Organizations could be at risk from cyberattacks due to a significant gap between the views of their own security experts and managers.
See also: Small business workers: We've relaxed about cybersecurity since we've been working from home

The World Economic Forum's new report, The Global Cybersecurity Outlook 2022, warns that there are wide discrepancies between managers and information security personnel regarding the state of cyber resilience within organizations.
According to the newspaper, 92% of business executives (managers) surveyed agree that cyber resilience is integrated into business risk – or in other words, protecting the organization from being the victim of a cyberattack or mitigating the incident so that it does not result in significant disruption.
However, only 55% of security-focused executives believe that cyber resilience is integrated into risk management strategies – suggesting a significant difference in attitudes towards cybersecurity.
See also: Many businesses are still unwilling to spend money on cybersecurity
This gap can leave organizations vulnerable to cyber attacks because managers believe enough has been done to mitigate threats, when in reality there could be negligible vulnerabilities or additional measures that could be taken.
One of the reasons this cybersecurity gap exists is because chief information security officers (CISOs) and other cybersecurity personnel often feel like they are not being consulted. This gap means that security is sometimes sacrificed in the name of efficiency or cost, which can have disastrous consequences.

For example, take the challenge of ransomware. Many ransomware attacks are successful because cybercriminals are able to exploit vulnerabilities in networks that could have been rendered harmless if standard security recommendations were followed – for example, implementing two-factor authentication, creating backups, or applying cybersecurity updates.
However, businesses may be reluctant to spend money on these areas or the staff required to ensure they are properly developed, viewing it as a cost rather than an investment that will prevent further spending of additional money.
See also: Cybersecurity: Graduates double but skills remain the same
Often managers only pay attention to security issues when the company falls victim to a cyberattack. Of course, this is not the desired way to pay attention. The right way is to take measures before any breach occurs.
Information source: zdnet.com
