Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Business and Policy - Underfunding and Leadership Gaps Weaken Cybersecurity Defenses
Business and Policy Articles Security Study & Research

Underfunding and Leadership Gaps Weaken Cybersecurity Defenses

Anastasios ArampatzisBy Anastasios ArampatzisSeptember 25, 2024Updated:November 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybersecurity Defenses
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Despite cyber risk growing at an alarming rate, a recent global study from Trend Micro, highlights that many organizations are failing to implement adequate cybersecurity measures due to a lack of strategic leadership and investment.

Key Findings of the Report

According to the study, which surveyed 2,600 IT leaders across regions including North America, Europe, and APAC, cybersecurity gaps are widening as the attack surface expands. In 2023, Trend Micro blocked 161 billion threats, marking a 10% increase from the previous year. However, despite the surge in digital threats, leadership across many organizations remains indifferent to the severity of these risks.

Alarmingly, 48% of respondents said their leadership did not consider cybersecurity to be their responsibility, leading to a fragmented approach to managing cyber risk. This is a significant concern, particularly as regulators around the world are increasingly demanding accountability from corporate boards. Both the U.S. Securities and Exchange Commission (SEC) and the European Union’s NIS2 directive now require that senior leadership plays a direct role in cybersecurity governance.

A Shortfall in Leadership and Resources

The report underscores that leadership neglect is not the only issue. Many organizations are under-resourced and over-reliant on overstretched IT teams. Nearly 96% of IT leaders expressed concern over the expanding attack surface, with 36% admitting they lacked the means to discover and mitigate high-risk areas. Furthermore, only 36% of the organizations surveyed can afford to have 24/7 cybersecurity coverage due to staffing gaps.

One of the report’s more concerning revelations is the tool sprawl many organizations are experiencing. Siloed and fragmented security tools, and the inability to consolidate data from different cybersecurity platforms are leaving organizations with significant visibility gaps. As a result, 19% of IT leaders admitted they are unable to manage cybersecurity from a unified source of truth, making it even harder to respond quickly to potential threats.

The Cybercrime Industry Thrives

While organizations struggle with internal issues, the cybercriminal underground continues to grow at an unprecedented rate. Worth trillions of dollars, this ecosystem provides everything from ransomware-as-a-service to AI-driven hacking tools, making it easier than ever for even novice attackers to launch sophisticated attacks. As cybercrime continues to evolve, the stakes are higher than ever for businesses that are slow to adapt.

According to the report, over half (54%) of the respondents believe their organization’s attitude toward cybersecurity varies month to month, illustrating the inconsistency in how companies approach risk management. This lack of a long-term strategic vision is a recipe for disaster, leaving organizations vulnerable to attacks that could result in severe financial and business disruptions.

Lack of Accountability: Who’s Responsible?

One of the central issues highlighted by Trend Micro is the confusion around who is responsible for cybersecurity. Only 42% of respondents believe that the CEO should be responsible for mitigating business risks related to cybersecurity, while others believe it should be the CIO (34%), the CISO (26%), or even the CFO (20%). The lack of clarity in roles and responsibilities is causing misalignment in cybersecurity strategy, which in turn hampers the effectiveness of an organization’s defense posture.

As regulatory pressures increase, organizations must adopt a more cohesive and accountable approach to cybersecurity. If leadership continues to push cybersecurity down the chain of command, they risk not only compliance fines but also the severe financial consequences of a breach.

Time to Act

The consequences of inaction are becoming clearer. With more regulations and potential criminal liability on the horizon, it is imperative for business leaders to prioritize cybersecurity as a core business issue. The message from Trend Micro’s study is clear: cybersecurity can no longer be someone else’s problem. It is a boardroom issue, and failure to address it could lead to disastrous consequences for businesses worldwide.

Anastasios Arampatzis
Anastasios Arampatzis

Anastasios Arampatzis is a cybersecurity content strategist, writer, and consultant with expertise in cybersecurity, digital identity, and regulatory compliance. Tassos has a strong background in creating thought leadership content, marketing materials, and strategic communications tailored to CISOs, security professionals, and business leaders. He has contributed to various cybersecurity publications and collaborates with organizations to develop compelling, insightful content that addresses industry challenges. He is a privacy advocate and a member of the ISC2 Hellenic Chapter. Before joining Bora, Tassos was an Hellenic Air Force Officer with a solid background on IT and Infosec.

  • Anastasios Arampatzis
    The quiet revolt: what the world happiness report 2026 tells security professionals
  • Anastasios Arampatzis
    Cybersecurity and the Power of Words: Why Security Must Be in Our DNA
  • Anastasios Arampatzis
    Have You Read the F***ing Policy?
  • Anastasios Arampatzis
    When Innovation Meets Education: Caution Before Celebrating ‘OpenAI for Greece’

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Rethinking the Security Estate: Why IT Spend Isn’t the Same as Cybersecurity Readiness

February 5, 20264 Mins Read

Have You Read the F***ing Policy?

December 2, 20254 Mins Read

UK insurers pay nearly £200m to help businesses recover from cyber attacks

November 12, 20252 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}