
Every fourth business executive in Southeast Asia (SEA) prefers not to flag a lack of understanding when discussing cybersecurity issues. A recent Kaspersky study also reveals one in ten C-level managers has never heard of threats such as Botnet, APT, and Zero-Day exploits. The same proportion appeared to be unfamiliar with cyber security concepts like DecSecOps, ZeroTrust, SOC, and Pentesting.
According to a PwC study, while backing cybersecurity in every business decision has already become the norm in every other company, more than half of executives lack confidence that their cyber spending is being allocated to the most significant risks their organization is facing. Kaspersky conducted their own research to help IT and C-level find common ground and explore the root of their misunderstandings, where a total of 300 executives from the SEA region were surveyed.
The Kaspersky poll indicates that C-suite sometimes struggles to understand their IT security peers and are not always ready to show their confusion. Thus, 26% of non-IT executives here say they would not feel comfortable flagging that they don’t understand something during a meeting with IT and IT security.
Although most of them hide their confusion because they prefer to clarify everything after the meeting or choose to figure everything out by themselves, more than half (55%) don’t ask additional questions because they don’t believe their IT peers will be able to explain it in a clear way. Almost two in five also feel embarrassed revealing they don’t understand the topic and 42% don’t want to look ignorant in front of their IT colleagues.
Also, even though all surveyed top managers from SEA regularly discuss security-related issues with IT security managers more than one-in-ten respondents have never heard of threats such as Zero-Day exploit (11%), Botnet (9%), and APT (9%). At the same time Spyware, Malware, Trojan and Phishing appeared to be more familiar for top-managers.
More than one-in-ten top managers here admit they have never heard of cybersecurity terms like DecSecOps (10%), SOC (10%), Pentesting (10%), and ZeroTrust (6%).
“Non-IT top management do not have to be experts in complex cybersecurity terminology and concepts and IT security executives should keep this in mind when communicating with the board,” comments Sergey Zhuykov, Solution Architect at Kaspersky.
“To establish efficient cooperation CISO should be able to focus C-level attention precisely on meaningful details and clearly explain what exactly the company is doing to minimize cybersecurity risks. In addition to communicating clear metrics to stakeholders, this approach requires offering solutions instead of problems,” says Zhuykov.
“On the other end of the communications spectrum, only 6% of IT security professionals in SEA admit facing difficulty in discussing aspects of their work to the C-level. This means the majority of our technical workforce deem that their updates are understood by the decision makers. To bridge this dangerous gap, security teams should also incorporate effective tools – real life examples and use of reports and numbers – to ensure that discussions are done effectively,” adds Chris Connell, Managing Director for Asia Pacific at Kaspersky.
To ease the communication between IT security and business functions within the company, Kaspersky recommends the following:
- IT security should be positioned as a driver for growth and innovation in the organization. To achieve this the IT security team should move away from prohibitive tactics and rather explain how the business can achieve its goals while mitigating cybersecurity risks.
- CISO should actively engage in operational activities and build relationships with the company’s stakeholders. While fewer than 20% of CISOs have established partnerships with key executives in sales, finance, and marketing, it is hard for them to stay abreast of the needs of the business.
- When communicating with the board, use arguments based on an overview of threats by experts, your company’s attack status and best practices.
- Explain to the board what the main responsibilities of the IT security team are. If possible, provide them with an opportunity to walk in a CISO’s shoes to get insights on the most relevant IT security challenges.
- Allocate cybersecurity investments in tools with proven efficacy and ROI. This means tools that lower the level of false positives, and reduce times of attack detection, the time spent per case and other metrics are important to any IT security team.
Kaspersky in Southeast Asia also has launched a Buy 1 Free 1 promo to help SMBs and midrange enterprises in beefing their cybersecurity capabilities. Businesses can now enjoy two years of enterprise-grade endpoint protection for the price of 1 with Kaspersky Endpoint Security for Business or Cloud or Kaspersky Endpoint Detection and Response Optimum, with 24×7 phone support. Interested customers can reach out to [email protected].
The full report and more insights on communications issues between C-level and IT security managers are available via the link.
Methodology
The research among Non-IT or IT security workers was conducted by Censuswide research consultancy commissioned by Kaspersky. The quantitative online research was undertaken amongst top-management and C-level who discuss security-related issues with IT or IT-security managers at least once a year. Researchers interviewed 2,300 employees, 300 were from Southeast Asia, from global businesses with more than 50 employees, with representation across 25 countries. Respondents were questioned on their organization’s perceived IT readiness, communication between IT staff and non-IT executives, and consequences resulting from miscommunication.

