• bitcoinBitcoin(BTC)$84,427.001.20%
  • ethereumEthereum(ETH)$2,715.592.77%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$778.641.10%
  • rippleXRP(XRP)$1.629.90%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$120.736.52%
  • tronTRON(TRX)$0.336937-0.89%
  • zcashZcash(ZEC)$1,584.237.16%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.82%
  • HyperliquidHyperliquid(HYPE)$93.212.29%
  • dogecoinDogecoin(DOGE)$0.0985236.68%
  • moneroMonero(XMR)$562.843.53%
  • chainlinkChainlink(LINK)$14.0414.55%
  • whitebitWhiteBIT Coin(WBT)$84.281.04%
  • USDSUSDS(USDS)$1.00-0.01%
  • cardanoCardano(ADA)$0.2571099.20%
  • RainRain(RAIN)$0.011879-0.95%
  • leo-tokenLEO Token(LEO)$8.83-0.91%
  • stellarStellar(XLM)$0.22387212.05%
  • bitcoin-cashBitcoin Cash(BCH)$335.880.29%
  • nearNEAR Protocol(NEAR)$5.0716.09%
  • uniswapUniswap(UNI)$9.839.48%
  • litecoinLitecoin(LTC)$69.915.82%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • CantonCanton(CC)$0.12275914.71%
  • avalanche-2Avalanche(AVAX)$10.585.55%
  • suiSui(SUI)$1.1419.98%
  • daiDai(DAI)$1.000.00%
  • USD1USD1(USD1)$1.000.02%
  • hedera-hashgraphHedera(HBAR)$0.0957656.39%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.432.15%
  • BittensorBittensor(TAO)$307.5510.17%
  • shiba-inuShiba Inu(SHIB)$0.0000065.50%
  • crypto-com-chainCronos(CRO)$0.0655358.19%
  • Global DollarGlobal Dollar(USDG)$1.000.02%
  • BitwayBitway(BTW)$1.128.30%
  • MemeCoreMemeCore(M)$1.20-2.02%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • tether-goldTether Gold(XAUT)$4,295.740.53%
  • OndoOndo(ONDO)$0.5520.29%
  • okbOKB(OKB)$120.832.45%
  • EthenaEthena(ENA)$0.24375318.13%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • aaveAave(AAVE)$148.718.58%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.09%
  • mantleMantle(MNT)$0.680.60%
  • polkadotPolkadot(DOT)$1.207.83%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

The modern CISO: Scapegoat or value creator?

May 25, 2024
in AI & Technology
Reading Time: 5 mins read
A A
The modern CISO: Scapegoat or value creator?
ShareShareShareShareShare

Join us in returning to NYC on June 5th to collaborate with executive leaders in exploring comprehensive methods for auditing AI models regarding bias, performance, and ethical compliance across diverse organizations. Find out how you can attend here.


2024 is already shaping up to be one of the most stressful years yet for CISOs. They are trying to defend their organizations against a growing number of threats as they increase in speed and complexity, fueled by emerging technologies like generative AI. It doesn’t help that cyber budgets are shrinking and CISOs can now be held personally liable for a breach, as was seen by the precedent-setting verdict against the former Uber CISO. 

YOU MAY ALSO LIKE

Google Adds Creepy Avatars To Gemini 3.8 Live’s Agents

Fastino Releases GLiNER2.5-Decide: A 340M Open-Weight Decision Model That Runs on CPU

To top it up, 61% of CISOs feel unprepared for a cyber-attack and 68% feel that their organization is at risk of an attack, according to Proofpoint. It’s no wonder that the modern CISO often feels like the scapegoat, with odds stacked against them.

In working with hundreds of CISOs across leading Fortune 100 companies globally, I understand their biggest challenges as I help them shift to the role of value creator and trusted partner. While there is no silver bullet solution, there are steps CISOs can take now to elevate the value of their cybersecurity programs, setting themselves up for success against a moving target.

Bring your board on board

Boards typically comprise seasoned executives with experience in operations, finance, sales and other industries, but may not have a detailed, technical understanding of cybersecurity. Yet, CISOs are faced with increasing scrutiny from their boards as they defend their cybersecurity program’s effectiveness.

VB Event

The AI Impact Tour: The AI Audit

Join us as we return to NYC on June 5th to engage with top executive leaders, delving into strategies for auditing AI models to ensure fairness, optimal performance, and ethical compliance across diverse organizations. Secure your attendance for this exclusive invite-only event.

Request an invite

To showcase the value of their programs and demonstrate effectiveness, CISOs must establish clear communication and overcome the disconnect between the board and their team. It’s up to the CISO to ensure the board understands the level of cyber risk their organization is facing and what they need to increase the cyber resilience of their organization. Presenting cyber risk levels in monetary terms with actionable next steps is necessary to bring the board of directors on the same page and open an honest line of communication, while elevating their cybersecurity team to the role of value creator. 

