Security leaders fail to balance data security and business objectives

Only 14% of security & risk management (SRM) leaders can effectively secure organisational data assets while also enabling the use of data to achieve business objectives, according to a survey by Gartner, Inc.

  • Thursday, 13th February 2025 Posted 1 year ago in by Phil Alsop

While 35% of survey respondents secure data assets and 21% use data to achieve business goals, only one in seven can effectively do both.

The survey was conducted from June through August 2024 among 318 senior security leaders across organisations of different industries and sizes worldwide.

“With only 14% of SRM leaders able to secure their data while supporting business goals, many organisations can face increased vulnerability to cyber threats, regulatory penalties, and operational inefficiencies, ultimately risking their competitive edge and stakeholder trust,” said Nathan Parks, Sr Specialist, Research at Gartner.

Gartner recommends that SRM leaders take five actions to align business needs to data security and successfully achieve both data protection and business enablement goals.

1. Reduce governance-related friction for the business by using a well-established process to co-create data security polices and standards with end users and by inviting their feedback.

2. Align data-security-related governance efforts by partnering with other internal functions to identify overlaps and synergies.

3. Delineate non-negotiable security requirements that must be met by the business when handling previously unknown data security risks.

4. Define high-level guardrails around GenAI-related decisions (e.g., when to pause or stop a GenAI tool or feature) that allow for business experimentation within set parameters.

5. Work jointly with data and analytics (D&A) teams to secure top-down buy-in on data security initiatives.

Cautious steps: UK SMBs and AI adoption trends

Posted 7 hours ago by Sophie Milburn
IONOS report reveals UK SMBs weigh AI adoption amidst cost, time, and trust challenges, preferring investment in immediate returns.

Enhancing cybersecurity with active exploits protection

Posted 7 hours ago by Sophie Milburn
Proofpoint has introduced a solution aimed at addressing cyber threats accelerated by AI, with a focus on improving real-time threat detection and...
Nebula Global Services has appointed Scott Lynn as Global Services Director to support the development of its service organisation, enhance delivery...

Semperis announces new Chief Information Security Officer

Posted 8 hours ago by Sophie Milburn
Semperis has appointed John Podboy as Chief Information Security Officer (CISO) to support its cybersecurity strategy, including work involving...
Climb Channel Solutions enhances its cybersecurity portfolio through partnership expansion with Fortra, targeting the UK and Ireland markets.

Kiteworks OSPO: Strengthening open source under ownCloud

Posted 11 hours ago by Sophie Milburn
Kiteworks establishes an Open Source Program Office (OSPO) under the ownCloud brand to coordinate its open-source activities and governance.

CrowdStrike enhances partner engagement with new Jet app

Posted 11 hours ago by Sophie Milburn
Jet app enables partners to engage and expand through digital experiences, streamlining processes and enabling real-time rewards.
Robertet Group is advancing its global operations through GTT’s Secure Connect SASE, with the aim of improving cloud access and supporting...