<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/chief-information-security-officer-ciso" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Chief-information-security-officer-ciso ]]></title>
                <link>https://www.itpro.com/tag/chief-information-security-officer</link>
        <description><![CDATA[ All the latest chief-information-security-officer-ciso content from the ITPro team ]]></description>
                                    <lastBuildDate>Mon, 02 Mar 2026 12:52:46 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ CISOs are keen on agentic AI, but they’re not going all-in yet ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cisos-are-keen-on-agentic-ai-but-theyre-not-going-all-in-yet</link>
                                                                            <description>
                            <![CDATA[ Many security leaders face acute talent shortages and are looking to upskill workers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jmhzCf3SFWZDeX55vuRGNX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RsxvmUinC8pBjYifD2swgj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Mar 2026 12:52:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RsxvmUinC8pBjYifD2swgj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Agentic AI concept image with human heads lined up with larger robotic humanoid head in background.]]></media:description>                                                            <media:text><![CDATA[Agentic AI concept image with human heads lined up with larger robotic humanoid head in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Agentic AI concept image with human heads lined up with larger robotic humanoid head in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RsxvmUinC8pBjYifD2swgj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>are upbeat about the potential of <a href="https://www.itpro.com/security/cisos-bet-big-on-ai-tools-to-reduce-mounting-cost-pressures">AI tools in security operations</a>, new research shows, but the priority focus for many right now is filling workforce gaps. </p><p>Findings from Splunk’s annual <a href="https://tracking.us.nylas.com/l/5911eca1d51c4fa1b14708f0476e3ef4/3/97f6b9a43ab78b8d4cd26566838848c3ee52376ee368e97b369bdc90ebf50063?cache_buster=1772015263" target="_blank"><u>CISO Report</u></a> show AI adoption is a key priority, with 68% highlighting investment in this domain as a leading focus alongside improvements to threat detection and response capabilities and identity and access management (IAM).</p><p>Indeed, around 92% said the technology is helping their teams to review more security events while 89% reported improved data correlation. </p><p>Yet despite this, just 6% have fully deployed agentic AI in security operations, pointing to sluggish adoption rates. </p><p>More than one-third (39%) of CISOs who have partially or fully adopted agentic AI strongly agree it has increased their teams’ reporting speed - more than twice the rate of those who are still exploring the technology.</p><p>More than eight-in-ten (82%) of CISOs, meanwhile, believe agentic AI will increase the amount of data reviewed, and 82% said it will increase correlation and response speeds. </p><p>While the potential benefits of AI are tantalizing for security leaders, the other side of the coin is that 86% fear agentic AI will increase the sophistication of social engineering attacks. </p><p>Similarly, 82% believe it will increase deployment speed and complexity of persistence mechanisms.</p><h2 id="new-tools-mean-nothing-without-talent-for-cisos">New tools mean nothing without talent for CISOs</h2><p>Although AI is increasingly prevalent, CISOs don't expect technology to replace any security analyst jobs. Instead, they're prioritizing human capital to address critical skills gaps: upskilling current workforces, hiring new full-time employees, and engaging contractors. </p><p>The skillsets CISOs are most lacking in their security programs are threat hunting, engineering support - for vendor tooling, detection engineering, or maintenance - software development, and network and cloud architecture. </p><p>"Because of AI, CISOs will need to constantly reskill, upskill and bring in new talent required to achieve the ROI leadership wants. In this sense, AI will be creating jobs, not eliminating them," said Ryan Fetterman, senior manager, SURGe by Cisco Foundation AI.</p><p>Among those who rank threat hunting as their team’s biggest skills gap, 71% said upskilling their current workforce was a top means for addressing shortages. T</p><p>hose with bigger engineering gaps tend to focus on hiring new full-time employees, while hiring contractors is the answer for most of those whose biggest gap is software development.</p><p>This is easier said than done, however, with only 16% expecting to fill all their shortages.</p><p>“Investing in your teams, in part, means rethinking your hiring strategy. I challenge conventional wisdom that demands a cybersecurity degree or a decade of experience,” said Fanning. </p><p>"In a field where technical knowledge becomes obsolete quickly, a candidate’s foundational understanding of computing, systems, and networks — as well as curiosity, adaptability, and problem-solving skills — are far more valuable. Cyber knowledge can be taught, where needed, on top of that foundation.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Finance and security leaders are odds over cyber priorities, and it’s harming enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/finance-and-security-leaders-are-odds-over-cyber-priorities-and-its-harming-enterprises</link>
                                                                            <description>
                            <![CDATA[ Poor relations between the departments can be solved by CISOs talking in a language CFOs understand ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LsuRmw2wQRMkkRVxNf8Kda</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zhUkMSXoady8SubuouUmxa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 Jan 2026 12:28:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zhUkMSXoady8SubuouUmxa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[C-suite executives arguing over generative AI adoption strategies in an office boardroom.]]></media:description>                                                            <media:text><![CDATA[C-suite executives arguing over generative AI adoption strategies in an office boardroom.]]></media:text>
                                <media:title type="plain"><![CDATA[C-suite executives arguing over generative AI adoption strategies in an office boardroom.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zhUkMSXoady8SubuouUmxa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Finance leaders have a poor opinion of the performance of <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs</a>, believing that they can't always communicate clearly and aren't fully aligned with business needs.</p><p>A new survey of 300 CISOs, directors of cybersecurity, <a href="https://www.itpro.com/strategy/28221/cfo-job-description-what-does-a-cfo-do">CFOs</a>, and finance leaders by threat-hunting firm Expel found less than half (46%) of security leaders think their finance counterparts are highly aligned with the security team’s priorities.</p><p>Finance leaders, though, are less convinced, with only 35% believing that their security counterparts are highly aligned with the finance team’s priorities.</p><p>These conflicting perceptions on both sides of the divide further exacerbate existing issues with alignment, the study noted. </p><p>Crucially, there's a similar pattern when it comes to risk tolerance and budget expectations. While 71% of surveyed security leaders say that security and finance teams are fully or very aligned, finance decision-makers are much less positive, with only 58% saying the same.</p><p>"While most finance decision-makers see security as business-critical, they demonstrate a lower level of assurance in some of their security teams’ abilities," the researchers said.</p><p>Only half of surveyed finance leaders said they were very confident that their security team can communicate business impact clearly or protect the organization from major cyber events, while only four-in-ten express full confidence in security’s ability to align with <a href="https://www.itpro.com/business/business-strategy">business strategy</a>.</p><p>Security decision-makers, meanwhile, are suspicious that they're perceived negatively by finance, with 36% saying they're seen as a cost center and 35% as no more than an operational necessity. </p><p>"The real issue isn't that finance sees security as a cost center — it's that too many security leaders haven't learned to articulate value in terms finance understands," said Greg Notch, Expel chief security officer.</p><p>"Security leaders should spend their time showing how that cost translates to business protection. Finance teams make cost-benefit decisions all day long. They're not afraid of costs; they're afraid of costs they can't quantify or understand."</p><h2 id="how-cyber-leaders-can-shake-up-communication">How cyber leaders can shake up communication</h2><p>When reporting results to finance, surveyed security leaders typically prioritize metrics like business impact of actual security incidents at 18%, cost of control versus potential losses at 17%, security program maturity level at 16%, and risk reduction score at 15%.</p><p>However, researchers found these metrics don't align with what finance actually requires for making strategic decisions. In fact, program maturity level versus industry benchmarks is the second least popular metric among finance leaders.</p><p>"Instead of falling back on maturity metrics, leaders need to communicate in the language of risk, especially when justifying security spend," advised Notch. </p><p>The calculation, he said, means taking the percentage - or percentage range - of likelihood that the organization will experience a breach, and the cost of that breach. </p><p>From there, you can determine that an investment that costs $x will likely lower your percentage likelihood of breach by x%.</p><p>"<a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>teams have to understand the KPIs that matter to the business and how their operations ladder up into those," he said. </p><p>"It’s all about cybersecurity teams being able to communicate how their impact is contributing to those KPIs in the language of the business — which is all about dollars and cents."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pentesters are now a CISOs best friend as critical vulnerabilities skyrocket ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/pentesters-are-now-a-cisos-best-friend-as-critical-vulnerabilities-skyrocket</link>
                                                                            <description>
                            <![CDATA[ Attack surfaces are expanding rapidly, but pentesters are here to save the day ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rem73Tbz5vDuHLZUD3xWuj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 24 Sep 2025 09:44:59 +0000</pubDate>                                                                                                                                <updated>Wed, 24 Sep 2025 09:45:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Often underestimated by CISOs, hardware and network vulnerabilities are on the rise as IoT proliferates and AI creates increasingly larger attack surfaces.</p><p>That’s according to an analysis by Bugcrowd, which found the last year has seen a massive 88% increase in hardware vulnerabilities and a doubling in network flaws.</p><p>In a new report, <a href="https://www.bugcrowd.com/resources/report/inside-the-mind-ciso-resilience-in-an-ai-accelerated-world/" target="_blank"><u><em>Inside the Mind of a CISO 2025: Resilience in an AI-Accelerated World</em></u></a>, the firm said that 81% of security researchers had encountered new hardware vulnerabilities in the past 12 months.</p><div class="product"><a data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="79fc052a-60a8-443a-b174-696335c075c0" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Bugcrowd pointed to a 40% rise in broken access control vulnerabilities as a key factor behind rising threats. Meanwhile, sensitive data exposure was another problem area, with a 42% increase in critical vulnerabilities tied to personal information like names, addresses, and account details.</p><p>"We are in a high-stakes innovation race, but with every AI advance, the security landscape becomes exponentially more complex," said Nick McKenzie, Bugcrowd CISO. "Attackers are exploiting this complexity, but still targeting foundational layers like hardware and APIs."</p><p>The good news is that the number of critical vulnerabilities has gone down slightly year-over-year. The number of <a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">critical flaws in API</a> targets fell by about 25%, for example, while vulnerabilities in website targets decreased by 30%. </p><p>There was a slight rise in critical vulnerabilities for <a href="https://www.itpro.com/software/google/android">Android</a>, hardware, <a href="https://www.itpro.com/mobile/30409/android-vs-ios-which-mobile-os-is-right-for-you">iOS</a>, and network targets. Of these, broken access control is now the top category at 36%. </p><p>However, there's also been a 42% increase in sensitive data exposure and a 10% increase in API vulnerabilities as attack surfaces expand. Network vulnerabilities doubled, according to the report.</p><h2 id="pentesters-are-having-a-field-day">Pentesters are having a field day</h2><p>This increasingly perilous threat landscape has sparked a boom time for <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hackers</a> and pentesters, the report noted. Across 2024, there was a 32% increase in average <a href="https://www.itpro.com/security/google-spent-dollar10-million-on-bug-bounty-payouts-last-year-heres-what-flaws-researchers-uncovered">bug bounty payouts</a> for critical vulnerabilities. </p><p>Bugcrowd said enterprises are focusing on critical vulnerability payouts, paying more for P1 vulnerabilities and less for P3, P4, and P5 vulnerabilities.</p><p>Despite this helping hand, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>are still contending with heavy workloads and growing challenges. With applications going through multiple <a href="https://www.itpro.com/software/development/367842/the-four-major-software-development-lifecycle-models-and-how-they-work">development cycles</a> and teams under immense pressure to release features quickly, this is creating a frantic environment where mistakes are made. </p><p>New attack vectors and often forgotten targets like APIs and hardware typically among those overlooked. </p><p>With this in mind, Bugcrowd said organizations should consider adding APIs and hardware to the scope of their offensive security testing programs. </p><p>They should also adopt an integrated approach to attack surface intelligence - which, the firm noted, would help to secure budgets by showing measurable improvements in security efficiency.</p><p>Naturally, the company urged enterprises to make better use of ethical hackers, pentesters, and <a href="https://www.itpro.com/security/cisa-breached-a-federal-agency-as-part-of-its-red-team-program-and-nobody-noticed-for-five-months">red teamers</a> for offensive security training.   </p><p>“By using adversarial testing and objective measurement, security leaders can shift from reactive firefighting to building true resilience, " said Trey Ford, chief strategy and trust officer at Bugcrowd.</p><p>"Ultimately, this enables CISOs to confidently articulate their security story and secure resources necessary to protect their organizations.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/this-deepseek-powered-pen-testing-tool-could-be-a-cobalt-strike-successor-and-hackers-have-downloaded-it-10-000-times-since-july">This DeepSeek-powered pen testing tool could be a Cobalt Strike successor</a></li><li><a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">Everything you need to know about penetration testing</a></li><li><a href="https://www.itpro.com/security/vulnerability-patching-ai-application-security">Businesses are taking their eye off the ball with vulnerability patching</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ RSAC in focus: Key takeaways for CISOs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/rsac-in-focus-key-takeaways-for-cisos</link>
                                                                            <description>
                            <![CDATA[ The RSAC Conference 2025 spotlighted pivotal advancements in agentic AI, identity security, and collaborative defense strategies, shaping the evolving mandate for CISOs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KFDJtGSvi5H5cvSA6uowjc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Nhy7xmyBmTQjk2s5vErMCU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Jun 2025 14:30:17 +0000</pubDate>                                                                                                                                <updated>Mon, 16 Jun 2025 14:30:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Nhy7xmyBmTQjk2s5vErMCU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two tech leaders talking and gesturing towards a large screen on the wall. The image is shot in close-up.]]></media:description>                                                            <media:text><![CDATA[Two tech leaders talking and gesturing towards a large screen on the wall. The image is shot in close-up.]]></media:text>
                                <media:title type="plain"><![CDATA[Two tech leaders talking and gesturing towards a large screen on the wall. The image is shot in close-up.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Nhy7xmyBmTQjk2s5vErMCU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The RSAC Conference 2025 last month left CISOs to process a whirlwind of discussions, innovations, and evolving strategic imperatives. Building on themes that gained significant traction in previous years, 2025's event solidified several critical areas demanding CISO attention, from the pervasive influence of AI to the increasing personal and professional pressures of the CISO role itself.</p><p>For security leaders navigating this complex terrain, the key takeaways from San Francisco were both challenging and clarifying. With a focus on agentic AI, identity security, collaborative defense, and human-centric strategies, the conference provided valuable insights for security leaders.</p><h2 id="agentic-ai-transforming-security-operations">Agentic AI: transforming security operations</h2><p>Agentic AI, defined by autonomous systems capable of independent decision-making, was a major topic at RSAC Conference 2025. Cisco unveiled an open-source 8-billion-parameter<a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2025/m04/cisco-security-reimagine-ai-rsac.html"> <u>Foundation AI Security Model,</u></a> which is intended to improve detection and response capabilities within security operations centers (SOCs). This model is designed to automate tasks such as identifying intrusion methodologies, assessing severity, and generating compliance reports.</p><p>Vasu Jakkal, corporate vice president of security at Microsoft,<a href="https://www.itpro.com/security/what-to-look-out-for-at-rsac-conference-2025"> <u>highlighted</u></a> the transformative potential of agentic AI in cybersecurity, discussing how AI agents can work collaboratively to detect and prevent intrusions, thereby reducing the cost and complexity of sophisticated security operations.</p><h2 id="identity-security-beyond-human-users">Identity security: beyond human users</h2><p>The rise of digital ecosystems has resulted in numerous non-human identities, like machine-to-machine communications and AI agents. Traditional identity management is now inadequate, prompting organizations to secure these digital identities against unauthorized access and system compromises.</p><p>Comprehensive identity governance solutions are required, covering both human and non-human entities, with strong authentication and authorization protocols throughout the enterprise.</p><h2 id="collaborative-defense-between-public-and-private-sectors">Collaborative defense between public and private sectors</h2><p>RSAC Conference 2025 underscored the vital<a href="https://www.youtube.com/watch?v=AJgOIK4Eklc"> <u>importance of collaboration</u></a> between private enterprises and government agencies in addressing evolving digital challenges. Sessions emphasized the importance of sharing intelligence and coordinating responses to close gaps in cybersecurity. Collective knowledge and resources can help organizations better manage modern digital issues, creating a stronger defense network.</p><p>Speakers and panellists deliberated on strategies for effective<a href="https://www.itpro.com/security/rsac-conference-2025-was-reminder-challenges-facing-cybersecurity-professionals"> <u>public-private partnerships</u></a>, advocating for open communication channels and trust-building measures. These<a href="https://www.everestgrp.com/blog/deep-dives-into-rsac-2025-four-standout-sessions-on-cybersecuritys-frontlines-blog.html#:~:text=The%20session%20on%20%E2%80%9CThe%20Future,their%20Security%20Cloud%20Control%20platform."> <u>partnerships</u></a> aim to streamline intelligence sharing on harmful activities, making it more actionable and timely, while also pooling technological resources to tackle sophisticated malicious campaigns. Despite political shifts and challenges that can sometimes hinder collaboration, the overarching consensus was that such alliances are indispensable for fortifying both national and organizational cybersecurity postures.</p><p>CISOs are advised to foster partnerships through intelligence-sharing forums and collaborative plans, enhancing preparedness against emerging risks.</p><h2 id="human-element-as-the-persistent-core-of-cybersecurity">Human element as the persistent core of cybersecurity</h2><p>While technological advancements dominate the cybersecurity landscape, the human factor remains a critical component. Keynotes and sessions consistently highlighted that human behavior, decision-making, and collaboration are irreplaceable elements in building robust security frameworks. Despite the proliferation of automation and artificial intelligence, the ability of humans to adapt swiftly to unforeseen security challenges and coordinate responses across diverse teams remains unmatched. This human-centric approach reinforces the significance of fostering a culture of vigilance and resilience within organizations, where each member is empowered to contribute to the collective defense.</p><p>The emphasis on community and shared responsibility further underscores the importance of continuous education and awareness programs. These initiatives are designed not only to enhance technical knowledge but also to cultivate critical thinking and proactive attitudes needed to counter increasingly sophisticated digital intrusions. By integrating these programs alongside cutting-edge technological defenses, organizations can strike a powerful balance, ensuring that while systems evolve to meet new challenges, the human element remains the persistent and vital core of cybersecurity success.</p><h2 id="innovation-and-investment-driving-the-future">Innovation and investment driving the future</h2><p>A key takeaway for CISOs from RSAC Conference 2025 is the<a href="https://www.prnewswire.com/news-releases/projectdiscovery-named-most-innovative-startup-at-rsac-2025-conference-innovation-sandbox-contest-302440254.html?utm_source=chatgpt.com"> <u>recognition</u></a> of ProjectDiscovery's open-source platform for managing system weaknesses as a game-changer for under-resourced teams. Its advanced scanning capabilities highlight the growing importance of accessible security tools in democratizing cybersecurity efforts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How is the role of the CISO evolving?  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/how-is-the-role-of-the-ciso-evolving</link>
                                                                            <description>
                            <![CDATA[ This role now stands as a pivotal figure in organizational strategy and security posture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">szBM5pFPPCZVia4FHBuQHL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 May 2025 14:53:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                    <sponsoredContent>true</sponsoredContent>
                                <cf:isSponsored>true</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:description>                                                            <media:text><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:text>
                                <media:title type="plain"><![CDATA[API and cloud security concept image showing cloud symbol with a padlock.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2AstwKwLA445ALahe3QyLN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The role of the Chief Information Security Officer (CISO) has undergone a profound metamorphosis. Once a primarily technical custodian sequestered within IT, the modern CISO is increasingly a strategic business leader, pivotal to organizational resilience, innovation enablement, and stakeholder trust. </p><p>Recent <a href="https://www.heidrick.com/en/insights/cybersecurity/2024-global-chief-information-security-officer-organization-and-compensation-survey">survey data</a> underscores the shift: the proportion of CISOs who report directly to the CEO has almost tripled in just one year, soaring from five percent in 2023 to 14 percent in 2024. Facing increasingly complex digital threats and transformative technologies like Artificial Intelligence (AI), today’s CISO must be a multifaceted expert, a strong communicator, and a visionary architect of enterprise-wide security.</p><h2 id="the-modern-day-ciso-responsibilities-remit-and-key-alliances">The modern-day CISO: responsibilities, remit, and key alliances</h2><p>Being a CISO in the current era means shouldering a vast array of responsibilities that extend far beyond the traditional confines of IT protection. Core duties now include strategic risk management, aligning security posture with overarching business objectives, and maintaining a dynamic grasp of the organization’s risk appetite. </p><p>As<a href="https://www.gartner.com/en/newsroom/press-releases/2025-02-11-gartner-survey-reveals-only-14-percent-of-security-leaders-successfully-balance-data-security-and-business-objectives"> Gartner’s Nathan Parks cautions</a>: “With only 14 percent of security-and-risk leaders able to secure their data and support business goals, many organizations court vulnerability and inefficiency.” </p><p>Developing and continuously tuning enterprise-wide policies, standards, and controls is, therefore, just the start. Indeed,; the modern CISO must also ensure the organization is ready to detect, respond to, and recover from security events with minimal disruption.</p><p>The CISO’s remit is truly enterprise-wide, touching every information asset and process, so success hinges on robust collaboration. Board-level engagement has become the norm: <a href="https://www.splunk.com/en_us/blog/leadership/the-power-of-partnerships-between-cisos-and-their-boards.html">Splunk’s 2025 CISO Report</a> notes that 82 percent of CISOs interact directly with the CEO and 83 percent attend board meetings on a regular basis, prompting author Michael Fanning to observe, “CISOs have officially arrived in the C-suite, and we’re working more closely with our boards than ever before.” </p><p>Beyond the boardroom, a tight partnership with the CIO grounds security strategy in operational reality, while coordination with Legal and Compliance navigates the rising tide of data-protection regulations. Human Resources helps cultivate a security-aware culture and manage insider risk, and — perhaps most critically — business-unit leaders ensure that controls support, rather than stifle, innovation.</p><p>Finally, today’s CISO is increasingly expected to spearhead organizational resilience. <a href="https://www.pwc.com/us/en/executive-leadership-hub/ciso.html">PwC’s 2025 Global Digital Trust Insights</a> frames the opportunity plainly: “CISOs can lead resilience-building efforts by proactively assessing risks and scenario-planning — translating how strong resilience benefits the business is just as important as the plan itself.” In other words, the modern security chief is no longer a gatekeeper at the edge of IT, but a business architect whose influence — and accountability — extends to every corner of the enterprise.</p><h2 id="the-evolutionary-journey-of-the-ciso">The evolutionary journey of the CISO</h2><p>The CISO role, or its early equivalents, began to solidify in the late 1990s and early 2000s, largely in response to the burgeoning reliance on networked IT systems and the initial waves of internet-borne malicious activities. Initially, the focus was heavily technical.</p><p>However, several powerful forces have dramatically reshaped and elevated the role, particularly over the last decade. The escalating sophistication of hostile actors, transitioning from opportunistic individuals to well-resourced, often state-affiliated groups, has fundamentally changed the nature of the challenge.</p><p>At the same time, widespread digital transformation, such as cloud adoption, IoT, mobile computing, and the sheer volume of data, has expanded the organizational surface vulnerable to security compromises. Additionally, the surge in data privacy regulations like <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a> and <a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">CCPA</a> has increased accountability on organizations and their CISOs. </p><p>Public security incidents now involve severe financial penalties, reputational damage, loss of customer trust, and operational paralysis, elevating security to a board-level imperative. Consequently, the CISO role has evolved from technologist to strategic risk executive, often reporting higher and needing broader skills in business, finance, communication, and leadership.</p><h2 id="on-the-horizon-enduring-challenges-and-ai-as-a-strategic-ally">On the horizon: enduring challenges and AI as a strategic ally</h2><p>The future for CISOs promises no abatement in challenges. Digital perils will keep mutating, which means security leaders must constantly try and stay more than several steps ahead. </p><p>Indeed, the talent crunch shows no sign of easing: the <a href="https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study">2024 ISC² Cybersecurity Workforce Study</a> puts today’s global workforce gap at 4.76 million professionals. Furthermore, more than half (59 %) of organizations say skills shortages have already had a significant impact on their ability to shield themselves against adversaries who can now use AI at scale while internal teams are stretched dangerously thin. </p><p>This all means that the modern CISO must marshal strategy, technology, and cross-functional alliances to keep the enterprise secure today, tomorrow, and beyond. </p><p>A number of technologies, particularly AI, offer a powerful means for CISOs to augment their capabilities and stay ahead. </p><p>AI can be a significant force for good by automating voluminous and repetitive tasks, thus freeing up human analysts for more strategic work. It can enhance detection capabilities by identifying subtle patterns and anomalies indicative of sophisticated hostile actions that might evade traditional tools. </p><p>Furthermore, AI can accelerate response times to security events through automated containment measures. Research from various bodies supports this positive outlook. </p><p>A <a href="https://www.microsoft.com/en-us/security/security-insider/practical-cyber-defense/ai-security-guide">Microsoft Security survey</a>, for instance, revealed that nearly half of current AI for security users felt good about its ability to make critical security decisions. This growing confidence suggests a shift in perception, where AI is increasingly viewed as an indispensable aid rather than a potential hindrance to an organization’s protective posture.</p><h2 id="the-path-forward-strategic-adaptation-and-leadership">The path forward: strategic adaptation and leadership</h2><p>While AI offers immense promise, the rapid emergence of generative AI (GenAI) also introduces a new frontier of specific concerns for CISOs, particularly regarding its secure adoption within the business. </p><p>Data protection and potential leakage are paramount. The ISMG "2024 Generative AI Study" <a href="https://msftstories.thesourcemediaassets.com/sites/711/2024/11/Gen-AI-Survey-FINAL-20231228.pdf">found</a> that 80% of leaders fear sensitive information slipping through the cracks when employees use GenAI tools, especially public models, without proper oversight. CISOs must establish robust governance frameworks to manage data input and output for GenAI systems to prevent inadvertent exposure of proprietary or customer information.</p><p>Compliance is another significant hurdle, with evolving regulations like the EU AI Act causing confusion. Indeed, just 38% and 52% of business and cybersecurity leaders, respectively, say they do have a good understanding of AI regulations, according to the ISMG study.</p><p>Finally, the rise of emerging GenAI-driven perils requires proactive attention. Hostile actors are already exploring how GenAI can be used to craft more convincing, deceptive email campaigns, generate polymorphic malicious code, or create sophisticated disinformation.</p><p>The CISO of today and tomorrow must be adaptable, business-savvy, and technologically astute. Their role involves not only safeguarding the organization but also enabling secure innovation. </p><p>This includes championing the safe, ethical adoption of AI in security and guiding its responsible use across the enterprise. By understanding both the potential and risks of technologies like GenAI, CISOs can strategically leverage them as powerful allies. </p><p>Continuous learning, strategic foresight, and resilient leadership are essential for navigating the digital world securely.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISOs bet big on AI tools to reduce mounting cost pressures ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cisos-bet-big-on-ai-tools-to-reduce-mounting-cost-pressures</link>
                                                                            <description>
                            <![CDATA[ AI automation is a top priority for CISOs, though data quality, privacy, and a lack of in-house expertise are common hurdles ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tyxPhqG5KsBeSEAoZGsuQf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HQxXLWD882pD9kW3xzkk53-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 May 2025 10:30:52 +0000</pubDate>                                                                                                                                <updated>Wed, 28 May 2025 10:31:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HQxXLWD882pD9kW3xzkk53-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female CISO advises colleague in a security operations center while working on desktop computers.]]></media:description>                                                            <media:text><![CDATA[Female CISO advises colleague in a security operations center while working on desktop computers.]]></media:text>
