HomeSecurityCybersecurity: Many managers simply don't want to understand the risks

Cybersecurity: Many managers simply don't want to understand the risks

Senior executives put businesses at risk of cyberattacks and data breaches because they don't understand cybersecurity issues and, in some cases, simply don't want to learn about the risks.

See also: Managers believe their systems are unbreakable

Cybersecurity: Many managers simply don't want to understand the risks

According to a survey by cybersecurity firm Trend Micro, only half of IT decision-makers believe the board understands cybersecurity risks. Of the 5,321 IT leaders surveyed, 90% said the board is not focused on cybersecurity because it has other priorities, such as digital transformation or improving productivity. As a result, they see cybersecurity as an obstacle to achieving their preferred goals.

However, there is also a significant minority of board members who simply don’t make the effort to learn about cybersecurity. According to the survey, 26% don’t try hard enough to learn about cybersecurity risks, while 20% simply don’t want to understand the cybersecurity risks their organization faces.

See also: IT managers don't care if their employees are happy

This lack of understanding is causing tension between information security teams and management, to the point that 82% of IT decision-makers say they have felt pressure to downplay the severity of cybersecurity risks to their board.

Nearly a third of these individuals say this is a constant pressure, indicating that many managers would rather bury their heads in the sand than deal with cybersecurity issues.

Nearly two-thirds (62%) said the board would only consider cyber risks if the organization suffered an attack or data breach, while 61% said they would be forced to notify it if customers requested enhanced security.

Cybersecurity: Many managers simply don't want to understand the risks

But even when boards and executives are concerned about cyberattacks and communicate with cybersecurity leaders about issues, detailing the risks and how to manage them can prove difficult, especially if executives don't have a strong technical understanding of the issues.

Therefore, it is vital that information security teams break things down for executives, regularly explaining issues – and, importantly, in ways that senior executives can understand.

See also: Small business workers: We've relaxed about cybersecurity since we've been working from home

It is recommended that the CISO report directly to the CEO in order to directly expose him to cybersecurity issues, helping to promote discussions around cybersecurity.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS