Published: 07 October 2024
Summary
CISOs risk organizing their security function inefficiently by searching for a one-size-fits-all model, which may not reflect the organization’s evolving security needs and practices. This research will help them design the “best-fit” security organization tailored to their organizations’ realities.
Included in Full Research
Overview
Key Findings
Many chief information security officers (CISOs) are still looking for a perfect security organization; but dynamic business environments necessitate organization-specific best-fit models instead.
Organizations are waking up to the reality that a reorganization does not make them more efficient or secure as it cannot remedy deeper governance or culture issues.
Many factors, such as enterprise risk appetite, corporate culture and maturity levels, influence the design of a security team, complicating organization planning.
Recommendations
CISOs responsible for organizing security teams must:
Clients can log in to view the entire
document.