                                <media:title type="plain"><![CDATA[Female CISO advises colleague in a security operations center while working on desktop computers.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HQxXLWD882pD9kW3xzkk53-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As cost pressures rise and cyber threats become more sophisticated, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>are increasingly looking to <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to reduce the strain, new research suggests. </p><p><a href="https://www.itpro.com/security/cyber-workforce-growth-slows-as-budget-constraints-hit-hiring-targets-and-its-going-to-create-a-more-dangerous-threat-landscape-and-send-burnout-through-the-roof">Cybersecurity budgets</a> are under pressure, with only two-in-ten global security leaders and consultants allocating more than 10% of their annual budget to cybersecurity - 12% down from 2023.</p><p>Notably, three-in-ten told Wipro for its 2025 <a href="https://www.wipro.com/cybersecurity/reports/state-of-cybersecurity-report-2025/#:~:text=Wipro%27s%202025%20State%20of%20Cybersecurity,state%20of%20cyberattacks%20and%20breaches%3F" target="_blank"><u><em>State of Cybersecurity Report</em></u><u> </u></a>that investing in AI automation to bolster <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>operations and reduce costs is a top priority.</p><p>A similar number are using AI to improve threat detection and response times, with a quarter using it to enhance incident response capabilities. </p><p>"Cybersecurity budgets are struggling to keep pace with the growing sophistication of cyber threats," said Tony Buffomante, SVP and global head of cybersecurity and risk services at Wipro.</p><p>"AI offers a solution by helping organizations strengthen defenses while optimizing costs. This allows CISOs to adopt a more outcome-driven focus by prioritizing risk-adjusted returns on investments." </p><p>There are, of course, challenges to AI adoption. More than three-quarters (84%) of respondents cited data quality and privacy as the biggest difficulty in implementing effective AI-driven cybersecurity solutions. </p><p>Other problems included a lack of expertise, a challenge for three-quarters of tech leaders, forcing them to depend on external resources or undertake costly upskilling programs.</p><p>Seven-in-ten respondents listed integration with legacy systems as a prominent challenge while budgetary constraints affect a similar number too - largely thanks to the need for significant investments in various hardware components and software licenses, along with continuous system monitoring and maintenance.</p><h2 id="cisos-target-tool-sprawl-to-optimize-costs">CISOs target tool sprawl to optimize costs</h2><p>Other strategies used by CISOs to optimize costs include ‘tools rationalization’. This involves evaluating and consolidating duplicate security tools across platforms to eliminate redundancies and improve efficiency while reducing costs. </p><p>Just over a quarter of respondents specifically highlighted tools rationalization as a key focus at present. </p><p>Tool sprawl has become a recurring issue for cybersecurity practitioners in recent years, with research in late 2024 showing teams were becoming <a href="https://www.itpro.com/security/adopting-more-security-tools-doesnt-keep-you-safe-it-just-overloads-your-teams-and-creates-greater-risks"><u>frustrated with a growing array of disparate solutions</u></a>. </p><p>Meanwhile, 23% are aiming to cut costs by undertaking security and risk management process optimization, and two-in-ten are aiming to simplify their operating model. </p><h2 id="security-strategies-require-bold-vision">Security strategies require bold vision</h2><p>Notably, Wipro’s study found organizations are taking a strategic approach to cybersecurity. There's an almost universal focus on Zero Trust security frameworks, with 97% of respondents identifying it as a top investment priority.</p><p>Meanwhile, 82% are investing in IoT device management and security to address the growing risks associated with the proliferation of connected devices.</p><p>Nearly eight-in-ten organizations are prioritizing investment in Secure Access Service Edge (SASE) to cope with rapid cloud adoption, the rise of remote work and the evolving threat landscape.</p><p>With an influx of AI tools, more than half (55%) of security leaders also said they are ramping up efforts to prioritize LLM guardrails. This, the study noted, is helping CISOs and security teams better manage and secure access to LLMs for enterprise applications. </p><p>"Increased technological complexity, constantly evolving regulations and a rise in sophisticated cyber threats across multi-hybrid cloud environments create daunting challenges for security teams," said Buffomante. </p><p>"CISOs need to adopt a risk-adjusted, outcome-oriented mindset and transition from technologists who merely prevent and react to breaches to risk strategists focused on optimizing enterprise cyber resilience."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/is-the-ciso-role-in-crisis">Bigger salaries, more burnout: Is the CISO role in crisis?</a></li><li><a href="https://www.itpro.com/security/CISO-boardroom-influence-growing">CISOs are gaining more influence in the boardroom, and it’s about time</a></li><li><a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">Why the CISO role is so demanding – and how leaders can help</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How enterprises are adapting to personal liability rules ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/how-enterprises-are-adapting-to-personal-liability-rules</link>
                                                                            <description>
                            <![CDATA[ With the threat of personal liability for data breaches hanging over CISOs' heads, organizations are increasingly working to minimize the risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g5T3rgxksFGAMYNfUXEGQP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Mar 2025 13:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Business Strategy]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:description>                                                            <media:text><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:text>
                                <media:title type="plain"><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the threat of <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">personal liability for data breaches</a> hanging over CISOs' heads, organizations are increasingly working to minimize the risk.</p><p>Recent US and EU legislation has made it possible to hold executives responsible for security breaches, with potential penalties of fines and even imprisonment. </p><p>A recent <a href="https://learn.fastly.com/cybersecurity-at-the-crossroads.html" target="_blank"><u>survey</u></a> from edge cloud platform provider Fastly found that 93% of organizations have made policy changes over the last 12 months to try and deal with concerns about increased personal liability for <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs</a>. </p><p>As part of this, two-in-five said they were giving CISOs more say in strategic decisions at board level. To reduce risk, 38% said they'd promised greater scrutiny of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>disclosure documentation from supervisory agencies.</p><p>The same number said they'd improved legal support for <a href="https://www.itpro.com/security/enterprises-are-struggling-to-fill-senior-cybersecurity-roles-and-its-causing-staff-burnout-to-skyrocket">cybersecurity staff</a>, including taking out liability insurance, and corporations have allocated more resources to security in the past year. </p><p>"It’s encouraging to see the vast majority of companies making changes to liability disclosure given the inevitability of another worldwide outage that will put CISO accountability back into the spotlight," said Fastly CISO, Marshall Erwin. </p><p>"However, while investing in legal protection is an important step, this change is often more about shielding organizations from legal risk rather than fostering meaningful accountability to drive better security practices."</p><h2 id="firms-are-still-uncertain-over-personal-liability-rules">Firms are still uncertain over personal liability rules</h2><p>Adding to the uncertainty is the fact that nearly half of organizations are unclear about who actually holds ultimate responsibility for cybersecurity incidents, while only 36% have clearly delineated roles and responsibilities within their teams.</p><p>"CISOs do not make the final call on every decision. When it comes to security risks, the question a board should be asking is, ‘Are we aligning the budget to address the risks the CISO has communicated to us?’," said Erwin. </p><p>"This is where accountability should start - at the senior leadership level, with clear communication and alignment of resources."</p><p>In late 2023, <a href="https://www.itpro.com/business/policy-and-legislation/new-sec-rules-around-data-breach-disclosures-arrive-on-monday-heres-what-you-need-to-know">new rules were introduced by the US Securities and Exchange Commission (SEC)</a> aimed at holding executives responsible for security breaches and mishaps. </p><p>It's no empty threat, either. Last year, the SEC <a href="https://www.itpro.com/security/solarwinds-claims-the-sec-is-spinning-a-false-narrative-over-sunburst-response">filed charges against both SolarWinds and its CISO, Tim Brown</a>, following the notorious attack in 2020. </p><p>Similarly, in 2023 Uber CSO <a href="https://www.itpro.com/security/hacking/356843/former-uber-cso-charged-hack-cover-up">Joseph Sullivan</a> was convicted of trying to cover up a data breach and sentenced to three years of probation, a $50,000 fine, and 200 hours of community service.</p><p>Across the Atlantic, similar rules have been introduced by EU lawmakers, in particular the EU’s <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive">Network and Information Security Directive (NIS2)</a>. This legislation aims to protect critical infrastructure and services across the union, and includes personal liability for executives. </p><p>The <a href="https://www.itpro.com/business/policy-legislation/368414/eu-digital-operational-resilience-act-dora">Digital Operational Resilience Act (DORA)</a>, which regulates security practices for financial institutions, does the same. </p><p>But there's great uncertainty about how readily the measures will be implemented, and in what circumstances, according to Fastly’s report. </p><p>"We need better, clearer standards from regulators and enforcers that distinguish between unavoidable incidents and avoidable ones resulting from truly deficient security practices," said Erwin. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/CISO-boardroom-influence-growing">CISOs are gaining more influence in the boardroom, and it's about time</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/how-cisos-are-navigating-the-slippery-ai-data-protection-problem">How CISOs are navigating the “slippery” AI data protection problem</a></li><li><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches">Remote work is still causing security headaches for CISOs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISOs are gaining more influence in the boardroom, and it’s about time ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/CISO-boardroom-influence-growing</link>
                                                                            <description>
                            <![CDATA[ CISO influence in the C-suite and boardrooms is growing, new research shows, as enterprises focus heavily on cybersecurity capabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">79f6pFKMKDhXrRuVL7eYNb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jan 2025 10:48:25 +0000</pubDate>                                                                                                                                <updated>Mon, 27 Jan 2025 15:58:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:description>                                                            <media:text><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:text>
                                <media:title type="plain"><![CDATA[Boardroom meeting with executives, including CEO, CISO, CTO, CIO and CFO discussing company strategy.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4HjqNAYrLhjoPQWxwyZcWP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The role of the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> is growing in status as <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> becomes an increasingly pressing issue for enterprises globally, new research shows. </p><p>A recent study from <a href="https://www.itpro.com/business/business-strategy/our-job-is-not-to-screw-up-cisco-ceo-chuck-robbins-vows-to-make-splunk-better">Splunk</a> shows security execs are being granted more powers to make strategic decisions for the business and are fostering closer collaborative ties with the boardroom and CEO.</p><p>More than eight-in-ten CISOs now report directly to the <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a>, a huge increase from 47% in 2023. Meanwhile, 83% participate in board meetings somewhat often or most of the time. </p><p>However, while six-in-ten acknowledge that board members with cybersecurity backgrounds have a more powerful influence on security decisions, only 29% say their board includes at least one member with cybersecurity expertise. </p><p>"As cybersecurity becomes increasingly central to driving business success, CISOs and their boards have more opportunities to close gaps, gain greater alignment, and better understand each other in order to drive digital resilience,” said Michael Fanning, chief information security officer at Splunk. </p><p>“For CISOs, that means understanding the business beyond their IT environments and finding new ways to convey the ROI of security initiatives to their boards. For board members, it means committing to a security-first culture and consulting the CISO as a primary stakeholder in decisions that impact enterprise risk and governance."</p><h2 id="cisos-on-the-board-builds-strong-security-practices">CISOs on the board builds strong security practices</h2><p>Splunk’s research found that board members with a security background reported stronger relationships with security teams, and felt more confident about the organization’s security posture. </p><p>They were much less likely than other board members to express concern they weren't doing enough to protect the organization.</p><p>Working relationships where a board member had a security background were particularly good when it came to setting and aligning on strategic cybersecurity goals, with CISOs on the board delivering a three-fold improvement.</p><p>Other areas to benefit included communicating progress against milestones and security goal achievements, along with budgeting adequately to meet goals. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CQVbgM8Vp6xdYdQJG2NW3T" name="Securing tomorrow_ Maximising the value of technology in an evolving defence sector.jpg" caption="" alt="Securing tomorrow: Maximising the value of technology in an evolving defence sector" src="https://cdn.mos.cms.futurecdn.net/CQVbgM8Vp6xdYdQJG2NW3T.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Intel)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/securing-tomorrow"><em>Defence firms must consider this when implementing new tech</em></a></p></div></div><p>There were, though, differences in priorities. More than half of CISOs thought innovating with emerging technologies was a priority, compared with just a third for board members. A similar proportion of CISOs prioritized <a href="https://www.itpro.com/business/careers-and-training/cyber-security-professionals-admit-knowledge-gaps-have-led-to-serious-security-blunders">upskilling</a> or reskilling security employees, versus only 27% for boards.</p><p>"As the role of the CISO grows more complex and critical to organizations, CISOs must be able to balance security needs with business goals, culture, and articulate the value of security investments," commented Shefali Mookencherry, chief information security and privacy officer at the University of Illinois Chicago.</p><p>"By establishing strong relationships across various departments and stakeholders, CISOs can provide guidance and leadership to propel cybersecurity and privacy programs."</p><h2 id="cisos-face-regulatory-challenges">CISOs face regulatory challenges</h2><p>As regulatory environments have become more complex, expansive, and punitive, CISOs are having to deliver <a href="https://www.itpro.com/security/security-incident-recovery-times-are-over-7-months-on-average">faster incident reporting</a>, and are <a href="https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating">facing more liability</a>.</p><p>However, only 15% of CISOs ranked compliance status as a top performance metric, a significant contrast to 45% of boards. Nearly a quarter (21%) of CISOs said they'd been pressured not to report a compliance issue, although 59% said they would become a whistleblower if their organization was ignoring compliance requirements.</p><p>Meanwhile, cyber budgets reflect inconsistent support and misalignment, with three-in-ten CISOs saying they receive the appropriate budget for cybersecurity initiatives and accomplishing their security goals, compared with four-in-ten board members who think budgets are adequate. </p><p>Other woes included concerns that they're not doing enough, with 18% revealing they were unable to support a business initiative because of budget cuts in the last 12 months. Nearly two-thirds said that lack of support led to a cyber attack. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISOs are working harder than ever, but their pay isn’t keeping pace ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/careers-and-training/cisos-are-working-harder-than-ever-but-their-pay-isnt-keeping-pace</link>
