Why Cybersecurity Breaches Persist: A Call for Cultural and Structural Changes in Organizations
It may be a bold statement to assert that security threats are here to stay, and only well-prepared organizations will avert the onslaught of threats against their infrastructure. The news media is awash with constant reports of security breaches at organizations of varying sizes. One would expect better protection mechanisms against cyber threats in well-established organizations, but that is often not the case. This outcome raises a critical question: "Why do organizations fail to implement adequate security measures?"
The answer can be both straightforward and complicated, depending on the complexity of the organization's infrastructure. The complexity may not necessarily be a security problem but an after-effect of processes that do not adhere to best practices or align with security principles. It is paramount that organizations ensure alignment between their business operations and security solutions to avoid vulnerabilities. Security breaches often occur when business processes inadvertently introduce vulnerabilities against the backdrop of security recommendations to meet business objectives. These breaches may make the security team appear inefficient, but they usually stem from a misalignment between business and security objectives.
Business leaders often prioritize maximizing profit and may rationalize or override security recommendations in the name of business interests. Indeed, some organizations have successfully positioned security leaders at the executive management level, such as Chief Information Security Officers (CISOs). However, these security leaders need adequate empowerment to have a voice in decisions that could prevent security breaches. In cases where the CISO reports exclusively to a Chief Information Officer (CIO), who has other business priorities, some security recommendations or critical issues may go unreported to the board. In the worst scenarios, security leaders may be dealing with some harmful practices of some executive leaders who themselves cause security breaches.
Top leadership must be seen as champions of the change they want to see in their organization. Otherwise, the change initiative is doomed to fail. Championing change includes ensuring the board has visibility into all aspects of security to support such initiatives. Such visibility will ensure enforcement across all strata of the organization. After all, the buck should not stop at the desk of the Chief Executive Officer (CEO); it must stop at the board's desk. Security leaders should have a direct reporting line to the board, or at the very least, organizational culture should embrace transparent reporting that holds everyone accountable, regardless of position.
The core message is that security breaches should not be assessed solely from the perspective of technical implementations, although they play a significant role. Organizations must continue to evaluate their internal culture and adherence to security principles and best practices. Business leaders should not shun security best practices for overarching business interests. Without threats of reprisal, security leaders should be able to advise on the ramifications of the organization's decisions and ensure they reach board leadership when necessary.
The board has a fiduciary responsibility to play an active role in security, making it a core function of their duties, especially considering today's rising cyber threats. It is not out of place for the board to demand visibility into organizational decisions that could impact the business. The saying that we are all responsible for security must be enshrined in practices at all levels of the organization. Until this is achieved, security breaches will persist due to human errors.