December 27, 2016 By Rick M Robinson 2 min read

Cybersecurity leadership begins at the top, with the chief information officer (CIO) and chief information security officer (CISO). That is the simple part. While leadership is never easy, it is fairly uncomplicated to grasp nonetheless.

The complicated part of IT leadership is understanding the security threats that organizations face and where they come from. Leading means setting an example, but of what and to whom?

In the connected ecosystem of the IT world, third-party risks are growing. Given the popularity of cloud and mobile apps and the emergence of the Internet of Things (IoT), organizations are navigating a sea of relations with external entities. That means dealing with the vulnerabilities and risks of interconnectivity.

Cybersecurity Leadership Lags

As CIO Insight reported, IT professionals are aware of these third-party risks, but organizations are lagging in holding leaders responsible for managing these risks. Three-quarters of respondents to a Ponemon Institute survey, “Tone at the Top and Third-Party Risk,” agreed that third-party risk was a serious concern, and 70 percent said they believed the risk was growing.

Another three-fifths of respondents named the IoT as a growing source of third-party risk, while 68 percent cited cloud migration. Assessment of significant risk, as opposed to growing risk, found a similar pattern. More than two-thirds of respondents identified cloud computing and mobility as significant threats, and more than three-quarters tagged the IoT as such. Just over half placed big data analytics in this category.

Despite these worries, third-party risk is not often a prime focus of risk management strategies. These are typically directed at minimizing downtime and business disruptions. Only 29 percent of survey respondents said their organizations had a formal third-party risk management program.

Managing Third-Party Risks

In short, cybersecurity leadership is lagging when it comes to third-party risks, even though the risks themselves are growing. Only 37 percent of respondents were confident that the C-suite understood its ultimate responsibility for managing third-party risks, while half felt that risk management was not aligned with enterprise goals. Confidence in the board of directors is also low, according to the survey.

The risks, however, are very big and very real. On average, respondents reported having spent $10 million in the past year in responding to “security incidents because of negligent or malicious third parties.”

For CIOs and CISOs, the message is clear: Someone needs to push the enterprise’s top leadership toward awareness of — and effective responses to — third-party risks. The CIO and CISO are best positioned to advocate for this strategy.

Organizations and their IT networks are interconnected to a degree that makes security a shared responsibility. A positive tone at the top can help organizations avoid working with untrustworthy third parties and build the ethical partner relationships in which responsibility for cybersecurity leadership is shared, productive and effective.

More from CISO

CISO vs. CEO: Making a case for cybersecurity investments

4 min read - Ask CISOs why they think there is a cyber skills shortage in their organization, what keeps them up at night or what the most important issue facing the industry is — at some point, even if not the first response, they will bring up budgets.For example, at RSA Conference 2024, a roundtable discussion about issues facing the cybersecurity industry, one CISO stated bluntly that budgets — or lack thereof — are the biggest problem. At a time when everything is…

Making smart cybersecurity spending decisions in 2025

4 min read - December is a month of numbers, from holiday countdowns to RSVPs for parties. But for business leaders, the most important numbers this month are the budget numbers for 2025. With cybersecurity a top focus for many businesses in 2025, it is likely to be a top-line item on many budgets heading into the New Year.Gartner expects that cybersecurity spending is expected to increase 15% in 2025, from $183.9 billion to $212 billion. Security services lead the way for the segment…

On holiday: Most important policies for reduced staff

4 min read - On Christmas Eve, 2023, the Ohio State Lottery had to shut down some of its systems because of a cyberattack. Around the same time, the Dark Web had a “Leaksmas” event, where cyber criminals shared stolen information for free as a holiday gift. In fact, the month of December 2023 saw more than 2 billion records breached and 1,351 disclosed security incidents, according to research from IT Governance — an increase of 332% and 187%, respectively, over the month of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today