                                                                            <description>
                            <![CDATA[ Many CISOs are being asked to take on more responsibility for domains that would normally lie outside of their remit ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ds3EgRRvXgYaJzLbwBN99Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bvAN9JDHhY8jpv9drsT4uh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jan 2025 08:15:10 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jan 2025 17:18:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bvAN9JDHhY8jpv9drsT4uh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Business meeting man presents ideas to colleagues]]></media:description>                                                            <media:text><![CDATA[Business meeting man presents ideas to colleagues]]></media:text>
                                <media:title type="plain"><![CDATA[Business meeting man presents ideas to colleagues]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bvAN9JDHhY8jpv9drsT4uh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/technology/artificial-intelligence/how-cisos-are-navigating-the-slippery-ai-data-protection-problem">CISOs</a> have reported the scope of their role has widened to encompass business concerns that extend beyond cybersecurity, but believe their compensation doesn't reflect this.</p><p>The <em>2025</em> <em>State of the CISO </em><a href="https://www.iansresearch.com/resources/ians-state-of-the-ciso-report" target="_blank">report</a> from <a href="https://www.itpro.com/security/ciso-job-satisfaction-is-plummeting-and-some-are-considering-quitting-altogether">IANS Research</a> includes testimony from roughly 800 CISOs on the growing importance of the role, and the simultaneous growth in the role’s complexity and scope of responsibilities.</p><p>The report found that in addition to their traditional remit of InfoSec and digital risk, CISOs are increasingly being asked to look after other business domains such as <a href="https://www.itpro.com/business/policy-legislation/368763/what-will-it-take-2022-uk-digital-strategy">digital strategy</a>.</p><p>For example, 90% of CISOs said they had ownership of what might be considered their traditional domains including the organization’s security operations, architecture, and governance, as well as <a href="https://www.itpro.com/business-strategy/digital-transformation/370200/minimising-digital-risk-with-cyber-resilience">digital risk</a> and compliance.</p><p>The majority (between 50 and 90%) also identified other elements of business risk, such as disaster recovery, <a href="https://www.itpro.com/security/cisos-are-facing-a-tsunami-of-regulations-heres-why-its-crucial-they-focus-on-quantifying-cyber-risk">business risk</a>, and third-part risk management, as well as broader security concerns such as product security as falling under their remit too.</p><p>However, IANS noted a series of ‘emerging domains’ that 1-25% of CISOs reported were being added to their workload, including <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, M&A security, change management, IT due diligence, digital transformation, and innovation.</p><p>The report found the broader scope associated with the CISO role has not been reflected in their compensation, with just 3% of CISOs attributing salary raises to taking on further responsibilities.</p><p>IANS found that only when switching employers were CISOs more likely to see their <a href="https://www.itpro.com/business-operations/business-management/361659/the-it-pro-podcast-how-to-beat-burnout">additional workload</a> reflected in their pay packet.</p><p>For example, 7% of CISOs said their <a href="https://www.itpro.com/business/careers-and-training/does-remote-work-fuel-wage-inequality-not-exactly-staff-working-from-home-tend-to-be-higher-earners-but-they-also-experience-lower-wage-growth">growth in compensation</a> was driven by a change in employers, a move which is often accompanied by taking on a larger role with more responsibilities, and this group received an average  increase of 31%.</p><p>The vast majority of CISOs (70%), however, indicated any raises they received were annual <a href="https://www.itpro.com/business/business-strategy/369986/intel-slashes-staff-salaries-bonuses-disappointing-financial-performance">merit-based</a> increases, which on average were 6%.</p><h2 id="cisos-taking-ownership-of-it-unlikely-to-see-meaningful-pay-rises">CISOs taking ownership of IT unlikely to see meaningful pay rises</h2><p>IANS identified three distinct segments among respondents in terms of their C-level access and <a href="https://www.itpro.com/business-strategy/chief-information-officer-cio/354564/cios-are-taking-their-seat-at-the-boardroom">boardroom influence</a>, using the labels ‘strategic, functional, and tactical’.</p><p>Strategic CISOs, which accounted for 28% of the group are described as those who report directly to the <a href="https://www.itpro.com/strategy/28224/ceo-job-description-what-does-a-ceo-do">CEO</a> or at least have a high-ranking position in the C-suite hierarchy, and thus have significant influence across the organization.</p><p>This group also enjoys frequent interaction with the board, with quarterly meetings as the minimum, which IANS said promotes “mutual understanding and aligning on <a href="https://www.itpro.com/security/ruthlessly-prioritize-whats-critical-check-point-expert-on-cisos-and-the-evolving-attack-surface">strategic priorities</a> between the CISO and top leadership”.</p><p>The next group, which made up 50% of respondents, is referred to as the functional CISO. According to IANS’s taxonomy, functional CISOs excel in one of these areas but do not enjoy both <a href="https://www.itpro.com/security/malware/357926/hacker-claims-to-be-selling-c-suite-executive-microsoft-account-credentials">C-suite access</a> and boardroom engagement.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HeUWYKLat8TZpmnc5HebxU" name="Better insights driving better health outcomes" caption="" alt="Better insights driving better health outcomes" src="https://cdn.mos.cms.futurecdn.net/HeUWYKLat8TZpmnc5HebxU.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/better-insights-driving-better-health-outcomes"><em>AWS is unlocking healthcare innovation</em></a></p></div></div><p>The final 22% of respondents were described as tactical CISOs, who have waning executive-level access to a lower organizational rank and only sporadic boardroom engagements.</p><p>Comparing the compensation for these three groups, IANS found strategic CISOs were the best remunerated, with an annual cash compensation of around $545,000, compared to $385,000 for functional CISOs and $291,000 for their tactical counterparts.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=57219564&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>IANS noted that CISOs who <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">oversee an organization's security</a> as well as all of its IT functions, referred to as ‘dual CISOs’, are a surefire way to ensure increased compensation.</p><p>The study found that dual CISOs at large organizations earn an average total compensation (including equity) of $1 million, whereas those who only take on partial IT oversight are closer to the average of traditional CISOs who manage none of the IT functions ($653,000).</p><p>“This would seem to indicate taking on all of IT is highly rewarded, but being given some IT functions opportunistically—perhaps due to the departure of another IT executive or unclear lines of ownership between infosec and IT—is not a reliable path to higher compensation,”the report noted.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gerald Beuchelt joins Acronis as CISO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/gerald-beuchelt-joins-acronis-as-ciso</link>
                                                                            <description>
                            <![CDATA[ The former Sprinklr and LogMeIn CISO will spearhead Acronis’ global information security strategy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TJJJTdHrUJSFyBaANrVMFZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxVMHuF4FDTmhLcJJvGXDW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jan 2025 14:29:19 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Jan 2025 16:47:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxVMHuF4FDTmhLcJJvGXDW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two business persons shaking hands standing outside.]]></media:description>                                                            <media:text><![CDATA[Two business persons shaking hands standing outside.]]></media:text>
                                <media:title type="plain"><![CDATA[Two business persons shaking hands standing outside.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxVMHuF4FDTmhLcJJvGXDW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity and data protection specialist Acronis has announced the appointment of Gerald Beuchelt as its new <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">chief information security officer (CISO)</a>.</p><p>An experienced industry leader, Beuchelt arrives with more than a decade of cybersecurity leadership experience, most recently serving as CISO at Sprinklr and previously holding the same role at LogMeIn.</p><p>Beuchelt’s career has also seen him serve as treasurer and director on the board of the Boston Chapter of Infragard, the FBI public-private partnership program, and the National Cyber Security Alliance. </p><p>Other roles include chief security officer at Salesforce-acquired Demandware, and principal information security engineer at The MITRE Corporation.</p><p>In his new role as Acronis’ CISO, Beuchelt will spearhead the firm’s global information security strategy to ensure the protection of its information, systems, and technologies. He will also work to drive its goal of securing clients’ data, applications, and systems, the company said in an announcement.</p><p>“We are proud to welcome Gerald to Acronis as our new CISO,” said Ezequiel Steiner, Acronis CEO. “His extensive experience and forward-thinking approach to cybersecurity will play a vital role in advancing our mission to protect all data, applications, and systems for organizations worldwide.</p><p>“As CISO, he will drive initiatives that ensure our customers and partners benefit from Acronis’ natively integrated solutions, which eliminate complexity and provide unmatched simplicity and performance.”</p><p>As a part of the firm’s senior security leadership team, Beuchelt will lead Acronis’ global team of IT, security, and compliance experts, as well as oversee corporate IT infrastructure such as help desk operations, server, and network management.</p><p>The cybersecurity provider said Beuchelt will also support the expansion of new research, reports, and threat intelligence from the Acronis Threat Research Unit (TRU).</p><p>Commenting on his appointment, Beuchelt praised the breadth of Acronis’ product capabilities, as well as its global impact and strategic direction.</p><p>“I’m particularly inspired by the company’s dedication to making security solutions scalable and accessible for service providers, enterprises, SMBs, and individual users alike,” he said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="i95dfjdDqzWPFmQQCuuuBE" name="dell-logo-white-bright-sign-wood-background-GettyImages-1175327992.jpg" caption="" alt="The Dell logo in white against a wood-panelled wall" src="https://cdn.mos.cms.futurecdn.net/i95dfjdDqzWPFmQQCuuuBE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/powerstore-prime"><em>Keep your IT infrastructure ready for future needs</em></a></p></div></div><p>“My focus will be on maintaining and continuously improving our security posture to address the increasingly complex threat landscape.</p><p>“As part of Acronis TRU, we will implement research-driven guidance that will shape Acronis’ capabilities to protect against modern threats while raising awareness of how our solutions empower businesses to succeed. I look forward to collaborating with the talented team at Acronis to expand our influence in the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> community.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Threat of personal liability has CISOs sweating ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating</link>
                                                                            <description>
                            <![CDATA[ With increased scrutiny, boards need to ramp up support for CISOs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yfEYTTgZJYyJC66PSNtdxJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Dec 2024 11:23:12 +0000</pubDate>                                                                                                                                <updated>Fri, 13 Dec 2024 15:55:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Tired man working on computer laptop late at night]]></media:description>                                                            <media:text><![CDATA[Tired man working on computer laptop late at night]]></media:text>
                                <media:title type="plain"><![CDATA[Tired man working on computer laptop late at night]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>CISOs are feeling the pressure over stories of their peers being held <a href="https://www.itpro.com/security/data-breaches/sec-data-breach-rules-branded-worryingly-vague-by-industry-body">personally liable for cybersecurity incidents</a>.</p><p>In the most notorious example, the US Securities and Exchange Commission (SEC) last year announced that it was <a href="https://www.itpro.com/security/solarwinds-claims-the-sec-is-spinning-a-false-narrative-over-sunburst-response">filing charges against both SolarWinds and its CISO, Tim Brown</a>, amid allegations of "fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities".</p><p>While Brown beat the charges earlier this year, others haven’t been quite as lucky. </p><p>Uber CSO Joe Sullivan, for example, was given a three-year probation sentence and a $50,000 fine for covering up a 2016 data breach. And CISOs fear such charges could potentially be filed against them. </p><p>Seven-in-ten told security firm BlackFog in a new survey that incidents like this had negatively affected their opinion of the job. Around a third said the trend was a no-win situation for security leaders, leaving them facing internal consequences if they report failings and prosecuted if they don’t.</p><p>"The role of the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> is all about managing risk for the organization but, as regulations tighten, security leaders increasingly need to consider their own personal risk," said BlackFog founder and CEO Dr Darren Williams.</p><p>Increased accountability has, at least, led to internal changes to improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> practices within their organisation. Nearly half (44%) of respondents said their company had already put processes in place to reduce their cyber exposure as a result.</p><p>Nearly half of all respondents believe that the potential for an individual to be prosecuted following a cyber attack would improve accountability and transparency amongst cyber professionals. </p><p>This was higher for respondents in the US, at 55%, compared with those in the UK at 43%.</p><p>When asked about the impact on the cybersecurity leaders of the future, only 15% believed that it would be a deterrent for IT professionals to become CISOs.</p><p>Meanwhile, four-in-ten said the increased scrutiny and potential of personal liability has made the board take cybersecurity more seriously. This was higher in the UK, with 47% of security leaders agreeing, compared with just 35% in the US.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ayY2eqwwgoPAZnhjhJrwDa" name="Bridging the gap_ How security teams can engage developers in security programs.jpg" caption="" alt="Bridging the gap: How security teams can engage developers in security programs" src="https://cdn.mos.cms.futurecdn.net/ayY2eqwwgoPAZnhjhJrwDa.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bridging-the-gap-how-security-teams-can-engage-developers-in-security-programs"><em>Engage developers in security programs</em></a></p></div></div><p>This has yet to translate into more resources, though, with just 10% of all respondents saying such concerns had translated to any rise in security budget. </p><p>"High profile instances of individuals being charged will no doubt add to the pressures they feel but could also be a catalyst for boards to support their leaders," said Williams. </p><p>"Improvements to governance, clear lines of reporting and incident response procedures are vital, but this must be supported by allocated resources so that security leaders can implement the security measures they need."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fredrick Lee is named new Reddit CISO ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/fredrick-lee-is-named-new-reddit-ciso</link>
