When it comes to cybersecurity readiness, C-level executives are not resting on their laurels – their most important objective is to meet and exceed compliance objectives, according to a new survey on the state of cybersecurity from Bell Canada.
The other top outcomes organizations are striving for include the following:
- Maintaining a high level of security posture confidence with business stakeholders
• Achieving the best possible rates for cyber insurance
• Having highly satisfied security staff (and lower turnover rates of security personnel)
• Avoiding cybersecurity breaches in the past 12 months
While many organizations report a high level of achievement across multiple key security outcomes, only 1.6% of Canadian businesses report high achievement on all top five indicators, the survey found.
Further, nearly two-thirds of respondents had breaches in the last year. Almost half occurred in cloud environments, according to the report.
[Related: CrowdStrike, Trend Micro, Bitdefender, Microsoft lead Forrester’s Wave for endpoint security]
Although breaches are the most direct performance indicator of any security program, most CISOs Bell surveyed found performance against compliance requirements and the ability to retain talented staff as important indirect indicators.
The importance of governance and cultureContrary to popular belief, cybersecurity success is often not determined by budget. The study found that there are other factors that matter more — and although they may require dollar investment as well as time, “optimized resource allocation trumps total budget size.”
Organizations with well-defined security governance outperform their peers, according to the Bell study. For this process to be successful, it needs to be a collaborative approach across the business. This is due in part to the fact that executing well on technical guardrails (e.g., configuration management, policy-as-code, access management, etc.) relies on agreed-upon risks, boundary lines, and responsibilities spread across the organization, the study found.
“Inadequate governance and/or security culture can undermine even the best talent and tools that money can buy,” according to the report. “Therefore, before examining technical controls, we start with governance and culture.”
The study also found that organizations that do the best at establishing and enforcing governance for acceptable use of cloud services are twice as likely to report exceeding compliance requirements.
To achieve good governance, the Bell study recommends building a set of metrics around your inventory of assets as a “natural starting point.” The study suggested asking this set of questions:
- How much attack surface coverage do I have?
- What is the change in exposure?
- How much time does it take to resolve issues?
- How quickly can we reduce our backlog of issues?
The report also advises that organizations create a culture that is comfortable learning and being open to experimentation within defined guardrails in the cloud; one that offers flexible architecture, rapid development and increased security automation.
“In a cloud-native world, governance is more easily reflected in software such as policy-as-code to manage risk in real time and/or limit the downside of experimentation,’’ the report said. “Organizations that achieve better security outcomes indicate that they embrace change. For example, organizations using large language models (LLMs) such as ChatGPT for security operations in production show improved security outcomes.”
Security program success factorsThe Bell study identified 29 factors that correlate with significantly higher success rates for at least one of the executives’ outcomes. The factors include the following:
- High integration of security in DevOps
- Establishing acceptable use of cloud
- Anticipation of IT and business needs by security
- Having strong recovery and resilience capabilities
- High integration among security technologies
For example, organizations reporting strong recovery and resilience capabilities report success rates that double those with lower integration.
Other success factors include establishing the level of risk for acceptable use of cloud services, close alignment between business and security strategies as a strategy for achieving stronger outcomes, a willingness to experiment with and adopt new technologies, and fostering a strong security culture.
MethodologyBell said it surveyed 402 organizations across the public and private sector to learn how they are achieving key outcomes and to see what activities might spur improvements.
Comments