Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cyber Security Must Be A C-Suite Priority
Articles

Cyber Security Must Be A C-Suite Priority

ISBuzz TeamBy ISBuzz TeamAugust 19, 20166 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Digital technology has fundamentally changed business practice over the past decade. Cloud based applications dominate, workers routinely access corporate information remotely via smart phones and access to the corporate network increasingly includes supply chain members, contractors and part time workers.  Yet cyber security has failed to keep up – and some of the responsibility has to lie with the C-suite.

Why are cyber security experts not involved from day one in every strategic decision? Why are businesses still expecting the security team to take responsibility yet leaving deployment in the hands of multiple departments, from application development onwards? It is time to address the fragmented, outdated, reactive attitudes to cyber security that still dominate. By failing to embrace security expertise and innovation up front, businesses are incurring far too much risk.  Adam Boone, Chief Marketing Officer, Certes Networks, insists it is time make cyber security a priority for every C-suite.

Exploding Attack Surface

 While it is hard to imagine a new business initiative or strategic development that is not IT driven, only 45% of boards participate in overall security strategy. Yet not only is technology underpinning every aspect of business, the increasingly fluid and agile way in which businesses now operate has fundamentally changed the threat landscape, most notably by massively expanding the attack surface. The number of applications now being used by a huge and diverse user base, both within and outside the organisation, across personal smartphones, in the cloud and, of course, IoT devices, has created a level of risk never before encountered. Each one of those users or end-points becomes a target, a point of potential vulnerability. Just consider that one hacked company can compromise the operations of every business along an entire supply chain. Or a single contractor who is compromised by an attack can become the steppingstone into the heart of your company. Cyber security practices clearly have not kept up with this exploded attack surface, the near daily exposure of breaches confirms.

The implications of this lack of senior level participation in cyber security strategies are tangible.  First of all, security is reactive, with experts consulted after strategic business decisions have been taken and IT deployments rolled out – leaving gaping holes in the security plan that simply cannot be effectively filled retrospectively. Secondly, responsibility for security is not centralised but fragmented across multiple silos – from application developers to network teams and those responsible for remote access or end-point protection.

The result is that while security may be tasked with safeguarding the business, achieving that objective can require interfacing with up to eight different groups – all of which are focused on their own areas of responsibility, rather than security. In some cases security is not the overriding, top priority of these teams, who are focused instead on application or network performance and other fundamental functions.  Even then security procedures and tools are implemented piecemeal, creating a fragmented and confused picture across the organisation.

While security remains a secondary business consideration and security teams lack central control, the corporate risks will continue to rise.

Best Practice in Cyber Security

 The difference between those organisations that have a top-level commitment to security and the rest is stark.  The best practice approach ensures security is considered, evaluated and incorporated into the planning stages of every corporate strategy – not addressed after the fact. Furthermore, a dedicated security team – preferably led by a Chief Information Security Officer (CISO) – has full, centralised control over policy and implementation enabling the business to achieve uniform security across the entire enterprise, rather than the fragmented, even contradictory solutions often deployed on a departmental basis.

Critically, with security people involved in the planning stage from day one, the company can ensure best security practices are baked in to the project from the outset – and that best practice cyber technologies can be embraced to both improve defence and drive business value.

Software-Defined Model

 For example, replacing a traditional – and vulnerable – rigid firewall with a software-defined perimeter that is far more fluid enables a business to remain secure despite constant operational change. A software-defined perimeter that is disconnected from the infrastructure can drastically simplify the complexities of adding or removing cloud applications, or granting mobile access for a specific set of workers.  Similarly, the adoption of software-defined Wide Area Networks (SDWAN) enables organisations to securely embrace the lower cost cloud computing model while maintaining every aspect of the security posture – from policies to encryption.

Essentially, with a centralised approach and a security strategy aligned with business direction, organisations can move away from outdated thinking about securing the perimeter. Simply put, security can no longer be about managing devices and networks. It must instead be focused on managing users and applications, and tightly aligned with the business objectives associated with both. For example, role-based access control can enable an enterprise to consistently enforce policies across the range of users and applications, directly aligning that critical security function of remote access with the overarching business objectives. Which applications do physicians need to access in order to do their jobs? Which do the nurses need? Which should never be accessed by either?

The most effective approach enforces these policies in the actual access control process itself, building on existing policies for user access and identity management. Then, when access is to be granted, the application traffic is protected by cryptographic segmentation that prevents it from being accessed by the non-permitted users.

This approach has the added benefit of blocking unauthorised lateral movement, which is the hallmark of modern data breach vectors. If all applications are protected by real-time role-based access control, and if all user access is limited to only what a user needs to do their jobs, then the compromise of one user does not grant access to everything. Lateral movement is constrained and the breach is contained.

Organisations that embed this software-defined model within strategic planning not only minimise risk but also support business innovation. Consider a company looking to deploy a new application to its workers that will increase productivity by 40%. Roll that out to the 50% of staff that work at HQ and the benefits are clear; but build in security planning from day one and that application can be securely extended to mobile workers on their smart phones and part time contractors – suddenly the 40% productivity gain is massively extended, boosting performance and delivering ROI for the application itself far, far quicker.

Conclusion

 When every business decision has a technology implication, cyber security clearly needs to be led from the top; it must be organisation-wide rather than silo-focused; centralised and consistent. Done well, security is not simply a defensive strategy, but an enabler of better enterprise performance – and those organisations with a C-suite that prioritises cyber security are not only in a far better position to minimise risk but also well placed to drive tangible business value.

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}