27 Comments
Youre so cool! I dont suppose Ive learn anything like this before. So nice to search out somebody with some unique ideas on this subject. realy thank you for beginning this up. this website is one thing that is wanted on the web, somebody with a little bit originality. useful job for bringing something new to the internet! patrickstash
Took me awhile to read all the comments, but I really enjoyed the article. It proved to be very helpful to me and I am sure to all the commenters here! It’s always nice when you can not only be informed, but also entertained! I’m sure you had fun writing this article. castro cvv
Respect to website author , some good selective information . jerrys vc
thank for dropping this story. I am definitely tired of struggling to find relevant and intelligent commentary on this subject. Everyone nowadays seem to go to extremes to either drive home their viewpoint or suggest that everybody else in the globe is wrong. thank for your concise and relevant insight. patrickstash
Pretty nice post. I just stumbled upon your blog and wanted to say that I have really enjoyed browsing your blog posts. In any case I’ll be subscribing to your feed and I hope you write again soon 강남 퍼펙트
I do accept as true with all of the ideas you’ve offered on your post. They are very convincing and will certainly work. Nonetheless, the posts are too short for beginners. Could you please prolong them a little from next time? Thanks for the post. 달리는토끼
I am happy that I observed this weblog , just the right information that I was looking for! . 다낭 유흥
Excellent. Thanks sharing. I enjoyed your article quite a lot while reading. Many thanks for sharing. 강남퍼펙트가라오케
I like this site so much, bookmarked . bclub
Hey! I’m at work surfing around your blog from my new apple iphone! Just wanted to say I love reading through your blog and look forward to all your posts! Keep up the outstanding work! swipestore
Hey! I’m at work surfing around your blog from my new apple iphone! Just wanted to say I love reading through your blog and look forward to all your posts! Keep up the outstanding work! ultimateshop
Great post. I am a regular visitor of your web site and appreciate you taking the time to maintain the nice site. I will be a frequent visitor for a really long time. gonzo c0m
An extremely good post. This post sums up for me just what this topic is all about and some of the major benefits that can be produced by knowing about it just like you. A friend once pointed out that you have a totally different approach when you do something for certain as opposed to when you’re simply just toying with it. In the case of this specific topic, I believe you’re taking, or start to go for, a more professional plus thorough approach to what and how you’re writing, which in turn helps you to continue to get better and help others who don’t know anything at all about what you have discussed here. Thank you. Jerry’s CC+CVV Store
building websites is not only fun, but it can also generate an income for yourself;; savastan0
This is sensible info! Where else will if ind out more?? Who runs this joint too? sustain the good work unitedshop
had issues with hackers and I’m looking at options for another platform. I would be awesome if you could point me in the direction of a good platform. vclubshop
Hey! I’m at work surfing around your blog from my new apple iphone! Just wanted to say I love reading through your blog and look forward to all your posts! Keep up the outstanding work! russianmarket
An incredibly fascinating read, I might not concur completely, but you do make some extremely valid points. b club
You ought to join in a contest for starters of the highest quality blogs online. I will recommend this page! realandrare
Thanks for the post, was an interesting read. Curious as to how you came about that solution… PatrickStash Market
After examine a number of of the blog posts on your web site now, and I really like your manner of blogging. I bookmarked it to my bookmark web site record and can be checking again soon. Pls try my website online as well and let me know what you think. patrickstash
잠실역 인근 윈가라오케 – 송파 최대 규모 65개 룸, 최고급 시설과 음향, 합리적 정찰제 가격의 프라이빗 노래방. 24시간 연중무휴 운영, 무료 음료·맥주 무제한 윈가라오케
I wanted to say thank you to you for this excellent read!! I have you saved as a favorite to see fresh stuff you post. đá gà thomo
스포츠 베팅이나 경기 예측에 관심이 있다면 한 번쯤 **“스포츠 픽”**이라는 용어를 들어보셨을 것입니다. 간단히 말해 스포츠 픽은 특정 경기의 결과를 미리 분석하고 예측한 정보를 의미합니다. 스포츠 픽
Hey! Good stuff, do tell us when you finally post something like this! sub sandwiches
Just since the blogs cover each number of topics, they have become a quality source of hyperlink for several online resources. An effective comment for just a site encourages somebody to add your website link into the other ?nternet site. By indexing links from weblog remarks you possibly can draw immense attention with your internet site. Check this out
I just additional this particular feed to be able to my book marks. I need to say, I seriously take pleasure in reading your own sites. Keep it up! Read more