One big threat to cybersecurity: IT geeks can’t talk to management
A new report on the state of risk-based cybersecurity management helps explain why IT employees and their corporate bosses don’t see eye to eye about hacking and other computer-based threats.
The report, titled “Are Security Metrics Too Complicated for Management?” is the latest installment of an ongoing series by Tripwire and the Ponemon Institute. The organizations surveyed 1,321 US and UK workers in IT security, IT operations, IT risk management, business operations, compliance/internal audit and enterprise risk management. According to the report, explanations about cybersecurity threats by IT workers get lost in translation in dialogue with corporate managers. “Finding meaningful ways to successfully bridge this communication gap is critical to broader adoption of risk-based security programs,” the report says. “The onus for this effort clearly lies with IT security and risk professionals.” What’s behind the breakdown in communication? A majority of IT professionals said the information is too technical to be understood by non-technical management.
One big threat to cybersecurity: IT geeks can’t talk to management