Proofpoint’s CISO 2024 Report: Prime Challenges Embody Human Error & Threat – Uplaza

In Proofpoint’s 2024 Voice of the CISO report, the cybersecurity firm discovered that CISOs are coping with people-centric threats greater than ever. Plus, cybersecurity budgets typically don’t change, and AI may also help and harm CISOs’ efforts.

Relating to the precise menace dangers, 41% of the CISOs largely worry ransomware assaults, adopted by malware (38%), electronic mail fraud (36%), cloud account compromise (34%), insider menace (30%) and distributed denial of service (30%) assaults.

Greatest menace dangers as perceived by CISOs for the following 12 months. Picture: Proofpoint

For this report, the analysis agency Censuswide surveyed 1,600 CISOs from organizations of 1,000 workers or extra throughout totally different industries in 16 nations.

CISOs’ fundamental people-centric safety issues

Based on the survey, extra CISOs than ever consider human error is the most important vulnerability for his or her organizations; 74% of the CISOs really feel this manner, up from 60% in 2023.

Share of CISOs by nation who contemplate human error as their group’s greatest vulnerability. Picture: Proofpoint

As well as, 80% of CISOs see human danger as a key cybersecurity concern over the following two years, up from 63% in 2023. That is the place AI comes into play, as 87% of CISOs wish to deploy AI-powered applied sciences to combat human vulnerability and block human-centric cyber threats.

Regarding threats additionally embody malicious insiders (36%) and compromised insiders (33%).

DOWNLOAD: Safety Consciousness and Coaching Coverage from TechRepublic Premium

Information loss occasions and menace mitigation

Negligent or careless workers are seen as the most important trigger of knowledge loss occasions for CISOs (42%) over exterior assaults (40%). Based on the Proofpoint report, 73% of CISOs added their information loss occasions had been attributable to workers leaving their group.

Trigger of knowledge loss occasions, as reported by CISOs who handled a cloth lack of delicate data up to now 12 months. Picture: Proofpoint

The results of those information loss occasions are largely monetary loss (43%), post-attack restoration prices (41%) and lack of vital information (40%).

SEE: CISOs in Australia Urged to Take a Nearer Take a look at Information Breach Dangers

To combat the info loss drawback, many CISOs educate their workers about pc safety greatest practices (53%), use cloud safety options (52%), deploy information loss prevention expertise (51%), endpoint safety (49%), electronic mail safety (48%) or isolation expertise (42%).

This adoption of DLP has surged from 35% to 51% in a yr, with the end result being 81% of CISOs believing their information is nicely protected.

An rising variety of cybersecurity threats

Proofpoint said the assault floor of organizations has by no means been bigger for numerous causes, together with hybrid work has turn out to be a normal, whereas reliance on cloud expertise has grown. Additionally, workers have turn out to be more and more cell, typically taking information with them when altering jobs.

Seventy % of CISOs really feel their group will most likely face a cloth cyberattack over the following 12 months, with 31% pondering it is vitally probably. The CISOs from the U.S., Canada and South Korea are probably the most involved about experiencing such an assault.

Share of CISOs who really feel their group is susceptible to a cloth cyberattack within the subsequent 12 months. Picture: Proofpoint

Synthetic intelligence helps CISOs but in addition cybercriminals

As famous earlier, most CISOs surveyed wish to deploy AI-powered applied sciences to assist them defend their group, even when they’re nonetheless at an early stage. Proofpoint wrote, “Even in these early stages, we can already connect the dots between external threats, sensitive content and anomalous behaviors or activity. That’s something that has not been possible at the same speed and scale with human moderation or traditional analysis.”

SEE: Google Cloud’s Nick Godfrey Talks Safety, Finances and AI for CISOs

But AI additionally advantages cybercriminals, rendering their assaults simpler to scale, and strategies that had been solely deployed by nation-state menace actors or well-funded cybercriminal teams are actually accessible for lower-skilled attackers. Greater than half of the CISOs (54%) assume AI poses some type of safety danger to their group.

Stress about cybersecurity budgets

The economic system has had an affect on organizations, in line with 59% of the surveyed CISOs. Plus, CISOs are pressured to do extra or no less than the identical for much less, with safety budgets remaining flat at greatest. Forty-eight % of the CISOs have been requested to chop employees, delay backfills or scale back spending.

CISOs’ high precedence in line with their finances is now bettering data safety and enabling better enterprise innovation (58%) barely forward of bettering worker cybersecurity consciousness (54%).

Prime priorities for organizations’ IT groups over the following two years. Picture: Proofpoint

CISOs’ issues embody burnout and insurance coverage

Along with the budget-related stress, 66% of CISOs really feel expectations on them are unrealistic. This quantity is repeatedly rising (61% for 2023), as additionally they really feel their issues are unanswered. This all ends in low job satisfaction, with 53% of the CISOs experiencing or witnessing burnout up to now yr.

Sixty-six % of CISOs are additionally involved with private, monetary and authorized legal responsibility of their function, fearing an absence of safety of their job. And, 72% of CISOs wouldn’t be a part of a company that may not provide them administrators and officers insurance coverage or related safety within the occasion of a profitable cyberattack.

A vivid spot: CISOs’ relationships with board members

Eighty-four % of CISOs reported they’ve eye-to-eye contacts with their board members, whereas solely 51% reported such contact in 2022 and 62% in 2023. These contacts have led to a better understanding from the board members.

Disclosure: I work for Development Micro, however the views expressed on this article are mine.

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Exit mobile version