Cisco 2019 CISO Benchmark Study Reports Increased Vendor Consolidation
Last Update: Monday, April 15, 2019 : 15:03 (+4GMT)
Survey of 3200 security leaders shows increased investment in defense technologies, security training, risk analysis and risk mitigation, as the unknown in users, data, devices, and apps are a major concern for CISOs
Dubai, UAE, April 15, 2019: Cisco recently published its annual CISO Benchmark Study. Now in its fifth year, the comprehensive global survey provides an annual health check on the state of the CISO for more than 3000 security leaders across 18 countries.
This year’s results show security professionals are placing higher priority on vendor consolidation, collaboration between networking and security teams, and security awareness exercises to strengthen an organizations security posture and reduce the risk of breaches. To further address complexity challenges, many CISOs are increasingly confident that migrating to the cloud will improve protection efforts.
Complex security environments made up of solutions from 10 or more security vendors could be hampering security professional’s visibility across their environments. Sixty-five percent of respondents do not find it easy to determine the scope of a compromise, contain it and remediate from exploits. The unknown threats that exist outside the enterprise in the form of users, data, devices, and apps is also a top concern for CISOs. To help address these challenges, and better protect their organizations, of those surveyed:
- Forty-four percent have increased investment in security defense technologies.
- Thirty-nine percent have security awareness training among employees.
- Thirty-nine percent focused on implementing risk mitigation techniques.
Survey respondents also noted the continued high financial impact of breaches. Forty-five percent of respondents reported the financial impact of a breach to their organization was more than $500,000. The good news is that more than 50 percent of respondents are driving breach costs below half a million. But there remains a stubborn eight percent claiming an eye-watering cost of more than $5 million per incident for their most significant breach of the past year.
“This year, more than ever before CISOs are reporting that they are taking a much more proactive role in reducing their exposure through consolidation and training, as well as investments in critical technologies, for cyber defense and breach containment, but the war is far from over,” said Fady Younes, Cybersecurity Director, Middle East & Africa. “Security leaders are still struggling to get greater visibility across their organization and into threats. You can’t protect what you can’t see. Cisco is committed to helping organizations address these challenges and implement new techniques and technology to stay one step ahead of malicious actors and threats.”
The following findings highlight some of the positive developments security professionals have made to improve their security posture:
- The trend away from point products to vendor consolidation continues— In 2017 54 percent of respondents cited 10 or fewer vendors in their environment. This number has risen to 63 percent.
- In many environments, multiple vendor solutions aren’t integrated, and therefore don’t share alert triage and prioritization. The survey showed that even those CISOs with fewer point solutions could better manage their alerts through an enterprise architecture approach.
- The most collaborative teams lose the least money. Elimination of silos shows a tangible financial upside:
- Ninety-five percent of security professionals reported that their networking and security teams were very or extremely collaborative.
- Fifty-nine percent of those who stated that their networking and security teams were very/extremely collaborative also stated that the financial impact from their most serious breach was under $100,000 – the lowest category of breach cost in the survey.
- There is more confidence in cloud-delivered security and in securing the cloud.
- Ninety-three percent of CISOs reported that migrating to the cloud increased efficiency and effectiveness for their teams.
- The perception of difficulty of protecting cloud infrastructure has decreased—52 percent in 2019 compared to 55 percent in 2017.
- “Cyber fatigue” – defined as virtually giving up on staying ahead of malicious threats and bad actors - is down from 46 percent in 2018 to 30 percent in 2019.
But the fight is far from over--the following findings show CISO challenges and opportunities for improvement:
- Employees/users continue to be one of the greatest protection challenges for many CISOs—having an organizational process that starts with security awareness training on day one is essential.
- Only 51 percent rate themselves as doing an excellent job of managing employee security via comprehensive onboarding and processes for transfers and departures.
- Email security remains the number one threat vector.
