Connect with us

Hi, what are you looking for?

HEADLINES

Adopting new solutions is toughest topic for C-level in SEA to discuss with IT colleagues

A Kaspersky study revealed that every third C-level executive (37%) struggles to speak about adopting new security solutions with their IT or IT security colleagues. The latter, however, feel increasing the budget for cyber security is the toughest topic to discuss with non-IT management. 

A Kaspersky study revealed that every third C-level executive (37%) struggles to speak about adopting new security solutions with their IT or IT security colleagues. The latter, however, feel increasing the budget for cyber security is the toughest topic to discuss with non-IT management. 

According to the poll majority of the IT workers say that the main reason their cyber security budget was lowered was that top management sees no reason to invest much in this sphere. Kaspersky conducted a special survey to explore if this situation might be a result of unclear communication between IT security staff and executives, and to discover whether there is a lack of mutual understanding between these two corporate tribes.

The study reveals that, while more than half of top managers in SEA (60%) think IT security employees should better communicate cyber risks to business, only 6% of cybersecurity workers from the region admit they have some difficulties explaining any aspect of their work to non-IT colleagues and executives.

“There is a clear communications gap between enterprises’ decision makers – non-IT C-level executives – and the technical security team responsible for the company’s cybersecurity posture. It is worrying because the same study showed miscommunications between the two groups have negative impacts like serious delays in projects (67%), one or more cybersecurity incidents (66%), and budget wastage (60%),” comments Chris Connell, Managing Director for Asia Pacific at Kaspersky.

IT and non-IT workers in SEA also differ on the most complicated topics to debate. C-level executives’ three toughest subjects to talk about with IT staff are: adopting new security solutions (37%), compliance with security regulations (37%) and changes to the cybersecurity policy (33%). 

Advertisement. Scroll to continue reading.

For IT workers the top-3 toughest themes to discuss with non-IT executives are the need to increase the IT security budget (55%), expanding the IT security team (54%), and raising cybersecurity awareness among employees (52%).

On the subject of finding common ground, the majority of respondents from SEA agree that the most efficient ways to facilitate discussions about IT-security issues are to choose real life examples and to use reports and numbers. Besides these topics C-level executives here also said that citing references to authoritative opinions (49%) would allow them to best understand their IT-security staff. The IT teams, on the other hand, believe threat stories (52%) will help them to better communicate with executives.

“It can be assumed that non-IT executives struggle to discuss the adoption of new cybersecurity solutions because of the abundance of complex technical terms and concepts often used by IT security staff. The latter, however, don’t like to speak about increasing budgets since C level executives expect them to use business metrics to justify their needs,” says Ivan Vassunov, VP, Corporate Products, Kaspersky. 

“Today, in a difficult economic environment and complicated threat landscape, mutual understanding between business and IT security people is more important for business continuity than ever before. To avoid additional cybersecurity risks it is crucial that both teams know how to speak a common language based on numbers, reliable references and understandable arguments.”

To make the communication between IT security and business functions within the company more transparent, Kaspersky recommends the following: 

  • Allocate cybersecurity investments into tools with proven efficacy and present new security concepts (including SASE, XDR and Zero Trust) to the board as investment projects or even business cases with calculated ROI. For example, in the cases of XDR (Extended Detection and Response) and SASE (Secure Access Service Edge) implementation, it is important to communicate that these technologies allow the burden on the IT security team to be reduced, while simultaneously improving company’s cybersecurity posture due to centralization and automation of processes. 
  • Use resources, such as the IT Security Calculator and reports based on experts’ observations containing structured information about the threats and security measures most relevant to your particular industry and company size to verify the probability of risks and the protective measures needed. 
  • Acquire additional knowledge to better understand professionals from other spheres. While business basics can be gained from training courses, non-IT executives have an opportunity to walk in a CISO’s shoes to gain insights into the most relevant IT security challenges. 

The full report and more insights on communications issues between C-level and IT security managers are available via the link.

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

HEADLINES

In 2025 alone, Converge denied nearly 12 billion entry requests to websites hosting dangerous, inappropriate, and harmful content that attempted to pass through its...

HEADLINES

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos' commitment to an open ecosystem...

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Attackers are operationalizing artificial intelligence (AI) to collapse attack workflows from weeks to days. The report finds that AI’s most immediate impact on cybercrime...

HEADLINES

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and...

HEADLINES

The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery....

Advertisement