Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Telkom warns Icasa call rate cuts will punish smaller players

      13 June 2024

      MultiChoice will ride out Nigeria chaos

      13 June 2024

      Showmax reports R2.6-billion in trading losses

      13 June 2024

      Big section of 2Africa subsea cable is now live

      12 June 2024

      MultiChoice sheds 9% of its subscriber base in 12 months

      12 June 2024
    • World

      SpaceX sued by engineers fired after accusing Elon Musk of sexism

      13 June 2024

      Elon Musk withdraws lawsuit against OpenAI

      12 June 2024

      Investors cheer Apple AI strategy

      12 June 2024

      High-fidelity audio is finally coming to Spotify

      11 June 2024

      Musk threatens to ban Apple devices over OpenAI integration

      11 June 2024
    • In-depth

      It’s Jensen’s world now

      6 June 2024

      From Talkomatic to WhatsApp: the incredible history of instant messaging

      28 May 2024

      The 20 most influential tech products of all time

      22 May 2024

      Early signs that AI is fuelling a productivity boom

      21 May 2024

      GPT-4o is a stunning leap forward in AI

      18 May 2024
    • TCS

      TCS+ | Telco or ISP? Tired of load shedding chaos? This is for you

      13 June 2024

      TCS+ | Check Point dissects the complexities of cloud security

      11 June 2024

      TCS | MultiChoice declares war on piracy – the man leading the fight

      10 June 2024

      TCS+ | ESET’s Adrian Stanford: how AI will transform cybersecurity

      10 June 2024

      TCS+ | Pinnacle CEO on how AI is going to transform SA business

      6 June 2024
    • Opinion

      Lessons from healthcare for navigating South Africa’s energy crisis

      12 June 2024

      How to maximise solar panel performance in winter

      11 June 2024

      Corrupt municipalities crushing affordable connectivity in South Africa

      4 June 2024

      Post Office debacle shows ANC is out of ideas

      28 May 2024

      Should the SABC have discretion to reject a political ad?

      19 May 2024
    • Company Hubs
      • 4IRI
      • Africa Data Centres
      • Altron Document Solutions
      • Altron Systems Integration
      • Arctic Wolf
      • AvertITD
      • CallMiner
      • Calybre
      • CoCre8
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • E4
      • Entelect
      • ESET
      • Euphoria Telecom
      • iKhokha
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LG Electronics
      • LSD Open
      • Maxtec
      • MiRO
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paratus
      • Ricoh
      • Skybox Security
      • SkyWire
      • Velocity Group
      • Vertiv
      • Videri Digital
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » Boost security maturity: bridge disconnects between execs, infosec specialists

    Boost security maturity: bridge disconnects between execs, infosec specialists

    Promoted | Disconnects between business executives and technical information security teams must be overcome to advance security maturity within organisations.
    By Solid8 Technologies23 June 2023
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp
    Skybox Security’s Justin Berman

    Disconnects between business executives and technical information security teams must be overcome to advance security maturity within organisations.

    This is according to Justin Berman, technical director for Skybox Security, who says many South African organisations are stuck in early levels of security maturity, which hampers their ability to optimise their security posture and properly support digital transformation of the business.

    Berman explains that the earliest stage of security maturity is an ad hoc approach, followed by a “developing” phase in which organisations have an active cybersecurity programme; then a “defined” phase in which programmes and processes have been defined; and a “managed” phase in which programmes and policies are well established. At the highest level, organisations are in the “optimising” phase, in which they have a holistic view of the attack surface, tight integration between IT and security, and are continually improving the environment.

    Disconnected goals and requirements

    To move beyond the early stages of security, organisations must address the disconnects between executives and technical stakeholders, he says. Berman notes that all stakeholders – from the C-suite through to security architects, NOC and SOC engineers, security architects, and IT operations – have the same goals of mitigating risk for organisational growth. However, the tools, data and dashboards they need to achieve this is different for each stakeholder.

