24.04.2013 Views

Governance of Enterprise Security: CyLab 2012 Report How ... - RSA

Governance of Enterprise Security: CyLab 2012 Report How ... - RSA

Governance of Enterprise Security: CyLab 2012 Report How ... - RSA

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

from IT IT security security experts, experts, and and 18% 18% said said insurance insurance brokers brokers provided provided outside outside expertise. expertise. In In the the 2010 2010 survey, survey,<br />

from 17% from 17% <strong>of</strong> <strong>of</strong> IT <strong>of</strong> the the security the respondents respondents experts, indicated indicated and indicated 18% that that said that IT insurance IT security security brokers experts experts provided provided outside outside expertise. expertise, expertise, while In while the 26% 2010 26% indicated indicated<br />

survey,<br />

17% insurance 17% insurance <strong>of</strong> the brokers brokers respondents provided provided indicated these these services, that services, IT security just just the the experts opposite opposite provided <strong>of</strong> <strong>of</strong> the the <strong>2012</strong> outside <strong>2012</strong> survey. survey. expertise, It It is is important while important 26% to to indicated to note note that<br />

that<br />

insurance the insurance the the survey survey brokers did did not not not provided ask ask ask what what these topics topics services, the the the outside outside just experts the experts opposite were were asked <strong>of</strong> asked the to <strong>2012</strong> to address, address, survey. so so it It it is is is possible important possible that that to the note the Audit,<br />

Audit, that<br />

the full the full full survey board, board, did or or or other other not other ask committees committees what topics hired hired the computer computer outside computer experts security security were or or IT asked IT expertise.<br />

expertise. to address, so it is possible that the Audit,<br />

full board, or other committees hired computer security or IT expertise.<br />

Industry & Region Comparison Table: Board Board Use <strong>of</strong> Use <strong>of</strong> Outside <strong>of</strong> Outside Experts Experts<br />

Industry & Region Comparison Table: Board Use <strong>of</strong> Outside Experts<br />

Source <strong>of</strong> <strong>of</strong> outside<br />

North North<br />

Europe Asia Asia Energy / / Financial IT IT / IT / / Industrials<br />

Source risk Source risk risk expertise expertise<br />

<strong>of</strong> outside North America North America<br />

Europe Asia Energy Utilities Energy Utilities / Financial IT Telecom IT Telecom / Telecom Industrials<br />

risk Risk risk Risk Risk expertise Services Services Firm Firm America 36% 23% 30% Utilities 17% 40% Telecom 0% 0% 0% 20% 20%<br />

Risk Insurance Risk Insurance Services Broker Broker Firm 36% 45% 36% 45% 23% 8% 30% 15% 30% 15% 15% 17% 0% 0% 40% 10% 40% 10% 0% 0% 0% 100% 20% 100% 100%<br />

Insurance IT Insurance IT IT <strong>Security</strong> <strong>Security</strong> Broker Experts Experts 45% 36% 45% 36% 39% 8% 39% 15% 50% 0% 50% 10% 20% 10% 20% 33% 0% 33% 33% 100% 20% 20%<br />

IT <strong>Security</strong> Experts 36% 39% 15% 50% 20% 33% 20%<br />

The North American respondents indicated that they they are are clearly clearly more more reliant reliant upon upon insurance insurance brokers brokers to<br />

to<br />

The provide The provide North outside outside American expertise expertise respondents than than Europe Europe indicated or or Asia. Asia. that It they It is is interesting are interesting clearly to more to note, note, reliant however, however, upon that insurance that respondents respondents brokers from from to the<br />

the<br />

provide energy/utilities provide energy/utilities outside and and expertise and IT/telecom IT/telecom than Europe sectors sectors or said said Asia. they they It do do is do interesting not not use use insurance insurance to note, brokers brokers however, brokers at at all that all for for respondents outside outside expertise,<br />

expertise, from the<br />

energy/utilities while while 100% 100% <strong>of</strong> <strong>of</strong> the and the respondents IT/telecom respondents from sectors from the the said industrials industrials they do sector not sector use indicated indicated insurance that that brokers they they use at use all insurance insurance for outside brokers brokers expertise, for for this<br />

this<br />

purpose. while purpose. while purpose. 100% <strong>of</strong> the respondents from the industrials sector indicated that they use insurance brokers for this<br />

purpose.<br />

IT IT IT security security and risk experience becoming more valuable to to boards.<br />

IT security and risk experience becoming more valuable to boards. Twenty-seven Twenty-seven percent percent (27%) (27%)<br />

<strong>of</strong> <strong>of</strong> Twenty-seven <strong>of</strong> the the the respondents respondents percent indicated indicated (27%)<br />

that <strong>of</strong> that <strong>of</strong> that the their their respondents board board had had indicated an an outside<br />

outside<br />

director that director that director their with board with cybersecurity<br />

cyber had security an security outside<br />

expertise, director expertise, director expertise, with up up from cyber from 18% security 18% in<br />

in<br />

2010. expertise, 2010. expertise, 2010. Seventy-three Seventy-three up from 18% percent<br />

percent in<br />

(73%) 2010. (73%) <strong>of</strong> Seventy-three <strong>of</strong> <strong>of</strong> the the the respondents respondents percent said<br />

said<br />

their (73%) their (73%) their boards boards <strong>of</strong> boards the had had respondents had an an an outside outside said<br />

director their director their director boards with with had risk risk an expertise,<br />

outside<br />

compared director compared director compared with with with risk 59% 59% expertise, in in in 2010.<br />

2010.<br />

Fifty-one compared Fifty-one compared Fifty-one percent percent with percent 59% (51%) (51%) in 2010. <strong>of</strong> <strong>of</strong> <strong>of</strong><br />

respondents Fifty-one respondents Fifty-one respondents percent indicated indicated (51%) that<br />

that <strong>of</strong><br />

their respondents their respondents their boards boards retain retain indicated retain pr<strong>of</strong>essional<br />

pr<strong>of</strong>essional that<br />

search their search their search boards firms firms retain to to seek seek pr<strong>of</strong>essional qualified<br />

qualified<br />

candidates search candidates search candidates firms for for to their seek their board.<br />

qualified board.<br />

candidates for their board.<br />

Not Not surprisingly, surprisingly, the the experience deemed most important in in recruiting directors was financial and<br />

management Not management Not management surprisingly, expertise. expertise. the experience IT IT expertise expertise deemed is is becoming becoming most important more more valuable, valuable, in recruiting however. however. directors When When was recruiting, recruiting, financial IT IT and IT expertise expertise was<br />

was<br />

very management very important important expertise. or or or important important IT expertise for for 37% 37% is <strong>of</strong> becoming <strong>of</strong> the the respondents respondents more valuable, and and somewhat somewhat however. important important When recruiting, for for for 42%. 42%. IT It It It is is expertise is encouraging encouraging was<br />

that very that that 64% important 64% <strong>of</strong> <strong>of</strong> the the respondents or respondents important indicated indicated for 37% that that risk <strong>of</strong> risk the and and respondents security security expertise expertise and was was somewhat either either very very important important or for or important important 42%. It and and is 27% encouraging 27% said said it<br />

it<br />

was that was that was somewhat somewhat 64% somewhat <strong>of</strong> the important. important. respondents indicated that risk and security expertise was either very important or important and 27% said it<br />

was somewhat important.<br />

Carnegie Carnegie Mellon Mellon <strong>CyLab</strong> <strong>CyLab</strong><br />

Carnegie Mellon <strong>CyLab</strong><br />

! !<br />

!<br />

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!