Security leaders fail to balance data security and business objectives

Only 14% of security & risk management (SRM) leaders can effectively secure organisational data assets while also enabling the use of data to achieve business objectives, according to a survey by Gartner, Inc.

  • Thursday, 13th February 2025 Posted 10 months ago in by Phil Alsop

While 35% of survey respondents secure data assets and 21% use data to achieve business goals, only one in seven can effectively do both.

The survey was conducted from June through August 2024 among 318 senior security leaders across organisations of different industries and sizes worldwide.

“With only 14% of SRM leaders able to secure their data while supporting business goals, many organisations can face increased vulnerability to cyber threats, regulatory penalties, and operational inefficiencies, ultimately risking their competitive edge and stakeholder trust,” said Nathan Parks, Sr Specialist, Research at Gartner.

Gartner recommends that SRM leaders take five actions to align business needs to data security and successfully achieve both data protection and business enablement goals.

1. Reduce governance-related friction for the business by using a well-established process to co-create data security polices and standards with end users and by inviting their feedback.

2. Align data-security-related governance efforts by partnering with other internal functions to identify overlaps and synergies.

3. Delineate non-negotiable security requirements that must be met by the business when handling previously unknown data security risks.

4. Define high-level guardrails around GenAI-related decisions (e.g., when to pause or stop a GenAI tool or feature) that allow for business experimentation within set parameters.

5. Work jointly with data and analytics (D&A) teams to secure top-down buy-in on data security initiatives.

Commvault partners with Delinea and Pinecone to enhance security and resilience for enterprises, centralising credential management and safeguarding...
New research highlights executive priorities amidst evolving pressures, showcasing the pivotal role of AI and automation within contemporary business...

Accelerating the next wave of AI-driven cybersecurity

Posted 1 day ago by Sophie Milburn
CrowdStrike, AWS, and NVIDIA join forces to fuel innovation in AI-driven cloud security.

Identity security meets real-time threat response

Posted 2 weeks ago by Sophie Milburn
SailPoint announces new integrations with CrowdStrike to bolster identity-based threat response, advancing security operations and decision-making...

Small businesses face rising cybersecurity attacks

Posted 2 weeks ago by Sophie Milburn
Nearly half of US SMBs faced cyberattacks, yet many remain underprepared and reliant on untrained staff for security, Guardz study finds.
TCS strengthens its alliance with Aviva by expanding its policy administration services, embracing advanced digital solutions for customer-focused...
Hammer teams up with Nexsan to offer storage solutions across EMEA, enhancing modern data management capabilities.

Nordic security expertise expands in Europe

Posted 2 weeks ago by Sophie Milburn
MetaCompliance expands its foothold in Europe by acquiring Nordic leader Junglemap, enhancing its capacity to offer advanced security and compliance...