{"id":54230,"date":"2023-02-22T09:41:45","date_gmt":"2023-02-22T01:41:45","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=54230"},"modified":"2023-02-22T09:41:47","modified_gmt":"2023-02-22T01:41:47","slug":"kaspersky-study-reveals-basic-cybersecurity-terms-unfamiliar-to-c-level-executives-in-sea","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/02\/22\/kaspersky-study-reveals-basic-cybersecurity-terms-unfamiliar-to-c-level-executives-in-sea\/","title":{"rendered":"Kaspersky study reveals basic cybersecurity terms unfamiliar to C-level executives in SEA"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Every fourth business executive in Southeast Asia (SEA) prefers not to flag lack of understanding when discussing cybersecurity issues. A recent Kaspersky study also reveals one in ten C-level managers have never heard of threats such as Botnet, APT and Zero-Day exploit. The same proportion appeared to be unfamiliar with cyber security concepts like DecSecOps, ZeroTrust, SOC and Pentesting.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to a <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.pwc.ro\/en\/press-room\/press-release-2020\/digital-trust-insights-2021--96--of-executives-said-they-ll-shif.html\">PwC\u2019s study<\/a>, while backing cybersecurity in every business decision has already become the norm in every other company, more than half of executives lack confidence that their cyber spending is being allocated to the most significant risks their organization is facing. Kaspersky conducted their <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/speak-fluent-infosec-2023\/\">own research<\/a> to help IT and C-level find common ground and explore the root of their misunderstandings, where a total of 300 executives from the SEA region were surveyed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Kaspersky poll indicates that C-suite sometimes struggle to understand their IT security peers and are not always ready to show their confusion. Thus, 26% of non-IT executives here say they would not feel comfortable flagging that they don&#8217;t understand something during a meeting with IT and IT security.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although most of them hide their confusion because they prefer to clarify everything after the meeting or choose to figure everything out by themselves, more than half (55%) don\u2019t ask additional questions because they don\u2019t believe the IT peers will be able to explain it in a clear way. Almost two-in-five also feel embarrassed revealing they don\u2019t understand the topic and 42% don\u2019t want to look ignorant in front of their IT colleagues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also, even though all surveyed top-managers from SEA regularly discuss security related issues with IT security managers more than one-in-ten respondents have never heard of threats such as Zero-Day exploit (11%), Botnet (9%), and APT (9%). At the same time Spyware, Malware, Trojan and Phishing appeared to be more familiar for top-managers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">More than one-in-ten top managers here admit they have never heard of cybersecurity terms like DecSecOps (10%), SOC (10%), Pentesting (10%), and ZeroTrust (6%).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cNon-IT top management do not have to be experts in complex cybersecurity terminology and concepts and IT security executives should keep this in mind when communicating with the board,\u201d comments Sergey Zhuykov, Solution Architect at Kaspersky.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cTo establish efficient cooperation CISO should be able to focus C-level attention precisely on meaningful details and clearly explain what exactly the company is doing to minimize cybersecurity risks. In addition to communicating clear metrics to stakeholders, this approach requires offering solutions instead of problems,\u201d says Zhuykov.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOn the other end of the communications spectrum, only 6% of IT security professionals in SEA admit facing difficulty in discussing aspects of their work to the C-level. This means the majority of our technical workforce deem that their updates are understood by the decision makers. To bridge this dangerous gap, security teams should also incorporate effective tools \u2013 real life examples and use of reports and numbers \u2013 to ensure that discussions are done effectively,\u201d adds Chris Connell, Managing Director for Asia Pacific at Kaspersky.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To ease the communication between IT security and business functions within the company, Kaspersky recommends the following:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IT security should be positioned as a driver for growth and innovation in the organization. To achieve this the IT security team should move away from prohibitive tactics and rather explain how the business can achieve its goals while mitigating cybersecurity risks.<\/li>\n\n\n\n<li>CISO should actively engage in operational activities and build relationships with the company\u2019s stakeholders. While <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2021-01-28-gartner-predicts-40--of-boards-will-have-a-dedicated-\">fewer than 20% of CISOs<\/a> have established partnerships with key executives in sales, finance, and marketing, it is hard for them to stay abreast of the needs of the business.&nbsp;<\/li>\n\n\n\n<li>When communicating with the board, use arguments based on an <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/apt-intelligence-reporting\">overview of threats by experts<\/a>, your <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/content.kaspersky-labs.com\/se\/media\/en\/business-security\/enterprise\/kaspersky-digital-footprint-intelligence-datasheet.pdf\">company\u2019s attack status<\/a> and <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.iso.org\/isoiec-27001-information-security.html\">best practices<\/a>.&nbsp;<\/li>\n\n\n\n<li>Explain to the board what the main responsibilities of the IT security team are. If possible, provide them with an opportunity to <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/media.kaspersky.com\/en\/business-security\/enterprise\/KL_SA_KIPS_overview_A4_Eng_web.pdf\">walk in a CISO\u2019s shoes<\/a> to get insights on the most relevant IT security challenges.&nbsp;<\/li>\n\n\n\n<li>Allocate cybersecurity investments in tools with <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security#recognition\">proven efficacy and ROI.<\/a> This means tools that lower the level of false positives, and reduce times of attack detection, the time spent per case and other metrics are important to any IT security team.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky in Southeast Asia also has launched a Buy 1 Free 1 promo to help SMBs and midrange enterprises in beefing their cybersecurity capabilities. Businesses can now enjoy two years of enterprise-grade endpoint protection for the price of 1 with Kaspersky Endpoint Security for Business or Cloud or Kaspersky Endpoint Detection and Response Optimum, with 24&#215;7 phone support. Interested customers can reach out to <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"mailto:sea.sales@kaspersky.com\">sea.sales@kaspersky.com<\/a>.&nbsp;&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent Kaspersky study also reveals one in ten C-level managers have never heard of threats such as Botnet, APT and Zero-Day exploit. The same proportion appeared to be unfamiliar with cyber security concepts like DecSecOps, ZeroTrust, SOC and Pentesting.<\/p>\n","protected":false},"author":6,"featured_media":49671,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[101,96,2727,1656],"class_list":["post-54230","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-kaspersky","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=54230"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54230\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/49671"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=54230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=54230"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=54230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}