- Phishing and risky user behavior (e.g. clicking malicious links in email or websites) remains high and is the top concern for CISOs. The perception of this risk has held steady for the past three years between 56 to 57 percent of respondents. Coupled with low levels of security-related employee awareness programs, this represents a possible major gap that the security industry can help address.
- Alert management and remediation remains challenging. A reported drop in remediation of legitimate alerts, 50.5 percent in 2018 to 42.7 percent this year, is concerning given that many respondents are moving toward remediation as a key indicator of security effectiveness.
- Security measurements are changing. The number of respondents who use mean time to detection as a metric for security effectiveness decreased from 61 percent in 2018 to 51 percent in 2019 on average. Time to patch has also dropped in focus from 57 percent in 2018 to 40 percent in 2019. Time to remediate has risen as a success metric: 48 percent of respondents cited this compared to 30 percent in 2018.
Recommendations for CISOs:
- Base security budgeting on measured security outcomes with practical strategies coupled with cyber insurance and risk assessments to guide your procurement, strategy, and management decisions.
- There are proven processes that organizations can employ to reduce their exposure and extent of breaches. Prepare with drills; employ rigorous investigative methods; and know the most expedient methods of recovery.
- The only way to understand the underlying security needs of a business case is to collaborate across siloes – between IT, Networking, Security and Risk/Compliance groups.
- Orchestrate response to incidents across disparate tools to move from detection to response faster and with less manual coordination.
- Combine threat detection with access protection to address insider threat and align with a program like Zero Trust.
- Address the number one threat vector with phishing training, multi-factor authentication, advanced spam filtering and DMARC to defend against Business Email Compromise.
Previous Article
The UAE's Minister of Economy Welcomes Italy's Deputy Prime Minis...
Next Article
Afghanistan Opens New Mining Areas to International Investment
Most Viewed – Last 30 Days
- Bridal Season Is Officialy Open with Benefit Cosmetics!... [2487-Views]
- Dubai Summer Surprises 2026 Unveils an Action-Packed Calendar of Shopping, Din... [2038-Views]
- Joyalukkas Strengthens US Footprint with 8th Showroom in Iselin, New Jersey... [2030-Views]
- Mercato Takes Media on a Magical Summer Journey with The Grand Comedy Circus a... [1602-Views]
- Group-IB launches Purple Teaming service to close the gap between security inv... [1230-Views]
- First winner of 'Win Your Home in Dubai' initiative announced as citywide home... [1133-Views]
- Dubai Gears Up for a Spectacular Start to 29th Dubai Summer Surprises with Liv... [1107-Views]
- Government of Fujairah Signs Agreement to Purchase Gasoline Production from Et... [960-Views]
- Global Talent Attraction and Retention Committee Convenes Tenth Meeting to Rev... [925-Views]
- MAIR Group and Makani Real Estate Announce Mall of Al Ain Redevelopment and Ex... [905-Views]
- Schneider Electric joins the World Economic Forum Lighthouse Operating System ... [896-Views]
- EGA wins the AI Vision and Strategy Award at the 2026 Manufacturing Leadership... [889-Views]
- EGA inaugurates UAE's largest aluminium recycling plant... [833-Views]
- Kia introduces PV5 as its first Platform Beyond Vehicle (PBV) model in Middle ... [827-Views]
- G-SHOCK MTG-B4000BD-1A: A New Language of Structural Beauty... [822-Views]
- The New SHEGLAM Lashlighter Root-Up Lash Primer Gets to the Root of the Matter... [811-Views]
- Dubai Summer Surprises: Shop, Save, and Win as the Great Dubai Summer Sale Arr... [808-Views]
- Dubai Municipality and Enviroserve sign strategic agreement to enhance e-waste... [773-Views]
- Dubai Municipality tours first vertical farm inside residential tower in Al Ha... [765-Views]
- Spain Defeats Argentina to Claim Second FIFA World Cup Title... [760-Views]





