Back to Insights Risk Management

Cybersecurity managers: Optimistic in the face of attacks? Don’t be

A survey by KPMG reveals a complex picture among C-level cybersecurity executives. Although a significant portion (40%) reported recent cyberattacks, CISOs remain optimistic about their defensive capabilities. The survey, which targeted senior executives at companies with revenues of $1 billion or more, sheds light on the evolving cybersecurity landscape.

Key Findings:
* Increase in Attacks: A concerning number of executives (38%) reported experiencing 1-3 attacks in the past year.
* Growing Threats: Sophisticated cybercrime groups, insider threats from employees and contractors, and independent hackers.
* Confidence vs. Breaches: Interestingly, even those who experienced attacks expressed confidence in their Security Operations Centers (SOC).
* AI as a Game Changer: Two-thirds of executives view AI-based automation as an essential tool for addressing emerging threats and improving SOC agility.
* Remaining Challenges: Security managers struggle with data quality, low-level alert fatigue, and the skill shortage.
* Budgetary Optimism: Despite the challenges, most executives expect an increase in headcount and budget over the next two years.

Conclusion: C-level cyber executives are facing a complex reality. While they are optimistic about their defensive capabilities, they acknowledge that threats are becoming increasingly sophisticated. The survey emphasizes the growing importance of AI and the need to address the skills gap to maintain cybersecurity resilience.

Insights from Senior Cyber Experts at IPV Security:
* Upgrading the Security Operations Center (SOC): Enhance the SOC through advanced training and exercises, sophisticated monitoring and detection tools, and comprehensive, up-to-date response plans.
* Leveraging AI and Automation: Integrate artificial intelligence across all security domains, validate AI recommendations, and address workforce concerns.
* Improving Data Quality and Alert Management: Implement rigorous data management processes and utilize machine learning for alert classification.
* Strengthening Recruitment and Retention: Invest in continuous training, build attractive career paths, and promote a positive work environment.
* Increasing Budget and Resources: Focus on critical areas, measure ROI, and collaborate with stakeholders.
* Proactive Management of Emerging Threats: Stay updated with threat intelligence, collaborate with peers, and implement a “Zero Trust” model.

In summary, the KPMG study presents a complex reality. By implementing these recommendations, organizations can strengthen their cyber resilience and stay one step ahead of evolving threats.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation