The bold decisions CISOs need to make today

Issue 6 2021 Information Security

This is a rare opportunity to drive an agenda that puts security at the heart of every future step. And we know that business leaders are receptive: security has shot up the boardroom agenda with 58% of business leaders noting improving data and network security as the issue of most importance to the organisation over the past year. More than ever, CISOs (chief information security officers) are getting involved in decision-making from the outset – and they need to be ready to lead from the front.

Organisations are changing how they operate as they begin to get a clearer vision as to what the future of work looks like.


Kevin Brown.

We’re entering the era of hybrid working, where some employees remain homeworkers, others return to the office full time and a large part of the workforce splits their time between the two. Organisations that want to win people back to the office need to pay close attention to their users’ experience – why should they stop working from home where they’ve got a steady supply of the coffee of their choice, a comfy sofa for breaks and a good broadband connection? Offices need to play connectivity catch-up if they’re to supply the seamless experience expected for effective collaboration and productivity.

This is an opportunity for organisations to baseline what they have and clear out the skeletons from the closets. It’s not often leaders get the freedom to fundamentally rethink how their business operates. This is a chance to be bold about the infrastructure plans and security investments, to put the organisation in the best possible place to capitalise on growth and tackle any future challenges.

Standing firm against a growing threat landscape

As well as preparing for the future of work, organisations are recognising that the threat landscape is escalating in an ominous way and are looking to do something about it. In recent research we conducted with over 7000 business executives, employees and consumers, 75% of executives said there are more security threats to their organisations every year. So, leaders know they have to be able to react quickly to threats, whilst also building flexibility and elasticity into their infrastructure to see them through at least the next three to four years. And it makes sense to incorporate security from the beginning.

Operating during the pandemic has given organisations renewed confidence that they can make changes at pace, supported by the rise of cloud providers. They’ve realised that agile development is a strong alternative to more traditional and slower waterfall iterative transformation and they’re seizing the moment.

This is a critical time to rethink how the organisation operates, how leaders want their employees to work and what they need from their connectivity and security.

Missing this golden opportunity has consequences

I believe that organisations that don’t make strong moves with their security now risk being left behind. It’ll be a lost opportunity to really capitalise on market growth. Users are becoming increasingly dissatisfied with their connectivity and this affects operational efficiency. And as the threat landscape expands, if organisations don’t make rapid changes to their security, their vulnerability to cyber-attacks will increase.

Some organisations will be more at risk than others. For instance, a cloud-native organisation is likely already in good shape. But those organisations that evolve their infrastructure and security slowly, tend to have to bolt on security, incurring greater costs in the long run. Ironically, being adventurous and strategic in the first instance can save the organisation money.

The bold decisions to take today

So, where to start? Well, above all I believe CISOs should be ambitious in their decisions and below I’ve outlined my suggested focus areas.

1. Put customers and users at the heart of security plans

Explore what will enable them to work in the most productive and secure way, without security causing friction. The idea is to deliver a seamless user experience with invisible security.

2. Make sure security is embedded in all plans

So many organisations today have a lot of different point solutions, but no overarching strategy. Thinking boldly now could protect the organisation against an escalating threat landscape.

3. Ensure the business has visibility and control

Data is increasingly flowing in ways that don’t involve the enterprise network, widening the organisation’s risks and decreasing its control. Threat actors are alert to the possibilities these potential new weaknesses bring, so it’s vital to have end-to-end visibility, from the user/device to the application/data.

4. Embrace automation

Think about how automation can be used as a cost-effective way to take the pressure off security teams so that they can focus on what’s critical.

5. Look for security partners that can help achieve the business aims

Be clear-sighted about what a co-managed security model could provide and how it could be used to stay ahead of threats. Although organisations can be reluctant to outsource completely, working with a partner on a co-management approach is an effective way to fill any expertise gaps.

Get involved in early strategy

Traditionally, the CISO hasn’t always been involved in shaping the strategy. However, right now, when security is at the top of the boardroom agenda, CISOs need to be at the heart of decision-making, shaping and driving a security policy that will protect the organisation as it emerges from the pandemic.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.