{"id":27870,"date":"2017-03-01T17:01:02","date_gmt":"2017-03-01T09:01:02","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=27870"},"modified":"2017-03-01T17:01:02","modified_gmt":"2017-03-01T09:01:02","slug":"report-finds-misaligned-incentives-executive-overconfidence-create-advantages-for-attackers","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/03\/01\/report-finds-misaligned-incentives-executive-overconfidence-create-advantages-for-attackers\/","title":{"rendered":"Report finds misaligned incentives, executive overconfidence create advantages for attackers"},"content":{"rendered":"<p><strong>Intel Security, in partnership with the Center for Strategic and International Studies (CSIS), released \u201cTilting the Playing Field: How Misaligned Incentives Work Against Cybersecurity,\u201d a global report and survey revealing three categories of misaligned incentives: corporate structures versus the free flow of criminal enterprises; strategy versus implementation; and senior executives versus those in implementation roles. The report highlights ways organizations can learn from cybercriminals to correct these misalignments.<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/07\/CanStock-photo-of-Man-and-Security.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9492\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/07\/CanStock-photo-of-Man-and-Security.jpg\" alt=\"\" width=\"800\" height=\"536\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/07\/CanStock-photo-of-Man-and-Security.jpg 800w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/07\/CanStock-photo-of-Man-and-Security-300x201.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2015\/07\/CanStock-photo-of-Man-and-Security-84x55.jpg 84w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/a><\/p>\n<p>Based on interviews and a global survey of 800 cybersecurity professionals from five industry sectors, the report outlines how cybercriminals have the advantage, thanks to the incentives for cybercrime creating a big business in a fluid and dynamic marketplace. Defenders on the other hand, often operate in bureaucratic hierarchies, making them hard-pressed to keep up.<\/p>\n<p>Additional misalignments occur within defenders\u2019 organizations. For instance, while more than 90 percent of organizations report having a cybersecurity strategy, less than half have fully implemented them. Moreover, 83 percent say their organizations have been affected by cybersecurity breaches, indicating a disconnect between strategy and implementation.<\/p>\n<p>And while cybercriminals have a direct incentive for their work, the survey not only shows there are few incentives for cybersecurity professionals, but that executives are much more confident than operational staff about the effectiveness of the existing incentives. For example, 42 percent of cybersecurity implementers report that no incentives exist, compared to only 18 percent of decision-makers and eight percent of leaders.<\/p>\n<p>\u201cThe cybercriminal market is primed for success by its very structure, which rapidly rewards innovation and promotes sharing of the best tools,\u201d said Candace Worley, Vice President of Enterprise Solutions for Intel Security. \u201cFor IT and cyber professionals in government and business to compete with attackers, they need to be as nimble and agile as the criminals they seek to apprehend, and provide incentives that IT staff value.\u201d<\/p>\n<p>\u201cIt\u2019s easy to come up with a strategy, but execution is tough,\u201d said Denise Zheng, director and senior fellow, technology policy program at CSIS. \u201cHow governments and companies address their misaligned incentives will dictate the effectiveness of their cybersecurity programs. It\u2019s not a matter of \u2018what\u2019 needs to be done, but rather determining \u2018why\u2019 it\u2019s not getting done, and \u2018how\u2019 to do it better.\u201d<\/p>\n<p>Other key findings of the report include the following:<\/p>\n<ul>\n<li>Non-executives are three times more likely than executives to view shortfalls in funding and staffing as causing problems for the implementation of their cybersecurity strategy.<\/li>\n<li>Even though incentives for cybersecurity professionals are lacking, 65 percent are personally motivated to strengthen their organizations\u2019 cybersecurity.<\/li>\n<li>Ninety-five percent of organizations have experienced effects of cybersecurity breaches, including disruption of operations, loss of IP, harm to reputation and company brand, among other effects. But only 32 percent report experiencing revenue or profit loss, which could lead to a false sense of security.<\/li>\n<li>The government sector was the least likely to report having a fully implemented cybersecurity strategy (38 percent). This sector also reports having a higher share of agencies with inadequate funding (58 percent) and staff (63 percent) than the private sector (33 percent and 43 percent, respectively).<\/li>\n<\/ul>\n<p>The report also suggests ways the defender community can learn from the attacker communities. These include:<\/p>\n<ul>\n<li>Opting for security-as-a-service to counter cybercrime-as-a-service<\/li>\n<li>Using public disclosure<\/li>\n<li>Increasing transparency<\/li>\n<li>Lowering barriers to entry for the cyber talent pool<\/li>\n<li>Aligning performance incentives from senior leadership down to operators<\/li>\n<\/ul>\n<p>The good news, according to the report\u2019s authors, is that most companies recognize the seriousness of the cybersecurity problem and are willing to address it. Organizations need more than tools to combat cyberattackers; experimentation is necessary to determine the right mix of metrics and incentives for each organization as they approach cybersecurity through more than just a cost-conscious framework and become more innovative in their organizational structure and processes.<\/p>\n<p>Intel commissioned independent technology market research specialist Vanson Bourne to undertake the research upon which this report is based. Intel surveyed more than 800 respondents from companies ranging in size from 500 employees to more than 5,000 across five major industry sectors, including finance, healthcare and the public sector. The survey targeted respondents with executive-level responsibility for cybersecurity as well as operators who have technical and implementation responsibilities for cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The good news, according to the report\u2019s authors, is that most companies recognize the seriousness of the cybersecurity problem and are willing to address it. Organizations need more than tools to combat cyberattackers; experimentation is necessary to determine the right mix of metrics and incentives for each organization as they approach cybersecurity through more than just a cost-conscious framework and become more innovative in their organizational structure and processes.<\/p>\n","protected":false},"author":6,"featured_media":9492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[1589,2883,5130,54],"class_list":["post-27870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cyber-security","tag-cyberattacks","tag-cybercrimes","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=27870"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27870\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/9492"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=27870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=27870"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=27870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}