CIOs and CSOs have a costly disconnect

When it comes to securing business-technology systems, CIOs face a challenge that won't go away.

The problem isn't necessarily new attack techniques, insecure software or even the latest government regulations. Rather, it's the challenge of seeing eye-to-eye with the CSO about how much security is enough.

The tenth annual Global Information Security Survey, conducted by PricewaterhouseCoopers and CIO's sister publication, CSO magazine, found that many of the 12,052 business and technology execs surveyed think that an overall lack of security leadership remains a serious obstacle to getting CIOs and CSOs on the same page, and others feel they lack an effective information security strategy.

Consider this: Only a third of respondents said security policies were tightly aligned with business goals, and 46 percent said they were only somewhat aligned.

With CIOs, business executives and IT security teams misaligned, it's next to impossible to build a consistent, sustainable security and risk management program that is capable of stopping the highly intelligent, motivated adversaries organizations face today.

This lack of cohesiveness between executive and security teams is also a large part of why so many believe that IT security gets insufficient capital and operating budget, says Jayson Street, CIO at Stratagem 1 Solutions, a security services provider.

"Much of this disconnect falls at the feet of the IT security profession," Street says. "It is IT security that, too often, is failing the business. We don't communicate risk well enough, and why the risk is worth mitigating."

Frank Cervone, vice chancellor for information services and CIO at Purdue University Calumet, says many security professionals focus more on specific risks and not on how those risks stack up against other pressing issues. "There is a difference in scope as to what the CIO has to look at as opposed to the CSO. The CSO doesn't always see the larger issues and needs to do a better job relating IT risks to overall business risk," says Cervone.

Mark Lobel, a principal in the advisory services division of PwC, agrees. "The business leaders have to manage what is burning, and rarely does security rise to be a pressing issue, unless a breach or something bad has just occurred," says Lobel. "It's hard to explain and quantify such an abstract risk to the business."

Lobel advises CIOs to work more closely with their security teams, and says that CSOs should link security needs to the overall direction and strategy of the business. For instance, if an important part of the business is Web applications, being able to keep those applications secure is key to the business's success.

Everyone interviewed encourages CIOs to focus on building out security programs based on measurable risks and outcomes. Too many organizations today are operating on gut instinct, our survey revealed.

The largest percentage of respondents (35 percent) measure the effectiveness of security spending by professional judgment, followed by reduced security incidents and breaches (29 percent), and total cost of ownership (24 percent). Less than a quarter of firms (24 percent) measure improvement against security metrics. One in five respondents do not know how the effectiveness of their IT security program is measured.

Those results are surprising, considering the substantial costs of security events when do they happen. Financial losses, according to our survey, average more than $1.6 million per incident.

Follow everything from CIO.com on Twitter @CIOonline, on Facebook, and on Google + .

Read more about security in CIO's Security Drilldown.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

IT Compliance Solutions

Enforce compliance consistently and cost-effectively across your organization.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.