    Questions about Skybox Security? Please e-mail [email protected]

    “The CISO, CIO and CTO need to align security with business objectives. They need quantifiable measurements of cyber risk and the outcomes of actions and programmes that address that risk. Security architects are also strategic thinkers – they must de-risk digital transformation and glue all the components together. They need a holistic view of the environment, risk and business requirements,” Berman says. “Meanwhile, the engineers and NOC and SOC analysts are focused on monitoring and managing critical infrastructure to support the business and enable availability, scale and performance. They need data that drives security efficacy and performance, resiliency and compliance. Finally, risk and compliance teams need reports that provide risk oversight around compliance, policies and enforcement, to prove they are compliant. They all need different information.”

    According to Heidrick & Struggles, only around 12% of CISOs were on corporate boards in 2021

    Meeting these needs in an increasingly complex environment can be challenging, Berman says. “There are communication gaps across business units and even within departments – for example, CIOs and CTOs may have the same objectives but different views and requirements for security, while the board sees security as priority, but is focused on finance and strategy. If a disconnect continues, security will be driven from the bottom up and not as a top-down approach, and as time moves on, security will fail to support the organisation’s strategic direction.”

    While CISOs are considered C-level executives, many tend to play an advisory role and do not sit on the board, he adds. “The CISO role is evolving, but while they drive strategy, they may not be the key decision maker on budget, tooling and engineering,” Berman says.

    According to executive search firm Heidrick & Struggles, only around 12% of CISOs were on corporate boards in 2021.

    People, process and technology for progress

    Berman says organisations must overcome disconnects and advance their security maturity by addressing people, processes and technology. “They need to automate menial tasks and free engineers to work on more meaningful and strategic projects. They also need to empower stakeholders with alerts, dashboards and reports that are timeous, actionable, intelligent and concise.

    “Processes also need to be improved across identification, prioritisation, remediation and oversight,” he says. “In South Africa, many organisations are stuck at identification level. We must put the right processes and workflows in place so that strategic and technical people get what they need, when they need it.”

    They need to automate menial tasks and free engineers to work on more meaningful and strategic projects

    Berman says the right technology helps overcome disconnects and ensure that all stakeholders have the information they need to improve security and compliance and better support the business. “Skybox consolidates the data and gives the right insights to the right people when they need it. It consolidates and aggregates many datasets across complex environments. It allows them to dynamically model the environment to visualise and assess the efficacy of security controls, gives context to help them understand exposure, prioritise vulnerabilities and determine optimal remediation strategies. It also helps them plan and analyse the impact of changes across the hybrid environment,” he says.

    “When executives and technical teams have the tools and information they need, and management is incentivised to drive security strategies, you see massive improvements in security,” Berman says.

    To learn more about Skybox Security, please e-mail [email protected].

    • Read more articles by Solid8 Technologies on TechCentral
    • Read more articles by Skybox Security on TechCentral
    • This promoted content was paid for by the party concerned
    Heidrick & Struggles Justin Berman Skybox Skybox Security Solid8 Solid8 Technologies
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleRMB: SA e-commerce to match developed world by 2026
    Next Article Larry Ellison scores big by cashing in expiring options

    Related Posts

    Telkom warns Icasa call rate cuts will punish smaller players

    13 June 2024

    MultiChoice will ride out Nigeria chaos

    13 June 2024

    TCS+ | Telco or ISP? Tired of load shedding chaos? This is for you

    13 June 2024
    Add A Comment

    Comments are closed.

    Company News

    How to harness customer insights in the age of information overload

    13 June 2024

    How LayUp is advancing lay-by payments in Africa

    12 June 2024

    Recapping an extraordinary month at Next DLP

    12 June 2024
    Opinion

    Lessons from healthcare for navigating South Africa’s energy crisis

    12 June 2024

    How to maximise solar panel performance in winter

    11 June 2024

    Corrupt municipalities crushing affordable connectivity in South Africa

    4 June 2024

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2024 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.