                                                                            <description>
                            <![CDATA[ The security veteran will lead Reddit’s privacy and security teams as the social media giant plans for further growth ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">btpzvPVfMvnwF4XWP2P4KV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xGWbohG897TjJYGRSPM5kn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Aug 2023 10:17:20 +0000</pubDate>                                                                                                                                <updated>Tue, 01 Aug 2023 14:48:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xGWbohG897TjJYGRSPM5kn-1280-80.jpg">
                                                            <media:credit><![CDATA[Reddit]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Reddit CISO: Fredrick Lee&#039;s headshot]]></media:description>                                                            <media:text><![CDATA[Reddit CISO: Fredrick Lee&#039;s headshot]]></media:text>
                                <media:title type="plain"><![CDATA[Reddit CISO: Fredrick Lee&#039;s headshot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xGWbohG897TjJYGRSPM5kn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Social media and content aggregation giant Reddit has announced the appointment of Fredrick Lee as its new chief information security officer (CISO). </p><p>Reporting to CTO Chris Slowe, Lee is tasked with overseeing Reddit’s privacy and security teams, which tackle the identification and mitigation of risks and challenges around information security, privacy, and compliance.</p><p>The security veteran brings more than 20 years’ experience leading global information and security efforts at major financial services companies and technology startups. </p><p>He joins the company from his previous role as chief security officer (CSO) and head of IT at Gusto and has previously held the position of CSO at Square. </p><p>Commenting on his appointment, Lee underlined Reddit’s need for robust security as the platform looks toward further growth.</p><p>“I believe Reddit uniquely helps its users build meaningful connections and conversations around the areas or interests they are most passionate about,” he said. </p><p>“As Reddit grows, it is crucial that our security and trust systems remain resilient and agile to adapt to the ever-evolving threat landscape. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6r4Roq2TeD4i8UAQmBooyE" name="Leaked Today, Exploited for Life How Social Media Biometric Patterns Affect Your Future _listing.jpg" caption="" alt="Girl looking at a smartphone with digital scanning icons surrounding her face" src="https://cdn.mos.cms.futurecdn.net/6r4Roq2TeD4i8UAQmBooyE.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Leaked today, exploited for life</strong></p><p class="fancy-box__body-text"><em>Read how social media biometric patterns affect your secure future.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/370153/leaked-today-expolited-for-life"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“I’m thrilled to be joining such an exciting platform, and looking forward to helping reinforce the platform’s existing safety infrastructure and cyber security defenses, and continue advancing the systems that protect Redditors and their communities.”</p><p>Reddit says the security of both its platform and the wider business remains one of its “core trust pillars”. The company has continued to bolster its safety and security efforts in recent years, expanding its teams and reinforcing existing measures that are designed to protect the platform and its users.</p><p>Today, the platform stands at 57 million active daily users, with more than 100,000 active communities, and over 13 billion posts and comments.</p><p>As part of its security efforts, Reddit launched a new Transparency Center and regularly shares its practices, updates, and findings to help maintain and protect its global user community.</p><p>One such update was posted back in February, detailing a “sophisticated phishing campaign” that aimed to steal the credentials and <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>two-factor authentication</u></a> tokens of Reddit employees. </p><p>The company said its systems were hacked as part of the campaign, with attackers gaining access to some internal documents, code, as well some internal business systems. </p><p>The point of initial intrusion came from a targeted <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing attack</u></a> on an employee who, after realizing what had happened, self-reported the incident, prompting the firm’s security team to quickly remove the attacker’s access and begin an internal investigation.</p><p>Reddit’s former <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISO</u></a> Allison Miller left the company shortly before the attack took place and it’s not thought that Lee’s appointment is related to the attack or Miller’s departure.</p><p>Looking ahead, Reddit says the appointment of Fredrick Lee as its new CISO will help the organization further develop its security infrastructure and protect its user base.</p><p>“We are thrilled to welcome Lee and his technical expertise and leadership capabilities to Reddit,” said Chris Slowe, Reddit’s <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do"><u>chief technology officer</u></a>. “His extensive experience will be integral to evolving our safety infrastructure and <a href="https://www.itpro.com/security/cyber-attacks/standardized-information-sharing-framework-essential-for-improving-cyber-security"><u>cyber security</u></a> processes so we can continue to ensure our users’ safety and defend against emerging cyber threats.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Crackdown on crypto needed to curb cyber crime, says expert ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/crackdown-on-crypto-needed-to-curb-cyber-crime-says-expert</link>
                                                                            <description>
                            <![CDATA[ Threat actors would struggle to generate money without the anonymity provided by unregulated digital tokens, but such a move would require worldwide buy-in ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nCnrSuRAtHRuhiZWLSiBbK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xGJmPF6JBChS3ooD86YFNA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Jul 2023 13:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 31 Jul 2023 13:11:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xGJmPF6JBChS3ooD86YFNA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Lots of large golden Bitcoin tokens pushed together, set against a sky-blue background]]></media:description>                                                            <media:text><![CDATA[Lots of large golden Bitcoin tokens pushed together, set against a sky-blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Lots of large golden Bitcoin tokens pushed together, set against a sky-blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xGJmPF6JBChS3ooD86YFNA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Governments could reduce international cyber crime by putting stronger regulations on cryptocurrency, a security expert has said.</p><p>Itai Greenberg, chief strategy officer at Check Point, told <em>ITPro</em> that greater government oversight of blockchain technology and transactions would be an immediate way to improve the threat landscape.</p><p>“If we put in regulation, we can dramatically reduce the amount of cyber attacks,” he said.</p><p>“It would have a direct impact, because cryptocurrency allows people to get dollars without being traced.”</p><p>Greenberg acknowledged that the government’s role in enforcing crypto rules can only go so far, and that the blockchain is here to stay.</p><p>“It was never introduced by governments, it will not be disappeared by governments.” </p><p>The different <a href="https://www.itpro.com/security/28031/what-is-blockchain"><u>blockchains</u></a> across the world support many legitimate uses, including more secure transactions of finances and synchronization of data in a decentralized format. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qLBQ6GoSJjwWBnFAofSaPW" name="Conquering technology risk in banking_listing.jpg" caption="" alt="A whitepaper from ServiceNow covering ways banking leaders can transform technology risk into advantage with image of female working stood outside high rise buildings, looking at a smartphone" src="https://cdn.mos.cms.futurecdn.net/qLBQ6GoSJjwWBnFAofSaPW.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Conquering technology risk in banking</strong></p><p class="fancy-box__body-text"><em>Discover the five best practices leaders in technology risk management and resilience.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/conquering-technology-risk-in-banking"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>But Greenberg maintained that clearer rules around tracing and taxing when it comes to the blockchain is still needed.</p><p>“There are many, many good people around the world that contribute to the success of blockchain and cryptocurrency. What they do not have is the big brother that will tell them how to do it right, and we’re starting to see it now with Celcius, with <a href="https://www.itpro.com/technology/cryptocurrencies/370304/regulation-cryptocurrencies-blockchain-useful-business-assets"><u>FTX</u></a>.”</p><p>Because transactions made on the blockchain are irreversible, it can prove difficult to recover funds stolen by hackers, or cryptocurrency that a company sends as ransom to a threat actor.</p><p>Cryptocurrency can be difficult to trace, but not impossible. The FBI was able to locate and recoup $2.3 million of the money lost in the 2021 <a href="https://www.itpro.com/security/ransomware/359615/colonial-pipeline-ceo-confirms-the-company-paid-darkside-hackers-44"><u>Colonial Pipeline ransomware attack</u></a>, and law enforcement can obtain warrants to check the digital assets of suspects.</p><p>Third-party exchanges can also work directly with government agencies to help them access funds.</p><p>But a fully fledged, international scheme to track and tax cryptocurrency would require the participation of world governments, and this could be difficult to secure. </p><p>Nations such as Russia already offer safe harbor to cyber criminals, and could be unwilling to compromise the payment channels of those under their protection.</p><p>More comprehensive tax requirements on crypto assets, as well as more stringent enforcement of existing laws, could help to dissuade criminals seeking to use crypto platforms as a basis for obtaining illicit funds.</p><p>In recent months, international agencies have become even more aggressive in their pursuit of cyber criminals and ransomware groups in particular.</p><p>The US Department of Justice (DoJ) <a href="https://www.itpro.com/security/ransomware/us-identifies-and-places-dollar10-million-bounty-on-lockbit-hive-ransomware-kingpin"><u>placed a $10 million bounty on a Russian man</u></a> linked to the groups LockBit and Hive, and has since <a href="https://www.itpro.com/security/cyber-crime/latest-arrest-places-lockbit-firmly-in-the-crosshairs-of-international-cyber-police"><u>charged a string of LockBit associates</u></a> as it embarks on more operations to disable the group.</p><p>Greenberg praised this activity, saying the actions further protect the cyber security landscape for organizations and individuals.</p><h2 id="improving-cyber-resilience">Improving cyber resilience</h2><p>Speaking on the wider strategies that companies can take to be more resilient to attacks, he suggested abandoning the traditional idea of detection and remediation, and to instead invest in real-time prevention.</p><p>With increasingly automated attacks such as <a href="https://www.itpro.com/security/botnets/367744/ukraines-vigilante-it-army-deploys-ddos-bot-automate-russia-attacks"><u>DDoS bots</u></a> or even <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370337/organisations-soon-be-using-generative-ai-prevent-phishing"><u>AI-assisted fuzzing</u></a>, the time delay between detection and response in older systems could mean the difference between resilience and compromise.  </p><p>Greenberg acknowledged this can change be difficult to implement. For example, while false positives are acceptable in a detection system they can cause unwanted interference and disable core processes if they crop up in a prevention system.</p><p>He said many companies try to estimate how many times per year they will be attacked and that this is likely to be in the thousands, but that some companies fall into the trap of thinking that there’s little difference between 95% prevention and 99% prevention.</p><p>“It’s not about the 95% that you block, it’s about what you don’t block. And it needs to go as close as possible to 100%.”</p><p>Greenberg also highlighted the struggle that <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>chief information security officers (CISOs)</u></a> face in optimising their limited IT budgets, workforce, and skillsets.</p><p>“There are two philosophies here, one that says you split your budget with half in SOC, remediation, engineering people and half in prevention and detection,” he said.</p><p>“I would advise a CISO to put as much as they can into the prevention technology. So make it 90% of your budget, because you are no longer in this race of putting people and technology in to deal with remediation.</p><p>“Resilient companies will put more in prevention and outsource their remediation and incident response into an <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/369416/msps-next-biggest-investment-will-be-in-mdr"><u>MDR</u></a> service.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rubrik appoints Richard Cassidy as new field CISO for EMEA ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/leadership/rubrik-appoints-richard-cassidy-as-new-field-ciso-for-emea</link>
                                                                            <description>
                            <![CDATA[ The former Securonix executive will focus on developing strategy and execution across the region ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P8diGsT2dinkMvxt8HZgig</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jul 2023 10:28:28 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Jul 2023 13:20:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Leadership]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:description>                                                            <media:text><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:text>
                                <media:title type="plain"><![CDATA[Rubrik logo appearing on a background of dark blue]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jYWhBayTGsrCrUWDnNjSSi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero trust data security provider Rubrik has announced the appointment of Richard Cassidy as its new field CISO for the EMEA region. </p><p>As Rubrik’s new field CISO, Cassidy will focus on further developing the company’s strategy and execution across the EMEA region, as well as supporting customers with cyber resilience.</p><p>“Running breach and threat hunting investigations in the UK and Europe has set me up well for a CISO position, where I’ve been involved with organizations across industry verticals such as finance, military, central and national government, and automotive,” he said.</p><p>“I’m passionate about demystifying the complexities of cyber security and how this translates into building viable security ecosystems that stand the test of time. I am really excited to continue this work with Rubrik.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TKHngta7EKcTaB2AYvzpPJ" name="Making sense of a quickly evolving ZTNA market_listing.jpg" caption="" alt="Dark shaded whitepaper cover with orange light rays behind title and logo" src="https://cdn.mos.cms.futurecdn.net/TKHngta7EKcTaB2AYvzpPJ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Making sense of a quickly evolving ZTNA market</strong></p><p class="fancy-box__body-text"><em>Discover new insights from the Enterprise Strategy Group</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/making-sense-of-a-quickly-evolving-ztna-market"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Cassidy’s appointment is the latest in a string of company-wide leadership hires in recent months. Back in June, <a href="https://www.itpro.com/business/leadership/rubrik-appoints-andres-botero-as-chief-marketing-officer"><u>Rubrik announced the appointment of seasoned SaaS leader Andres Botero</u></a> as its new chief marketing officer, while former Zscaler executive <a href="https://www.itpro.com/business/leadership/rubrik-appoints-former-zscaler-executive-as-vice-president-for-ukandi"><u>Toby Keech was hired as vice president for its UK and Ireland business</u></a>. </p><p>The move also follows the launch of advanced user intelligence on the Rubrik Security Cloud platform, which leverages Rubrik’s Time Series Data and Metadata architecture to proactively fight cyber attacks and reduce data risks.</p><p>“Richard joins Rubrik at a very exciting time for the company following the recent launches of our advanced user intelligence and <a href="https://www.itpro.com/security/ransomware/368167/double-extortion-ransomware-pushes-average-payments-close-to-1-million"><u>double extortion ransomware</u></a> solutions,” said James Hughes, VP of Rubrik’s Solutions Engineering business in EMEA. </p><p>“Richard’s experience across the channel, sales, product development, and engineering will be invaluable as we continue to prioritize a <a href="https://www.itpro.com/security/five-zero-trust-pitfalls-to-avoid"><u>zero trust strategy</u></a> and commitment to customers.”</p><p>A renowned industry thought leader and Forbes Technology Council member, Cassidy brings extensive experience in cyber leadership, threat intelligence, and technical advisory to the role. </p><p>The seasoned veteran joins the company from security provider Securonix, where he held the role of vice president of global technology. </p><p>As an advisor to various sectors, Cassidy has spent his 22-year career developing deep knowledge across all aspects of security – including SecOps, threat hunting and forensics, incident response, managed services, as well as networking and cloud.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber insurance costs fall in 2023 despite steep rise in ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/cyber-insurance-costs-fall-in-2023-despite-steep-rise-in-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Premiums drop from historic highs as insurers eye a ransomware resurgence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xDYjLfPhk8yF5YfsV5gyNS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kkRNECmdssyTTqPusj3isG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Jul 2023 10:41:42 +0000</pubDate>                                                                                                                                <updated>Fri, 07 Jul 2023 15:10:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kkRNECmdssyTTqPusj3isG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Denoting cyber insurance, this is a digital mockup of a cityscape as if it were skyscrapers coming out of a motherboard, all in a multi-tonal blue colour scheme]]></media:description>                                                            <media:text><![CDATA[Denoting cyber insurance, this is a digital mockup of a cityscape as if it were skyscrapers coming out of a motherboard, all in a multi-tonal blue colour scheme]]></media:text>
