What is the most overlooked step in a cybersecurity plan?

3.3k viewscircle icon1 Upvotecircle icon8 Comments
Sort by:
Senior Information Security Manager in Software4 years ago

Testing, and that the plan must be regularly updated.
Regularly could mean quarterly or more often.

Lightbulb on3
Director of Technology in Government4 years ago

Overlooking physical security in your CyberSecurity plan could leave a major gap in your CyberSecurity posture.

Lightbulb on1
CIO / Managing Partner in Manufacturing4 years ago

Getting senior executives fully on board and understanding it.

Fractional CIO in Services (non-Government)4 years ago

Communicating it in a way that makes sense to your people.

VP, Director of Cyber Incident Response in Finance (non-banking)4 years ago

This is an excellent question.  I think it's the maintenance of the plan itself.  Because even if you document the plan, and the processes to address the response, each security incident is unique enough that it will require you to update the processes involved.  So the moment you publish your plan, it's already out of date!

1 Reply
no title4 years ago

Absolutely. I would say actually following it, and keeping it up to date and current, are the biggest challenges. Too many organizations create a plan, the stick it on a shelf until the next annual audit rolls around. It does you no good if you don't actually follow through from the plan.

Lightbulb on2

Content you might like

AI-driven threats (deepfakes, automated attacks) 21%

Software supply chain risks 21%

Insider risk (both malicious & accidental) 13%

Regulatory compliance 11%

Cloud misconfigurations 13%

Shadow IT (or shadow AI) 11%

Ransomware 4%

Talent shortage in cybersecurity4%

Something else (comment to explain)2%

View Results

Artificial Intelligence / Machine Learning41%

Automation18%

Cloud17%

Edge / IoT6%

Augmented / Virtual Reality6%

Blockchain4%

5G3%

Other (comment)

View Results