Security leaders fail to balance data security and business objectives

Only 14% of security & risk management (SRM) leaders can effectively secure organisational data assets while also enabling the use of data to achieve business objectives, according to a survey by Gartner, Inc.

  • Thursday, 13th February 2025 Posted 1 year ago in by Phil Alsop

While 35% of survey respondents secure data assets and 21% use data to achieve business goals, only one in seven can effectively do both.

The survey was conducted from June through August 2024 among 318 senior security leaders across organisations of different industries and sizes worldwide.

“With only 14% of SRM leaders able to secure their data while supporting business goals, many organisations can face increased vulnerability to cyber threats, regulatory penalties, and operational inefficiencies, ultimately risking their competitive edge and stakeholder trust,” said Nathan Parks, Sr Specialist, Research at Gartner.

Gartner recommends that SRM leaders take five actions to align business needs to data security and successfully achieve both data protection and business enablement goals.

1. Reduce governance-related friction for the business by using a well-established process to co-create data security polices and standards with end users and by inviting their feedback.

2. Align data-security-related governance efforts by partnering with other internal functions to identify overlaps and synergies.

3. Delineate non-negotiable security requirements that must be met by the business when handling previously unknown data security risks.

4. Define high-level guardrails around GenAI-related decisions (e.g., when to pause or stop a GenAI tool or feature) that allow for business experimentation within set parameters.

5. Work jointly with data and analytics (D&A) teams to secure top-down buy-in on data security initiatives.

A recent global study explores the role of trust in cybersecurity and its influence on risk and decision-making, highlighting key challenges...

Decoding the accelerated cyber attack cycle

Posted 8 hours ago by Sophie Milburn
Rapid7's latest report highlights the shrinking timelines in cyber threat landscapes and underscores the urgency of effective cyber-resilience...

Flare launches Foretrace for employee identity protection

Posted 8 hours ago by Sophie Milburn
Flare introduces Foretrace, providing employees with tools to help monitor and address personal identity risks within the enterprise environment.

Inside the Race: Insights from Pax8’s Mission Briefing

Posted 12 hours ago by Sophie Milburn
From Red Bull Racing HQ, Pax8’s Mission Briefing explored a channel under pressure, where rising complexity and the rapid growth of AI are...
Docusign has updated its Intelligent Agreement Management platform in the UK, adding new features for contract preparation, processing, and...

Empowering AI with secure identity control

Posted 4 days ago by Sophie Milburn
Ping Identity introduces “Identity for AI,” extending identity and access control to autonomous enterprise agents with real-time enforcement and...

Huntress extends ITDR solution to Google Workspace

Posted 6 days ago by Sophie Milburn
Huntress expands its Managed ITDR coverage to Google Workspace, providing organisations with enhanced detection and response for identity-based...
DigiCert updates its Document Trust Manager to support document security and global compliance as digital document use and AI-related risks increase.