As the threat escalates, a publicly traded corporation continues to cut corners on IT security, relying on hope rather than defense.

The CISO? No influence. No budget. No team.

Now the few employees are sick, and no one cares.
The executive suite? Looking the other way.

Years of overload, zero recognition, no opportunities for development, and a management team lulled into a false sense of security. The risk is no longer hypothetical. When the last person on the security team is overwhelmed and drops out, everything comes to a standstill. And the attackers won’t wait.

Burnout has now become a security vulnerability in itself:

  • CISOs work an average of eleven hours of overtime per week.
  • 60% report acute burnout
  • Many leave the role after a few years. Burned out, discouraged, left alone.

What is the point of having a CISO if they don’t receive any real support? When will board members take responsibility instead of making excuses ?

The much-cited cyber security skills gap? In my opinion, it’s homemade.

It’s caused by decision-makers who prioritize incorrectly, downplay or ignore risks, and thus lose the very professionals they are desperately seeking.

Cyber security does not fail because of a lack of talent; it fails because of a lack of leadership.

Tags

Share post

More articles

Over the past six months, we have held numerous discussions with medium-sized organisations of various sizes that would like to take out new cybersecurity insurance or adapt existing policies. The consistent tenor that we have...
Efficient protection through 2-factor authentication Multi-factor authentication (MFA) or mostly 2-factor authentication is on everyone’s lips. You read a lot about the benefits – and yet you are often annoyed when “the second factor” has...
Numerous details about people, their purchases and other sensitive details could be accessed unprotected on the web for months, as Der Spiegel (German content) prominently reports on its website. A service provider had inadequately secured...