Security

Research

Meatbag mishaps more menacing than malware? CISOs think so

Company boards, on the other hand, aren't letting cybersecurity disturb their sleep as much


Chief information security officers (or CISOs) see human error as the most significant risk to data protection compared to other UK board directors.

Meatbag errors are keeping CISOs awake at night, according to Proofpoint, which has just released a "Cybersecurity: The 2023 Board Perspective" report. The organization told The Reg that 78 percent had tapped it as the most significant risk. Only 56 percent of UK board directors felt the same way, said the analysts.

However, while nearly three-quarters (73 percent) of CISOs were confident in their organization's ability to protect data, just over half (56 percent) of directors agreed.

Overall, the confidence of UK board members has improved year over year, according to data included in the report. In 2022, more than three-quarters (76 percent) reckoned their organization was at risk of a cyber-attack. By 2023, less than half (44 percent) were as worried. Global board members, however, remained jittery – researchers found 73 percent felt at risk of cyber-attack.

The confidence of UK boards was in marked contrast to other countries. In 2022, 50 percent of board members in Canada felt at risk of a cyber-attack. The figure rose to 95 percent in 2023. The global average for the board was 73 percent in 2023.

Other gaps in perception included worries about personal liability – a whopping 79 percent of UK CISOs were concerned about their liability in the event of a cybersecurity incident, while the board was more blasé; just over half (54 percent) of directors expressed similar concern.

There were also differences in where UK CISOs and board members felt the biggest risks lay. Board members listed malware, cloud account compromise, and ransomware as the biggest worries. CISO concerns were email fraud, insider threats, and phishing. CISOs also listed cloud account compromise, indicating the two may not be so far apart.

Finally, the specter of AI was found to be haunting UK boards as 41 percent of directors viewed emerging technology such as ChatGPT as a security risk.

Researchers surveyed 659 board members from 12 countries – the US, Canada, the UK, France, Germany, Italy, Spain, Australia, Singapore, Japan, Brazil, and Mexico. While globally it was noted that CISOs and board members were relatively aligned, the UK still has work to do.

Ryan Kalember, executive vice president of cybersecurity strategy at Proofpoint, said: "Growing even stronger board-CISO relationships – particularly in the UK, where our data shows the need for significant improvement in this area – will be instrumental in the months ahead for directors and security leaders."

Kalember is correct. The report showed a marked decline in interaction between the board and cybersecurity leadership in the UK, dropping from 55 percent of directors saying they had regular chats in 2022 to 43 percent in 2023.

Andrew Rose, Resident CISO, EMEA at Proofpoint, said: "UK board members should keep in mind that the risk of material cyber-attacks are still very real and threats will continue to evolve."

Rose went on to emphasize the importance of board-CISO partnerships and warned against complacency. He said: "Boards must continue to invest heavily in improving preparedness and organisational resilience." ®

Send us news
6 Comments

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

UK and US lead international efforts to raise AI security standards

17 countries agree to adopt vision for artificial intelligence security as fears mount over pace of development

EU lawmakers finalize cyber security rules that panicked open source devs

PLUS: Montana TikTok ban ruled unconstitutional; Dollar Tree employee data stolen; critical vulnerabilities

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

AlphV lays claims to the intrusion

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

BlackCat ransomware crims threaten to directly extort victim's customers

Accounting software firm Tipalti says it’s investigating alleged break-in of its systems

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

23andMe responds to breach with new suit-limiting user terms

Also: 'well-known Bay Area tech' firm's laptops stolen and check out some critical vulns

Yet another UK public sector data blab, this time info of pregnant women, cancer patients

NHS Trust admits highly sensitive data left online for nearly three years

Memory-safe languages so hot right now, agrees Lazarus Group as it slings DLang malware

Latest offensive cyber group to switch to atypical programming for payloads

UK government denies China/Russia nuke plant hack claim

Report suggests Sellafield compromised since 2015, response seems worryingly ignorant of Stuxnet

Today's 'China is misbehaving online' allegations come from Google, Meta

Zuck boots propagandists, Big G finds surge of action directed at Taiwan