New CyberArk survey on security programme effectiveness

New CyberArk survey on security programme effectiveness Seventy-nine percent of IT security professionals report to executive…
Firefly security fence surrounding building with a cyber digital background abstract

Share this article:

New CyberArk survey on security programme effectiveness

Seventy-nine percent of IT security professionals report to executive management on compliance, yet 59 percent say threat detection metrics are most critical

New industry research sponsored by CyberArk (NASDAQ: CYBR) finds that one-third of CEOs and 43 percent of management teams are not regularly briefed on cyber security issues. Additionally, while 79 percent of IT security professionals are reporting on compliance metrics to demonstrate security programme effectiveness, 59 percent state that threat detection metrics are most important.

An independent survey of global IT security professionals, “The Gap Between Executive Awareness and Enterprise Security,” drills into the types of metrics used to measure security programme effectiveness, frequency of reporting, and other factors such as budget and skills.

The cyber security gap: Executive awareness and responsibility
The survey shows that 60 percent of respondents believe their organisation can be breached. As cyber attacks grow in aggression and impact, CEOs and boards are being held accountable for the security posture of their organisation. A closer look at the perceptions of IT security practitioners regarding executive cyber security leadership provides some clues into what’s driving a lack of alignment:

• 61 percent believe that CEOs do not know enough about cyber security;
• 69 percent say cyber security is too technical for their CEO;
• 53 percent think that CEOs make business decisions without regard to security;
• 44 percent believe CEOs simply do not grasp the severity of today’s risks.

IT security professionals need to properly educate executives
While IT security professionals are relying on executive level leadership on security issues, CEOs are increasingly relying on their IT security teams to provide them with the security information that matters. The survey shows that the cyber security awareness gap may be driven in part by the need for security teams to properly educate CEOs on what’s business critical when it comes to security:

• One-third of CEOs are still not regularly briefed on cyber security issues and related business risks;

• Forty-three percent of management teams do not regularly receive security status reports;

• Fifty-nine percent of respondents emphasised threat detection metrics as the most effective for measuring security programme effectiveness, yet 79 percent still provide compliance and audit findings to their CEOs and executive teams;

• Executive visibility into security programme effectiveness varies by industry with the highest percentage of respondents in financial services (72 percent) and healthcare (70 percent) saying they regularly provide executives with reports and metrics;

• 50 percent or less of respondents in manufacturing, hospitality, transportation and non-profit industries said that they regularly provide reports and metrics to their executive teams;

“Compliance does not equal security. It can lull a CEO into a state of complacency because all it demonstrates is a simple checking of a box without context for responsible levels of information protection,” said John Worrall, chief marketing officer, CyberArk. “Security professionals are briefing executives on the wrong information. They need to arm their CEOs and executive teams with information that matters such threat detection and risk metrics versus compliance and system availability.”

Is budget a barrier to effective cyber security?
Improving IT security fundamentals is a critical step in improving an organisation’s overall security posture. The survey identified areas for improving organisational security:

• Seventy five percent of respondents cited budgeting issues as the primary barrier to improving cyber security;

• In the face of a growing cyber security skills gap, 53 percent cited the lack of expertise as a primary barrier;

• Endpoint security and privileged account security were cited as the top two organisational security priorities over the coming year.

“Increasingly it’s CEOs who own the security agenda – whether they want to or not. One of our goals with this survey was to identify specific gaps between IT security and executive teams and help drive productive conversations that prioritize enterprise security,” continued Worrall. “By providing greater visibility into how cyber security programmes are performing, and regularly communicating needs around budget and skills, IT professionals will gain the support of the executive team and in turn help their organisation become more proactive in protecting against advanced threats.”

To help support the need for greater executive guidance and dialogue around critical cyber security decisions, CyberArk recently launched a new industry initiative, the CISO View. The CISO View provides a forum for the CISO community to share best practices and tangible guidance for building effective cyber security programmes. A new report, “The Balancing Act: The CISO View on Improving Privileged Access Controls,” features advice from a panel of CISOs from global 1000 enterprises about how to lead a comprehensive privileged account security programme including recommendations for getting executive buy-in, delivering metrics that matter, and measuring effectiveness of the controls. The report is available for free here.

“The Gap Between Executive Awareness and Enterprise Security” survey was conducted by Dimensional Research. The study, commissioned by CyberArk, surveyed 304 global IT security professionals. The primary research goal was to capture hard data on visibility and support of security programmes at the executive level. In addition, researchers sought to determine which metrics are used to define security effectiveness.

[su_button url=”http://www.cyberark.com/” target=”blank” style=”flat” background=”#df2027″ color=”#ffffff” size=”10″ radius=”0″ icon=”icon: arrow-circle-right”]Click here to find out more about CyberArk[/su_button]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top