                                <media:title type="plain"><![CDATA[Denoting cyber insurance, this is a digital mockup of a cityscape as if it were skyscrapers coming out of a motherboard, all in a multi-tonal blue colour scheme]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kkRNECmdssyTTqPusj3isG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber insurance pricing is down by 9% in 2023 following an all-time high at the end of 2022, despite ransomware activity having increased 48% year on year (YoY).</p><p>The figures show the shock experienced by the cyber insurance market during 2020 and 2021 as ransomware frequency and severity escalated sharply. The result increased the cost of cyber cover more than double.</p><p>Things are more nuanced in 2023, according to a report published by the Howden Group. Activity relented in 2022 - accompanied by the implementation of mitigations and risk controls by companies - before surging again in 2023.</p><p>However, strengthened defenses have paid dividends and the report noted that “resurgent ransomware activity in the first half of the year has so far not been accompanied by a corresponding rise in losses or claims”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9dA5Tkp445uoybcjDEhAsT" name="The near and far future of ransomware business models_listing.jpg" caption="" alt="Rear facing image of man sat in dark tech lab using VR headset and gloves" src="https://cdn.mos.cms.futurecdn.net/9dA5Tkp445uoybcjDEhAsT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The near and far future of ransomware business models</strong></p><p class="fancy-box__body-text"><em>What would make ransomware actors change their criminal business models?</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The effect of this is that despite the uptick in ransomware activity, cyber insurance premiums are remaining flat or even decreasing from their historic highs.</p><p>The <a href="https://www.howdengroup.com/sites/g/files/mwfley566/files/2023-07/howden-cyber-report-coming-of-age-03072023-final_0.pdf"><u>report</u></a> described the surge in ransomware during 2020 and 2021, attributed in part to the availability of <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service"><u>low-cost ransomware kits</u></a>, as “unlike anything experienced previously”.</p><p>At one point in 2021, ransomware incidents were up by 390% compared to a Q1 2019 baseline. The result was what the report described as a “major market correction”.</p><p>After 18 months of relative calm for the <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a> market, optimism around a drop in claims and a return to competition was tempered by an increase in global ransomware attacks - up 47% in the first quarter of 2023 compared to the same period in 2022.</p><p>The average US <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> payment also went up by 55% YoY.</p><p>Ransomware gangs have been accelerating their activity after a year of comparatively smaller gains. Average ransom payments in early 2023 were nearly double those of the previous year. 40% of companies surveyed reported payments of $1 million compared to 11% in 2022.</p><p>Cyber criminal groups are paying more attention to an organization’s ability to pay versus the security measures in place, according to the report. </p><h2 id="mounting-issues-with-cloud-outages">Mounting issues with cloud outages</h2><p>Away from cyber insurance, the report also highlighted the potential for businesses to become more greatly exposed to spiraling losses due to interruptions in the digital supply chain, not necessarily only from cyber attackers.</p><p>Jonathan Hatzor, CEO at Parametrix Insurance, said: “The cloud goes down almost every day”.</p><p>He noted that the big three cloud vendors only tended to report major disruptions and that the most common reported cause of outages was human error.</p><p>The resulting financial and <a href="https://www.itpro.com/security/data-breaches/357063/the-it-pro-podcast-the-myth-of-reputational-damage">reputational costs</a> from such incidents can be severe.</p><p>Estimates can vary depending on the <a href="https://www.vertiv.com/globalassets/documents/reports/2016-cost-of-data-center-outages-11-11_51190_1.pdf"><u>research</u></a> and the type of customer, but an organization’s financial loss as a result of a major outage at one of the big three <a href="https://www.itpro.com/cloud/370001/hyperscaler-earnigns-highlight-new-era-of-maturity-in-global-cloud-market">hyperscalers</a> could range between a few thousand dollars per hour and more than $300,000.</p><p>“Cyber supply chain risk is something that companies operating in all sectors and geographies need to measure, manage, and mitigate,” said Hatzor.</p><h2 id="war-exclusions">War exclusions</h2><p>Finally, the war exclusions issue in cyber insurance has focused minds as positions are clarified on <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber warfare</a> and buyers check that existing levels of protection will be maintained. </p><p>Earlier this year, cyber insurance provider Lloyd’s introduced ‘war exclusions’ to its policies, attracting criticism from the industry. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6gaPJVtHp6DDtttvxJLHma" name="Monitoring & alerting best practices guide_listing.jpg" caption="" alt="Blue eBook cover with logo and title and image of smiling female holding glasses in front of a laptop" src="https://cdn.mos.cms.futurecdn.net/6gaPJVtHp6DDtttvxJLHma.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: LogicMonitor)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Monitoring & alerting best practices guide</strong></p><p class="fancy-box__body-text"><em>Best practices for smarter alerting, faster troubleshooting, and more proactive monitoring</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/monitoring-and-alerting-best-practices-guide"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>The new wording from Lloyds and the broking community means losses will not be covered if they arise from a physical war, from a cyber attack carried out as part of a physical war, or "from a state-sponsored cyber attack that causes a major detrimental impact to the essential services required for the functioning of a sovereign state”.</p><p>While the clause might sound initially alarming, the report noted that “cyber insurers have confirmed that they do not consider any attack to date, including NotPetya, would be of sufficient scale to trigger the exclusion”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security consolidation is about improving results, not just cost savings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/security-consolidation-is-about-improving-results-not-just-cost-savings</link>
                                                                            <description>
                            <![CDATA[ Channel partners can play a key role in enabling businesses to consolidate security operations and bolster resilience ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HVExvNtPcxZxxpseyT3kBm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Jun 2023 11:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 19:45:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matthew Middleton-Leal ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RA5TMT4SzkAwrdBagh9GAc.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:description>                                                            <media:text><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock operating on the electronic circuit CPU]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JiT3Ap3nyi8dqAUWbuxrF7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The economy is in a difficult situation. ONS figures show that the UK economy grew by 0.1 percent in the first quarter of 2023 and the cost-of-living crisis continues to affect confidence. </p><p>While the technology sector has traditionally been able to weather tough conditions, that&apos;s not the case this time around. </p><p>Even areas like IT security are facing challenges. While Gartner predicted this market will <a href="https://www.gartner.com/en/documents/4019160" target="_blank"><u>continue to grow by 11.1% year-on-year</u></a> through to 2026, this increase in spending will have to be stretched further to keep pace with emerging threats. </p><p>CISOs are having to look at their strategies with fresh eyes in order to stretch budgets, including potentially consolidating the number of vendors they work with.</p><p>So what will these consolidation exercises look like, and how can channel partners capitalize?</p><h2 id="what-should-consolidation-mean-to-your-customers">What should consolidation mean to your customers?</h2><p>When we use the term consolidation, we typically mean cost-cutting. However, for security teams, the ability to reduce costs should not be conflated with decreasing budgets, which will ultimately leave teams without critical resources. </p><p>The challenge is how to make budgets go further and invest where companies need it, rather than this being an exercise in having money taken away.</p><p>Waiting until customers ask about this approach is too late. Instead, taking a proactive approach can put you - and your customer’s security team - in the driving seat when it comes to how projects are defined and what the success metrics are.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-the-channel-can-help-secure-the-future-of-work">How the channel can help secure the future of work</a></p></div></div><p>To get started, analyze how your customer manages their security processes and the products. It’s easy to build up shelfware that is either not being used, or only utilized for tasks that are not valuable enough to carry on spending on them. </p><p>These solutions can be removed and replaced with more cost-effective options, especially where other solutions can be used to cover the same tasks.</p><p>This may throw up some interesting findings. You may find yourself dealing with challenging scenarios and internal company politics. For example, you may find that processes are not as efficient as they could be, or that teams are relying heavily on manual work to get things done.</p><p>In a worst case scenario, you may uncover something that is not compliant with an industry standard or regulation. </p><p>It’s important to be tactful here, as security teams may have invested a lot of their time into building and evolving their processes. With anything that has been in place for a while, this can create a lot of attachment. While we all like to think of ourselves as rational beings, this is not always the case. </p><p>Taking a diplomatic approach can pay off as no-one likes to think of their deployment as wasteful.</p><h2 id="building-back-up-again">Building back up again</h2><p>Once you have established the tools, processes, and people involved in delivering security, you can assess the potential overlaps and where consolidation can occur. </p><p>Every vendor talks about the mythical single pane of glass for security, and you may find that customers have multiple ways of achieving this result. They may even be running multiple product suites for their security and risk management requirements, from identity management through to firewalls, <a href="https://www.itpro.com/security/369418/information-security-vs-cyber-security-vs-network-security"><u>network security</u></a>, and cloud.</p><p>From here, you can look at how to consolidate and improve security operations. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/building-channel-resilience-in-2023-and-beyond">Building channel resilience in 2023 and beyond</a></p></div></div><p>This may remove some tools, but the main goal should be to achieve better processes and faster delivery. Ideally, you can reduce the overall vendor count and make use of more integrated suites of services rather than multiple products. </p><p>This can make a big difference in cloud environments, where customers would otherwise have to run multiple agents to get the security services they need. Taking a ‘one agent’ approach reduces the overall amount of compute resources required to manage security services, which helps the customer save costs.</p><p>On top of this audit, you can move into recommending how best to consolidate and maintain security levels. For example, many companies will subscribe to a <a href="https://www.itpro.com/endpoint-security/30038/three-key-pillars-of-threat-visibility"><u>threat intelligence </u></a>feed, but do they make use of it? </p><p>Instead, can you supply a service that combines multiple feeds for better coverage while also offering recommendations on where to improve over time. This delivers an ongoing revenue opportunity while helping customers reduce their spending on specific security products.</p><p>Alongside this, explore ways  you can help the customer to automate their processes where possible. These efforts not only help the security team work faster and more efficiently, but it can show where there are ways to improve processes and working practices. </p><p>Security vendors are all deploying AI and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning]"><u>machine learning</u></a> to streamline processes, but this should also be used to free up focus time for security analysts.</p><h2 id="looking-for-more-opportunities-around-value">Looking for more opportunities around value</h2><p>While security consolidation projects may set out to cut costs, they might lead to other opportunities that you can build on. For instance, many companies now need more help in communicating their security position to their internal leadership teams or the board. </p><p>This calls for more risk management support, but it also requires nuanced communication support as well. It is not enough to <em>just </em>provide a dashboard – instead, you may need to help security teams <a href="https://www.itpro.com/security/information-security-infosec/370355/cyber-security-suffers-communication-problem"><u>work on how they communicate with leadership</u></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/how-the-channel-ecosystem-can-tackle-future-tech-shocks">How the channel ecosystem can tackle future tech shocks</a></p></div></div><p>Improving communication is a great secondary objective for consolidation projects. By cutting the number of tools involved, you can remove some of the headaches for security teams about getting the right data together. </p><p>On top of this, you can make it easier for them to demonstrate they are doing a good job.</p><p>Many companies need help on security consolidation projects. To maximize these opportunities, start by looking for overlaps and gaps. Once this audit is complete, you can make recommendations on how to reduce the number of vendors, integrate those that are in place, and make processes more efficient for everyone involved. </p><p>The result should save the company money, but it should also deliver better security posture for the future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The cyber security skills your business needs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs</link>
                                                                            <description>
