Intelligent CISO Issue 66 | Page 36

Most companies in the region do not recognise the value they can provide at a more strategic level as business enablers . disconnect contributed to 42 % of delayed investments and 41 % of late strategic decisions and a 33 % of unnecessary increase in spending . But , most importantly it caused a 28 % spike in the number of successful cyberattacks .
With a closer alignment with the business goals , it would be easier to identify possible cybersecurity pitfalls in the roadmap and intervene earlier .
editor ’ s question

?

ust like companies

J put a lot of effort into devising sound plans and a detailed roadmap to achieve success , they should also spend time conducting a detailed assessment to understand their specific cyber-risks , pinpointing vulnerabilities and deciding the level of investments , based on their risk tolerance . Most importantly , they should consider their cybersecurity efforts as building blocks of their business roadmap , instead of something separate .

While cybersecurity teams have a primary role in protecting the company , minimising risks and thwarting increasingly sophisticated cyberattack techniques , most companies in the region do not recognise the value they can provide at a more strategic level as business enablers .
This misalignment has several consequences . On one hand , it perpetrates the misconception that cybersecurity is nice to have , but fundings can be moved to other areas of the business if needed . From research we conducted earlier this year , we know that in the UAE and KSA region the

Most companies in the region do not recognise the value they can provide at a more strategic level as business enablers . disconnect contributed to 42 % of delayed investments and 41 % of late strategic decisions and a 33 % of unnecessary increase in spending . But , most importantly it caused a 28 % spike in the number of successful cyberattacks .

On the other hand , it prevents the company from leveraging the entire potential of its personnel and having a complete vision of what is possible and feasible when it comes to delivering on the roadmap . For example , thanks to their technical knowledge and expertise , the cybersecurity teams could provide valuable support in increasing internal efficiency , ensuring critical systems are always available and continuously aligned and compliant with legislation requirements , and supporting innovation , such as new product development efforts . Moreover , with a closer alignment with the business goals , it would be easier to identify possible cybersecurity pitfalls in the roadmap and intervene earlier with less impact on the business .
Closer alignment requires a change of perspectives and company and
MORTADA AYAD , DIRECTOR – SALES ENGINEERING , DELINEA

With a closer alignment with the business goals , it would be easier to identify possible cybersecurity pitfalls in the roadmap and intervene earlier .

cybersecurity leaders can facilitate it in several ways , such as running crossdepartment outcome-based meetings , developing skills or revisiting the reporting structure of the security teams . The way cybersecurity programmes are evaluated should also change , adding business metrics like risk management , compliance levels and Business Continuity metrics to the technical and activity-based ones used today .
Unlocking the cybersecurity team ’ s potential is among the most effective strategies to protect the business and make it flourish .
36 www . intelligentciso . com