The red lights are flashing everywhere. News stories are warning about a sharp rise in ransomware attacks, a 2000X fold increase in cybersecurity breaches, and more cyber-related doomsday scenarios. Meanwhile, the Biden Administration released a much-anticipated cybersecurity plan earlier this year, calling for more investments in cybersecurity.
With new threats circling and the president’s call for additional cybersecurity resources, one would think that cybersecurity funding has increased across the board. Think again. According to McKinsey, more than 70% of CISOs and security buyers anticipated their budgets shrinking last year -- and this is during the pandemic.
Clearly, many executives still do not understand the importance of cyber risk management. It’s almost as if we need a “cybersecurity for executives” 101 course. In absence of that, let’s talk about why it’s still so difficult for some C-level executives to embrace the need for a better cybersecurity posture.
Misunderstanding how cybersecurity impacts performance
One possible explanation is that, in light of the recent difficult economic environment, corporate executives and board members are closely examining their organizations’ finances. As such, they’re likely to make cuts in areas that don’t appear to directly affect revenue. On the surface, it may appear to them that cybersecurity doesn’t directly correlate with a company’s bottom line.
Of course, that’s not true. Just ask organizations like Capital One, which had to pay $80 million to settle claims related to its cybersecurity breach. In addition to being costly, cyberattacks can cause irreparable damage to a company’s reputation.
But unless it’s explained in terms they understand or care about, it’s often hard for senior executives to directly tie risk into corporate performance. They don’t want to hear about how many potential intrusions a firewall prevented over the past six months, for instance. They want to know, how would those intrusions have impacted the business if successful? How much data would we have lost? And how does that translate into company performance and loss of revenue?