                            <![CDATA[ The threat landscape is constantly evolving, so it's important you have the right cyber security skills in place ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g54rZeYwyrofCQX35aFahU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/aEqLCd2eKuD4Zq2b8gRXAb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Sep 2019 10:22:00 +0000</pubDate>                                                                                                                                <updated>Thu, 26 Oct 2023 09:15:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Peter Ray Allison ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Zach Cooper ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/aEqLCd2eKuD4Zq2b8gRXAb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:description>                                                            <media:text><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:text>
                                <media:title type="plain"><![CDATA[A graphic depiction of an ethical hacker certificate]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/aEqLCd2eKuD4Zq2b8gRXAb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security has become a vital part of any business plan. Even the smallest business needs to have the appropriate policies and methodologies in place for protecting their data as best they can.</p><p>To achieve this, every business needs access to a variety of cyber security skills, whether that&apos;s through hired staff or trusted partners.</p><p>Minimizing the <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management">threat surface</a> only goes so far. As businesses grow, through opening new offices and new staff joining, so too does the potential threat surface, especially with expanding network coverage and new cloud systems being incorporated.</p><p>Given the multitude of online threats facing modern businesses, it can be easy to be overwhelmed by the many different types of security required. Cyber attacks are inevitable; but, with the appropriate skillsets in place, it is possible to take advantage of the opportunities offered online whilst protecting data and mitigating the risk of attack.</p><h2 id="the-cyber-security-skills-every-business-needs">The cyber security skills every business needs</h2><h3 class="article-body__section" id="section-ethical-hacking"><span>Ethical hacking</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2120px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="vTWY5tC2VcR7hhst2CUbND" name="Ai_businessman_GettyImages-1449793314.jpg" alt="A businessman looking at a tablet in front of an abstract background of blue lines and dots" src="https://cdn.mos.cms.futurecdn.net/vTWY5tC2VcR7hhst2CUbND.jpg" mos="" align="middle" fullscreen="" width="2120" height="1193" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty)</span></figcaption></figure><p>One of the most effective ways to gain a granular understanding of a business&apos; threat posture is to use <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hacking</a>. An ethical hacker’s job is to assume the role of an offensive hacker and probe a business’ IT estate for vulnerabilities and attack paths so these can be fixed or otherwise mitigated.</p><p>The skill set of an ethical hacker can prove invaluable to organisations. The value to be had is not just in spotting security issues; the deep understanding of computer systems required to do the job can help when building new products like apps, for example, and they can be built securely from the outset.</p><p>It&apos;s important to note that ethical hacking is more than just <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>. While penetration testing assesses the technical elements of a system, and is a central component of many cyber security strategies, ethical hacking considers all parts of a business, including soft-skills and the security culture.</p><p>Ethical hacking essentially acts as a live-fire training exercise of what could happen during a targeted attack, giving valuable experience to IT teams and identifying potential vulnerabilities in the threat posture. This can involve conducting genuine phishing attempts against staff to see if the organisation’s access management rules are robust enough. It can also involve testing the <a href="https://www.itpro.com/enterprise-security/31054/under-the-prevailing-threat-of-ransomware-physical-security-is-being">physical security</a> of the office itself.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="G68qR5iUp7vD2Gd45xkAsS" name="The Business Leader’s Guide to Digital Worker Technology for Improving Productivity 2 (1).jpg" caption="" alt="The business leader’s guide to digital worker technology for improving productivity whitepaper" src="https://cdn.mos.cms.futurecdn.net/G68qR5iUp7vD2Gd45xkAsS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><em>Turn your workforce into a talent force <br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/the-business-leaders-guide-to-digital-worker-technology-for-improving-productivity">DOWNLOAD NOW</a></p></div></div><p>Ethical hacking can be performed in-house by your own <a href="https://www.itpro.com/security/34590/stories-from-the-front-line-the-secrets-of-the-red-team-revealed">Red Team</a> – a group of employees tasked with pretending to be adversaries – but for an optimum understanding of the response to a breach, an external testing team can be covertly contracted.</p><p>How far you go with ethical hacking will largely be a question of resources, as there really is no limit to what you can learn about your own systems. That said, ethical hacking does involve misleading employees, and so each business will need to assess what is reasonable.</p><h3 class="article-body__section" id="section-network-security"><span>Network security</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2121px;"><p class="vanilla-image-block" style="padding-top:66.67%;"><img id="AoporhjzSb25rJ6qKjGh78" name="GettyImages-1459899801.jpg" alt="A digital purple cloud connected to cubes by lines to symbolise a business network" src="https://cdn.mos.cms.futurecdn.net/AoporhjzSb25rJ6qKjGh78.jpg" mos="" align="middle" fullscreen="" width="2121" height="1414" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Modern businesses rely on their networks, and so strong network security is fundamental. With the types of available network tools increasing and more devices being connected to networks, it&apos;s imperative that the appropriate security technologies are in place to protect the flow of data.</p><p>Administrating access controls is an essential part of network security. Access rights ensure each user and device has the appropriate level of access and that data are protected against potential threats, both malicious and accidental. The concept that governs this the information security principle of &apos;Least Privilege&apos; – the idea that employees should only be given access to the data they need to perform their jobs effectively. Anyone who works outside of <a href="https://www.itpro.com/digital-transformation/34350/five-digital-transformation-tips-for-hr">HR</a>, for example, shouldn’t be able to access HR files, while those who work in the finance department are the only ones who should be able to access payroll data.</p><p>Administrators will be pleased to know that there are plenty of tools to choose from to help them adopt these policies. This includes firewalls, <a href="https://www.itpro.com/security/27098/best-vpn-services" target="_blank" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPNs (virtual private networks),</a> or even the fancy new machine learning algorithms which can identify when a device or user is acting strangely and automatically cut it off from the network. Machine learning is also being deployed in firewalls to make web application firewall (WAF) tools. WAFs help to create an extra barrier to prevent hackers from targeting your apps, although they aren’t intelligent enough yet to determine whether users are humans or machines.</p><h3 class="article-body__section" id="section-cloud-security"><span>Cloud security</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2386px;"><p class="vanilla-image-block" style="padding-top:52.64%;"><img id="wxGViKgPy2V5b45ABRZo5c" name="Multi_Cloud_Stock_Image_GettyImages-1478328227 (1).jpg" alt="Five cloud symbols on a blue background signifying multi-cloud approach" src="https://cdn.mos.cms.futurecdn.net/wxGViKgPy2V5b45ABRZo5c.jpg" mos="" align="middle" fullscreen="" width="2386" height="1256" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>The Cloud has become a ubiquitous part of the modern enterprise environment, whether it is online storage or leasing additional processing power through cloud computing. That said, while <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362605/what-is-iaas">IaaS</a> providers take steps to maintain data integrity, looking after your own data is your responsibility, not the cloud storage provider&apos;s.</p><p>Not all cloud providers are the same. Although the core services they offer are broadly the same, they offer different functionalities and levels of protection, based upon the service subscription. Part of the cloud security skill is being able to curate the different cloud services, choosing which is the most appropriate for the business and its objectives.</p><p>However, cloud security is a highly technical skill that requires an in-depth understanding of how the cloud operates and remains one of the hardest skillsets to find.</p><p>Among the cloud security threats is poor identity management, as hackers may mask themselves as legitimate users in order to access, modify and delete data.</p><p>Another is poorly-secured cloud apps. Most apps and cloud services <a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">use APIs</a> to communicate and transfer data. This means the security of the API directly affects a cloud service&apos;s security. The chance of a data breach increases when third parties are granted access to APIs.</p><p>Institutions such as SANS and CSA offer cloud security certifications for professionals to increase their skill sets in this area.</p><h3 class="article-body__section" id="section-risk-management"><span>Risk management</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2121px;"><p class="vanilla-image-block" style="padding-top:66.67%;"><img id="h5HmEjSf6HH6vFTvLi5mkJ" name="GettyImages-1376105849.jpg" alt="A man in a modern office pointing to a board covered in multi-coloured sticky notes" src="https://cdn.mos.cms.futurecdn.net/h5HmEjSf6HH6vFTvLi5mkJ.jpg" mos="" align="middle" fullscreen="" width="2121" height="1414" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Risk management is a necessary part of cyber security. Risk is a combination of the likelihood of something happening and the impact it would have.</p><p>Having the appropriate strategies and planned response for cyber incidents forms the foundation of any strong risk strategy, which should incorporate prevention (reducing risk), resolution (response during an incident) and restitution (post-incident actions).</p><p>With limited resources, escalating threats and a plethora of security technologies being marketed, businesses need to carefully consider the most effective investments for their IT budget. This requires an innate understanding of the risks facing the core functionality of the business.</p><p>A background in risk management offers the capacity for in-depth risk analysis for the threats a business is facing and their potential vulnerabilities. This skillset enables businesses to carefully balance the needs of maintaining operations against potential risks within the IT budget.</p><h3 class="article-body__section" id="section-patching-and-software-management"><span>Patching and software management</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2067px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="Gs4LmKsDtuCe6fUMMPJaP5" name="GettyImages-1343575026 2.jpg" alt="A close up of a button labelled 'update' on a blue computer screen" src="https://cdn.mos.cms.futurecdn.net/Gs4LmKsDtuCe6fUMMPJaP5.jpg" mos="" align="middle" fullscreen="" width="2067" height="1163" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Ensuring software is up to date and secure is vital for maintaining a robust security posture, as known <a href="https://www.itpro.com/security/exploits/360411/top-30-most-exploited-vulnerabilities">vulnerabilities</a> are quickly exploited by threat actors. It can often be seen as an ever-escalating arms race between hackers and patchers.</p><p>The instinctive response when a new patch is released might be to immediately deploy it, but this can negatively impact the business by overloading the network or losing functionality. New products and services that can be used to maintain competitiveness need to be deployed, but without disrupting ongoing business operations.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fdMyvv7XRnNYS5yNAjWJUA" name="GettyImages-1356382582_AI_code_software.jpg" caption="" alt="Lines of blue computer code next to a blue digital render of a human face" src="https://cdn.mos.cms.futurecdn.net/fdMyvv7XRnNYS5yNAjWJUA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/how-ai-is-changing-patch-management">How AI is changing patch management</a></p></div></div><p>For networks that incorporate modified, specialist or bespoke systems, it can be prudent to test an update in advance by virtually deploying it in a sandbox environment. Doing so enables administrators to test whether the patch will adversely impact any systems within the network.</p><p>Patching and software deployment need to be considered in association with maintaining business operations, usually by scheduling them during out of normal business hours. However, this can be complicated when there are multiple sites in different time zones. Thus, software management is just a much a collaboration between security and business operations as it is a skill in coordinating updates.</p><h3 class="article-body__section" id="section-big-data-analysis"><span>Big data analysis</span></h3><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2309px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="VGzkXrzhdDXaUHzZM6tc5L" name="GettyImages-1471976069.jpg" alt="A CGI image of cubes rippling at slightly varying heights, each marked with a '1', a '0', or the image of an orange padlock to represent data security. It is lit in blue and purple light." src="https://cdn.mos.cms.futurecdn.net/VGzkXrzhdDXaUHzZM6tc5L.jpg" mos="" align="middle" fullscreen="" width="2309" height="1299" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>IT teams are bombarded with information generated by a multitude of security systems, which can quickly become overwhelming and potentially lead to valuable insights being missed.</p><p>Being able to curate the diverse information streams and prioritize critical information is therefore a key skill. A single incident on its own may be negligible, but when the same incident keeps repeating, then action may need to be taken. It&apos;s important security teams are able to effectively analyze the data and provide a rapid response to escalating threats.</p><p>Big data analysis is particularly effective at identifying advanced persistent threats (APTs), as there are often massive amounts of data to analyze for abnormalities. With big data analysis, APTs will be spotted sooner, allowing the mitigation of the potential damage they may cause.</p><h3 class="article-body__section" id="section-non-technical-skills"><span>Non-technical skills</span></h3><p>Due to the highly technical nature of IT, there can be a rift between IT departments and the rest of the business. The weakest link within a business’s security posture is often the people, most commonly through unsecure devices and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a>.</p><p>However, robust security posture is not just dependent upon technical skills, but also upon communication and collaboration. There needs to be clear exchange between all stakeholders to ensure an understanding of security needs.</p><p>Being able to communicate the need for IT security in an easy-to-understand format is a crucial skill for encouraging a culture of <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">security awareness</a>. This could be through presenting seminars on pro-active security skills or orchestrating security exercises to educate staff and identify those who may need further training.</p><p>Networking with others within the security sphere is also useful for being forewarned of emerging trends and potential threats.</p><h3 class="article-body__section" id="section-governance-compliance"><span>Governance & compliance</span></h3><p>The past few years have witnessed a swathe of security legislation around the world, especially in regard to data security. Although the <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">EU’s General Data Protection Regulation</a> has become the default standard for <a href="https://www.itpro.com/security/data-protection">data protection</a>, there are variations between different legislations, which can cause lengthy data sharing issues for unprepared businesses.</p><p>Export control regulations need to be followed, especially for third-party providers that offer services to both sensitive and non-sensitive business sectors.</p><div  class="fancy-box"><div class="fancy_box-title">More on governance & compliance</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Ac4YQsZyHatCHishgE9mFi" name="Ac4YQsZyHatCHishgE9mFi.jpg" caption="" alt="A padlock on a circuit board in a dark room" src="https://cdn.mos.cms.futurecdn.net/Ac4YQsZyHatCHishgE9mFi.