Risk appetites have grown for 81% of CISOs

Netskope has published a new report analyzing the evolution of the CISO role within the retail sector. ‘The Retail CISO: Bringing Balance’, is based on research with over 1,000 CISOs globally, and it explores the evolution of the retail sector CISO role as a strategic member of the executive team, comparing the sector to cross-sector averages to identify unique insights.

  • Monday, 7th October 2024 Posted 1 year ago in by Phil Alsop

81% of retail CISOs say their appetite for risk has grown in recent years (much higher than the cross-sector average of 57%), but all (100%) believe conflicting risk appetites in the C-suite are a major issue.

Less than 2% of retail sector CISOs classify their risk appetite as low

However, nearly a quarter (23%) would describe their CEOs’ risk appetite as low

Retail CISOs see interactions with the C-suite and business as a constant balancing act, with 47% reporting that most interactions are about risk and 53% countering that most are about opportunity

An overwhelming majority (98%) of retail CISOs now consider themselves to be business enablers (well above the cross-sector average of 59%), and more than four-fifths (87%) want to play a more active role as a business enabler going forward (compared to an average of 67%). 86% of retail CISOs increasingly see their role as improving business resilience, not just managing cyber risk.

Retail CISOs are clear that they want to embrace more measured, centralized decision-making processes knowing the high levels of governance involved. This again contrasts with all other sectors who saw themselves moving the other way—drawn to a model described as “agile, fast decision-making with devolved responsibility”.

One of the pathways identified by retail CISOs for achieving the sometimes conflicting goals of the C-suite is adopting a zero trust approach. More than two-thirds (72%) believe zero trust will help them balance conflicting priorities better (higher than cross-sector averages of 55%), enable their organizations to move faster (77%) and encourage more innovation (71%).

Commenting on the findings, James Robinson, Chief Information Security Officer, Netskope said:

“Over the past decade, CISOs in the retail sector have transformed themselves, and their appetite for risk - along with their confidence in their ability to transform their organization - is marked. They have clearly identified that a zero trust approach holds advantages for their organizations, and are embracing it earlier than other industries - 71% already follow zero trust principles compared to sector averages of 44%.

However, in order to elevate their standing among their C-suite peers, CISOs will need to ensure their strategic discussions do not fall back into conversations about technology tools. Communication must focus on business enablement and business risk.”

Delinea will acquire StrongDM to extend its identity security capabilities for enterprises managing human and machine access.
GTT has updated its EnvisionDX platform with AI features and process improvements to support channel partners in configuring, quoting, and managing...
WatchGuard has launched Open MDR, expanding its managed detection and response service to support third-party security tools alongside its own...
Westcon-Comstor expands its relationship with Weblib, becoming the exclusive distributor of Weblib’s Smart Wifi solution on AWS Marketplace, aiming...
Mitel introduces a revised Global Partner Program to support partners with a unified structure and performance-based incentives amid evolving hybrid...
IBM introduces AI ready sovereign software designed to help organisations manage digital environments under evolving regulatory requirements.

WatchGuard expands Open MDR to support MSPs at scale

Posted 2 days ago by Sophie Milburn
WatchGuard Technologies expands its managed detection and response services with Open MDR, offering unified security coverage across multiple...
A new survey reveals the hidden costs of AI-generated outputs, suggesting that without proper infrastructure and training, productivity gains may...