Cybersecurity

Why your Cybersecurity Strategy is Probably Out of Date

Many CEOs, however, still haven’t learned that lesson and are therefore in denial about the weakness of their cybersecurity strategies, according to at least one analytics firm.

After surveying 200 American CEOs, RedSeal and data company 72 Point found that 80% were confident in their company’s defenses, even as the frequency and cost of successful attacks surge.

“CEOs are underestimating their companies’ cyber vulnerabilities,” RedSeal CEO Roy Rothrock said. “Their confidence does not square with what we observe. Cyber attacks are up and financial losses associated with these attacks are increasing dramatically.”

“CEOs are underestimating their companies’ cyber vulnerabilities Cyber attacks are up and associated financial losses are increasing dramatically.

Cybercrime is now the second-most frequently reported economic crime by business, behind asset misappropriation, according to a survey released this year by PwC, jumping from the fourth-most reported crime a year earlier. The professional services firm also has forecast the combined costs of cyber attacks to grow to over $2 trillion in 2018, from around $500 billion in 2014.

The intelligence community, and some CEOs, have long warned that companies will be breached whether they like or not.

“It’s not a question of if you’re going to get hacked, but when you’re going to get hacked,” Verizon CEO Lowell McAdam said in October amid revelations its takeover target Yahoo had suffered a serious breach.

Even so, this most recent survey found that around half of its CEO respondents still prioritized keeping hackers out of their network, versus 24% who were concerned with building capabilities to deal with hackers once they’d gotten inside.

“Firewalls, virus detectors, and malware scans are required to keep out 99% of the bad guys, but the 1% who get in can cripple a firm, critical infrastructure or a government agency,” Rothrock said.

That’s why, he argues, CEOs need to focus on building resilience into their business so they can maintain operations in the event of a breach. This could involve creating a tactical response team, learning how to secure IT systems to contain breaches and preparing an effective public relations strategy.

Paul van Kessel, a cybersecurity adviser at EY, said companies have come a long way in preparing for a cyber breach. “But as fast as they improve, cyber attackers come up with new tricks,” he said.

EY this week published the results of a cybersecurity survey of 1,735 organizations globally. It found that 57% rated business continuity and disaster recovery as a high priority, but only 39% were planning to invest more in that area in the coming year.

Ross Kelly

Ross Kelly is a London-based business journalist. He has been a staff correspondent or editor at The Wall Street Journal, Yahoo Finance and the Australian Associated Press.

Share
Published by
Ross Kelly

Recent Posts

Calero CRO Eric Martorano Knows Stories Can Be Our Most Powerful Tool

Calero, argues that data informs but stories drive action—making narrative clarity a core leadership skill…

1 day ago

The 3 Lessons Of Tim Cook

There are many, of course, from the Apple CEO, who just announced he is stepping…

2 days ago

An Autism Diagnosis At 55 Reframed This CEO’s Entire Life

From naval combat to building companies, his remarkable ability to remain calm wasn’t coldness or…

3 days ago

Raising The Bar: A More Disciplined Way To Hire Senior Leaders

Without a forward-looking lens, even a well-run process can produce the wrong outcome.

6 days ago

The State Of The States: Who’s Building The Future Of Business?

As the nation marks a quarter millennium, Chief Executive’s annual CEO survey of the Best…

6 days ago

Best & Worst States For Business 2026: Inside The Rankings

Our annual survey of more than 650 CEOs, presidents and business owners—with representation from every…

6 days ago