New research shows that cyber risk management is more difficult now than it was two years ago. Primary causes include increasing workloads, sophisticated threats, and more demanding business executives. Credit: Thinkstock Cyber risk management is significantly more difficult today than it was two years ago.That’s according to new ESG research involving 340 enterprise cybersecurity, GRC, and IT professionals who were asked to compare cyber risk management today to two years ago. (Note: I am an employee of ESG.) The data indicates that 39 percent of survey respondents believe that cyber risk management is significantly more difficult today than it was two years ago, while another 34 percent say that cyber risk management is somewhat more difficult today than it was two years ago.4 reasons why cyber risk management is more difficultWhy do 73 percent of cybersecurity, GRC, and IT professionals believe cyber risk management is more problematic? Several issues stand out: The ever-growing attack surface. Forty-three percent of respondents say cyber risk management is more difficult today because their organization has moved more workloads to the public cloud. Furthermore, 41 percent say their organization has more sensitive data, while 39 percent claim they have more devices on the network. All these IT additions point to a common problem: Enterprises have a lot more stuff to protect than they did just two years ago. By the way, this trend never ceases.More vulnerabilities. Forty-two percent of those surveyed say cyber risk management is more difficult today because the number of software vulnerabilities has increased. There are also plenty of other vulnerability issues, such as misconfigured devices, systems, administrator accounts, and untrained users.The dangerous threat landscape. Forty-two percent of those surveyed say cyber risk management is more difficult today because the technical sophistication of cyber-adversaries has increased. This is also a perpetual trend.Business requirements. Thirty percent of those surveyed say cyber risk management is more difficult today because business managers are asking for more risk management analysis and reporting. So, I guess cybersecurity really is a boardroom issue.Think about this data from a CISO perspective. Your bosses are pushing you for more frequent updates on cyber risk management, and they want it presented in a business context. Meanwhile, your staff — which is likely incrementally bigger than it was two years ago, if at all — must collect, process, analyze, and report on risk management across from an increasing and vulnerable attack surface, being targeted by more sophisticated cyber-adversaries. Let’s face it, CISOs are being forced to bring knives to a cyber risk management gun fight — this model is completely broken. Fortunately, there is hope. Stay tuned for future blog posts. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe