and anxiety is up. Without a proactive and reliable approach to defend against modern cyberthreats and strengthen confidence in an organization’s ability to resolve these cyber events, these impacts - both human and organizational – will continue to worsen and feed each other,” Steven Stone, Head of Rubrik Zero Labs, said in a statement.
“We often overlook the psychological dimension of cyberattacks and the chaos that tends to follow after discovering an incident,” echoed Chris Krebs, former director of the Cybersecurity and Infrastructure Security Agency (CISA). “In the end, IT and security leaders alike tend to take the blame for these cyberattacks.”
“One of the most effective techniques I’ve seen to prepare for these types of attacks is to accept you’re going to have a bad day at some point, and your job is to ensure that it doesn’t become a ‘worse day.’ This is why we need defenders across the spectrum to come together – sharing best practices, learnings after attacks, simulations, frameworks – so that we’re collectively strengthening our defenses and minimizing the psychological impact brought on by an attack,” he added.
Rubrik: Two Places Where CIOs, CISOs Are MisalignedThe report surveyed 411 CIOs and 408 CISOs and found that despite both roles being key during a cyber incident, they might have slightly different stands on ransomware payments.
Ten percent of the surveyed CIOs are “extremely likely” to consider paying a ransom during an attack, compared to 13% of the surveyed CISOs, 38% of the CIOs vs. 47% were “very likely,” while 26% of CIOs are at least “not too likely” to consider compared to 15% of CISOs.
CIOs do have more confidence than CISOs that they have the trust of their board members or executive teams about their abilities to recover the data or business from a cyberattack. Around 70% of the CIOs respondents reported they are “completely or usually confident” on this point while 57% of CISOs were. And about 30% of the CIOs and 43% of the CISOs expressed critical or no confidence in this trust.
The gap might be partly because CISOs are more likely to be heavily scrutinized or pay the price following an incident.
Ron Layton, VP of cyber fusion and asset protection at Sallie Mae Bank, said during an earlier Industry Leaders Forum CxO Roundtable that some CISOs find themselves “in hot water” despite the think that security responsibility should be spread out among the organization.
Comments