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/369834/building-a-data-governance-strategy">Building a data governance strategy in 2023</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/it-legislation/29635/gdpr-certification-what-is-it-and-do-you-need-it">GDPR certification: What is it, and do you need it?</a></p></div></div><p>Knowledge of IT governance enables businesses to have an innate understanding of the legislative requirements that applies to them, thereby ensuring that they can seamlessly exchange information between all the regions they operate in.</p><p>The proliferation of regulations being applied not only protects consumer privacy, but also protects business data and IT infrastructure. Compliance benefits both the organisation and any customers and partners it comes into contact with. Though, it is important to not be so focused on simply compliance that actual cyber risks are forgotten.</p><h3 class="article-body__section" id="section-automation"><span>Automation</span></h3><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WBcZFAaexhFbdb92SXvCpR" name="" alt="A hand reaching out to a screen which displays automation options" src="https://cdn.mos.cms.futurecdn.net/WBcZFAaexhFbdb92SXvCpR.jpg" mos="https://cdn.mos.cms.futurecdn.net/WBcZFAaexhFbdb92SXvCpR.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>One solution being proposed to cover the problem of the cyber security skills gap, while also improving security in businesses overall, is the increased use of automation.</p><p>With threats increasing and budgets not necessarily keeping pace with inflation, businesses are turning to automation to cut the cost out of simple tasks, enabling staff to prioritize their attention on difficult ones. The increasing functionality of machine learning enables some of the simpler and repetitive tasks to be automated.</p><div  class="fancy-box"><div class="fancy_box-title">More on automation</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wYEx4rNisx3HvKtgtzRdu7" name="wYEx4rNisx3HvKtgtzRdu7.jpg" caption="" alt="Traffic moving really fast on a motorway at night" src="https://cdn.mos.cms.futurecdn.net/wYEx4rNisx3HvKtgtzRdu7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/slack-says-automation-can-save-every-employee-a-month-of-work-per-year">Slack says automation can save every employee a month of work per year</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/what-is-decision-automation">What is decision automation and what are the benefits?</a></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/automation/367382/hyperautomation-in-action-most-exciting-examples">Hyperautomation in action: The most exciting examples</a></p></div></div><p>This needs to be done with care; solely relying on automation could be detrimental, as automation is not always 100% effective. Instead, automation is best used for everday tasks, such as flagging potential abnormal network behavior, with a human in the loop for decision-making. This means that anything flagged as a potential issue is less likely to be a waste of human time.</p><p>AI and machine learning can identify threats by type, such as <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> or <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attempts, whether it&apos;s a known malware strain or not. They can also identify errant behaviour by users, for example, if a person who works 9-5 becomes active at 3am, or starts trying to access systems and data they don&apos;t normally or don&apos;t have the appropriate privileges for. This could be indicative of a successful hack or an insider threat and can be investigated by the appropriate members of the IT team.</p><p>The most modern enterprise security software offers AI and machine learning capabilities, although what you choose to adopt will depend on the skills already present in your business, and how able you are to balance existing skills.</p><p>For example, if there&apos;s no one in your business who knows how to investigate and remedy potential and actual hacks, you will need to train someone up in this area in order to use the software effectively.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is an MSSP? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/28879/what-is-an-mssp</link>
                                                                            <description>
                            <![CDATA[ Why appointing an MSSP is becoming the norm for SMBs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8y3sBo9TBqYjsU9nftpRZY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 22 Aug 2019 10:50:00 +0000</pubDate>                                                                                                                                <updated>Fri, 31 Oct 2025 14:14:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:description>                                                            <media:text><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:text>
                                <media:title type="plain"><![CDATA[Female IT programmer working on a desktop computer in data centre]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pXCbVvNzHjKfG3wFAC6vS9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The frequency and complexity of cyber attacks continue to escalate, creating a challenging environment for organizations of all sizes. In 2025, cybersecurity<a href="https://www.itpro.com/uk/security"><u> </u></a>is dominated by advanced threats, including AI-powered <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a>, adaptive malware, and relentless <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware </u></a>campaigns. Cybercriminals are leveraging artificial intelligence to automate and personalize attacks, making them harder to detect and more effective at bypassing traditional security measures. For example, <a href="https://www.rapid7.com/blog/post/emerging-trends-in-ai-related-cyberthreats-in-2025-impacts-on-organizational-cybersecurity/"><u>AI-driven phishing</u></a> can now tailor messages to mimic trusted contacts and adapt to avoid detection, while AI-powered malware evolves in real time to evade defenses.</p><p>Recent data underscores the severity of this trend: ransomware attacks are surging, with a notable 84% increase in ransomware incidents over the previous year, and ransomware now accounts<a href="https://www.sentinelone.com/cybersecurity-101/cybersecurity/cyber-security-statistics/"><u> </u></a>for 35% of all cyberattacks in 2025. The<a href="https://www.ibm.com/reports/data-breach"><u> global average cost of a data breach reached an all-time high of $4.88 million in 2024</u></a>, a 10% increase from the prior year. This intensification of threats is further amplified by the rapid adoption of AI by both cybercriminals and state-sponsored actors, who use it to automate reconnaissance, exploit vulnerabilities, and conduct large-scale social engineering attacks.</p><p>For many businesses, especially small and mid-sized organizations, effectively managing security in-house is an increasingly daunting challenge. This difficulty is compounded by a persistent cybersecurity skills gap, with an <a href="https://www.isc2.org/Insights/2024/09/Employers-Must-Act-Cybersecurity-Workforce-Growth-Stalls-as-Skills-Gaps-Widen"><u>estimated 4.8 million person shortage</u></a> in the industry. </p><p>The struggle to keep pace with evolving threats and a lack of specialized talent has made the services of a Managed Security Service Provider (MSSP) more critical than ever. The <a href="https://www.thebrainyinsights.com/report/managed-security-services-market-12638#:~:text=Market%20Introduction,propel%20the%20MSS%20industry%20forward."><u>global market for managed security services is projected to reach nearly $76 billion by 2030</u></a>, reflecting a growing reliance on outsourced expertise to build cyber resilience. An MSSP offers the specialized knowledge and continuous monitoring necessary to protect vital infrastructure, allowing internal teams to focus on core business objectives.</p><h3 class="article-body__section" id="section-what-is-an-mssp"><span>What is an MSSP?</span></h3><p>MSSPs are specialized third-party providers that deliver outsourced cybersecurity services. They handle the security operations for an organization, either in part or in full, and can do so from a remote location or by placing experts on-site.</p><p>An MSSP may offer a broad suite of security capabilities or specialize in core focus areas like <a href="https://www.itpro.com/uk/cloud"><u>cloud </u></a>security or compliance. The majority, however, will manage a business's security infrastructure and monitor systems for threats from their own Security Operations Centers (SOCs). To do this, they implement and manage a sophisticated technology stack that goes far beyond basic <a href="https://www.itpro.com/antivirus/28144/best-antivirus"><u>antivirus </u></a>software. Common tools include Security Information and Event Management (SIEM) platforms, Managed Detection and Response (MDR) services, <a href="https://www.itpro.com/security/27098/best-vpn-services"><u>VPN </u></a>management, and advanced firewall management.</p><p>Ongoing responsibilities also include system upgrades, patch management, and configuration changes, ensuring a client's security posture continuously adapts to new threats and business demands.</p><h3 class="article-body__section" id="section-services-an-mssp-can-provide"><span>Services an MSSP can provide</span></h3><p>MSSPs offer a comprehensive suite of services designed to protect organizations before, during, and after a cyber attack. Proactively, their primary goal is to harden the IT infrastructure and enforce robust security policies to minimize the attack surface. This includes vulnerability assessments, penetration testing, and ensuring systems are configured securely.</p><p>Should an attack occur, an MSSP's role shifts to rapid detection and response. Using advanced security monitoring tools, they can identify threats in real time and take immediate action to neutralize them, preventing or limiting damage to the organization's systems.</p><p>Because MSSPs serve numerous clients, they accumulate a vast amount of experience dealing with a wide variety of attacks. This broad visibility allows them to understand emerging threat patterns and containment strategies. They leverage this collective knowledge to continuously refine and strengthen your security posture.</p><p>Typical services provided by an MSSP include:</p><ul><li><strong>Security infrastructure management:</strong> Implementing and managing firewalls, intrusion detection and prevention systems (IDPS), and other security hardware and software.</li><li><strong>24/7 monitoring and threat detection:</strong> Continuously monitoring networks, systems, and applications for suspicious activity from a Security Operations Center (SOC).</li><li><strong>Vulnerability management:</strong> Regularly scanning for and remediating vulnerabilities in your systems through patching and configuration updates.</li><li><strong>Incident response and remediation:</strong> Developing and executing a plan to contain threats, eradicate them from the network, and <a href="https://www.itpro.com/storage/29803/best-backup-software"><u>recover affected systems</u></a>.</li><li><strong>Security information and event management (SIEM):</strong> Aggregating and analyzing log data from various sources to detect patterns indicative of a cyber attack.</li><li><strong>Compliance management:</strong> Assisting organizations in meeting regulatory requirements such as GDPR, HIPAA, or PCI DSS.</li></ul><p>For a small to medium-sized business (SMB), a good MSSP functions as a seamless extension of the firm's own IT employees, providing specialized expertise that would be difficult and expensive to build in-house.</p><h3 class="article-body__section" id="section-why-use-an-mssp"><span>Why use an MSSP?</span></h3><p>For organizations seeking to alleviate the stress and complexity of building and maintaining robust security infrastructure, partnering with an MSSP is often the optimal choice. An MSSP not only relieves internal IT teams of the bulk of routine security tasks, such as daily threat monitoring and incident response, but also assumes responsibility for maintaining uptime, managing upgrades, and ensuring swift remediation in the event of a breach.</p><p>While some organizations may develop and execute their own security strategies, from deploying necessary software and training staff to allocating adequate resources, this approach can prove overwhelming, particularly for smaller IT teams. In such cases, outsourcing to an MSSP becomes a compelling solution.</p><p>SMBs frequently lack the specialized expertise required to manage a comprehensive security infrastructure independently. Even with strong commitment and resource allocation, the demands of security maintenance can quickly exceed the capacity of limited teams. This strain can result in critical IT functions, like system patching, hardware management, and digital transformation initiatives, receiving insufficient attention. The rise of <a href="https://www.itpro.com/security/357935/top-security-tips-for-employees-working-from-home"><u>remote work</u></a> only compounds these challenges by introducing additional layers of complexity.</p><p>The evolving cybersecurity landscape further complicates matters. Smaller teams may struggle to respond effectively to the full spectrum of threats, especially as cyberattacks become more sophisticated. While in-house staff can handle some known risks, an MSSP provides specialized expertise and round-the-clock monitoring, offering a crucial layer of protection and peace of mind. Leading MSSPs bring a depth of knowledge that is difficult to cultivate internally, with dedicated teams that continuously monitor emerging threats, assess IT environments, and provide actionable recommendations. They also deliver support services, keeping all business units informed and engaged.</p><p>Partnering with an MSSP also addresses the persistent challenge of talent acquisition. Many <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISOs </u></a>report increasing difficulty in recruiting and retaining skilled security professionals, a problem that is especially acute for smaller firms or those located outside major urban centers. MSSPs offer immediate access to a pool of experienced security specialists, eliminating recruitment headaches and ensuring continuous protection.</p><p>MSSPs provide a comprehensive suite of security services delivered remotely, and their pricing models are typically designed to accommodate financial constraints. Most providers charge a predictable, flat monthly fee, enabling businesses to budget effectively and avoid unexpected expenses.</p><p>As technology evolves, MSSPs ensure that security measures scale and adapt alongside your business. Through regular assessments and audits, they deliver strategic insights and recommendations, allowing organizations to focus on core business objectives without compromising security.</p><p>MSSPs can operate either on-site or <a href="https://www.itpro.com/business/business-strategy/356096/remote-working-are-you-ready-for-the-new-normal"><u>remotely</u></a>, but in either scenario, they integrate seamlessly with existing IT teams. This collaboration frees internal staff to concentrate on innovation and other strategic projects, rather than being consumed by security incidents. Ultimately, MSSPs help enhance customer experiences by improving response times and boosting satisfaction.</p><p>By partnering with an MSSP, organizations can overcome resource limitations, access specialized expertise, and achieve scalable, cost-effective security, all while enabling their internal teams to focus on driving business growth.</p><h3 class="article-body__section" id="section-msp-vs-mssp"><span>MSP vs MSSP</span></h3><p>A <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service"><u>managed service provider </u></a>(MSP) offers a broad range of IT management services, such as network support, application management, system administration, and email management, typically delivered to multiple clients on a recurring, pay-as-you-go basis. While MSPs are essential for maintaining smooth business operations and IT efficiency, their security offerings are generally limited to baseline protections like routine monitoring and patch management.</p><p>In contrast, an MSSP specializes exclusively in cybersecurity, delivering advanced, round-the-clock services such as threat detection, incident response, and compliance monitoring from a dedicated security operations center (SOC). MSSPs are well-positioned to serve as strategic security partners for organizations seeking robust protection as cyber threats grow in both frequency and sophistication.</p><p>As the threat landscape evolves, MSPs that do not expand their security capabilities risk losing business to those that do, or to MSSPs that offer more comprehensive protection. While it is possible for an MSP to transition into an MSSP by enhancing its security offerings, such as adding antivirus, patch management, and web protection, delivering true, enterprise-grade cybersecurity requires specialized expertise, tools, and continuous monitoring that are the hallmark of an MSSP.</p><p>Many MSPs now partner with MSSPs to provide their clients with the best of both worlds: efficient IT management and advanced security. This dual approach ensures organizations can maintain operational efficiency while safeguarding their critical assets from ever-evolving threats.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>