File an honest SEC 10K without increasing cyber risk (no really!)

New disclosure requirements from the Securities and Exchange Commission (SEC) and other regulators require CISOs to have a firm understanding of their material risks and disclose how they manage and mature their cybersecurity program. Yet, recent analysis of SEC 10Ks filed in early 2024 shows that 31% of enterprises had no cybersecurity disclosures and 23% did not quantify or describe how their cyber risk is managed. 

CISOs are deeply wary about sharing too many details on their cybersecurity posture in the public domain, because of the unnecessary and preventable risk of exposing their organizations to cyberattacks, which are expected to cause $10.5 trillion in damages by 2025. 

Filing an honest 10K while preserving your organization’s cyber defenses requires a delicate balance. We’ve already seen Clorox fall victim when the balance was off. 

A good example of an honest, yet balanced SEC 10K is Lockheed Martin’s 2024 SEC 10K filing, which took a descriptive approach. The company named the CISO as being responsible for its security strategy. It outlined specific cybersecurity policies, frameworks, and requirements that it would comply with, indicating the maturity of the organization’s cybersecurity program. They proactively described their cyber risk models and clarified the methodology for supplier and third-party risk management. Lockheed Martin also mentioned using techniques such as third-party assessments, penetration testing, audits and threat intelligence to test the design and effectiveness of controls. These are all vital components of having a robust risk management program and filing for a balanced and honest SEC 10K.

Adopt gen AI to mitigate cyber risk

According to data from Gartner, there are only enough qualified cybersecurity professionals available to meet just 70% of the current demand. This need for the right talent will no doubt increase as the threat landscape continues to evolve rapidly. 

Effectively managing cybersecurity risk requires identifying critical vulnerabilities and evaluating your security controls’ efficacy. However, petabytes of data from disparate sources and a stagnant team size make gaining complete visibility into these risks a challenge for CISOs. 

Often, the core obstacle for security teams is converting raw data into actionable insights, which is necessary to facilitate effective risk reduction in a way that is digestible for the entire organization. By leveraging advanced technologies such as generative AI, deep learning and other specialized machine learning techniques to analyze millions of assets and vulnerability instances, security teams can access real-time, actionable insights and rapidly reduce cyber risk. 

More so, this can enable security leaders to understand the effectiveness of their security program and showcase the return on investment of their cybersecurity initiatives. Ultimately, this facilitates an easier and more productive conversation with the board, too.

Given the pace at which the cybersecurity landscape is continuing to evolve, the CISO’s job is getting tougher. They are responsible not only for successfully defending their organizations against threats but also for providing proof of their efficacy to the board and reporting it to the SEC. Keeping pace with the latest technology and ensuring open and honest communications with non-cybersecurity stakeholders is imperative for fully embracing the role of value creator in an organization.

Gaurav Banga is the CEO and founder of Balbix, an AI-powered cybersecurity risk management platform. 

DataDecisionMakers

Welcome to the VentureBeat community!

DataDecisionMakers is where experts, including the technical people doing data work, can share data-related insights and innovation.

If you want to read about cutting-edge ideas and up-to-date information, best practices, and the future of data and data tech, join us at DataDecisionMakers.

You might even consider contributing an article of your own!

Read More From DataDecisionMakers

Credit: Source link

ShareTweetSendSharePin

Related Posts

Google Adds Creepy Avatars To Gemini 3.8 Live’s Agents
AI & Technology

Google Adds Creepy Avatars To Gemini 3.8 Live’s Agents

September 25, 2026
Fastino Releases GLiNER2.5-Decide: A 340M Open-Weight Decision Model That Runs on CPU
AI & Technology

Fastino Releases GLiNER2.5-Decide: A 340M Open-Weight Decision Model That Runs on CPU

September 25, 2026
Black Forest Labs Releases FLUX 3 Action: A 7B Open-Weights World Action Model That Tops RoboLab-120
AI & Technology

Black Forest Labs Releases FLUX 3 Action: A 7B Open-Weights World Action Model That Tops RoboLab-120

September 25, 2026
Warzone Is Adding A Button To Hide All The Goofy Skins
AI & Technology

Warzone Is Adding A Button To Hide All The Goofy Skins

September 24, 2026
Next Post
Daughter reacts to GTR! #gtr #daughter #goals #reaction

Daughter reacts to GTR! #gtr #daughter #goals #reaction

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
The 50/30/20 Budgeting Rule Explained in Simple Terms

The 50/30/20 Budgeting Rule Explained in Simple Terms

September 22, 2026
Everton Blair wins in Georgia’s 13th District special election, NBC News projects 

Everton Blair wins in Georgia’s 13th District special election, NBC News projects 

September 23, 2026
Bentley unveils Torcal SUV, its first EV costing an ‘affordable’ 0K

Bentley unveils Torcal SUV, its first EV costing an ‘affordable’ $230K

September 23, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!