Podcast
Root Causes 244: PwC Survey Reports Cyber Security as Biggest Risk to Companies


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
September 26, 2022
A recent survey from PwC reports that cyber threats are no longer solely the domain on the CISO but instead have become every senior executive's concern. We dive deep into these survey results and talk about they correlate with our own experiences, IT skills gaps, and feeding the podcasting beast.
Podcast Transcript
Lightly edited for flow and brevity.
As stated in the survey. And a very large number of the response, more than a third, basically listing cyberattacks as a serious risk as well. So, we are talking about the majority of people who responded to the survey, people very high up within enterprises, not necessary IT people, we’re talking about them saying my biggest risk overall, even in a world where we have Ukraine, where we have rising interest rates, where we have all kinds of things that affect businesses negatively, things that you have make shifts for as a corporate executive – cyber risk is Number 1.
And there’s a statement that has been made here that caught my eye as the reason why I wanted to cover this in a podcast and that is, cyber threats are no longer solely the domain of the CISO.
Tim, to me, that’s huge because one of the biggest problems that I have, you have, a lot of us who come from the computer security industry is trying to make the big decision makers understand that security really needs to be a top down enterprise for the whole organization. You need to see this as more than just a cost center from which you just solve a problem and move on to the rest of your business. It’s something that – Tim, you’ve made this point before about how every single business out there is digital. Digital transformation has happened everywhere and there’s very few businesses that don’t have to rely on computer communications from some kind. Business to customer. Business to other businesses. Your ability to operate yourself. Your ability to report on yourself. The dashboards. Your inventory systems. Everything, Tim.
Now it’s interesting. So, you talk about don’t just think of this as the domain of the CISO. There’s a department; the department handles it; I give them enough money; I don’t want to think about it ever again. Some of the other things on this list are big and broad enough that it would affect the whole company. Everyone would be worried about it. And I’ll just grab a few just pretty at random – inflation, U.S. regulatory environment, recession, U.S./China relations, COVID-19 variants and other public health crisis, climate change. Like these are things that would affect all kinds of people. Supply chain disruptions. These are things that affect all the people and department inside of your company. If you were worried about supply chain disruptions or COVID-19, everybody would say how does this affect me? What do I need to do differently? And to your point, Jay, which I think is good one, is for many, many years, people didn’t think that way about the computer stuff. The computer stuff was the computer department’s department, if you will, and not mine to worry about. But suddenly, it’s topping the list.
There’s a talent gap. There’s a skills gap. In this field in particular – I’ve seen other research other places that suggest that that IT skills gap is greater than any other skills gap in any professional segment in the world.
I don’t think the bullpen is anywhere near what it needs to be and I don’t think it’s just because, as you and I like to joke, computers are hard and security is even way harder.
And, here we are, industry graybeards, that’s what we call ourselves at the top of the podcast, and even some of the guests we have on, these are folks we’ve known for years and years and the numbers of just the fresh faces who haven’t worked with you before, can’t wait to have a good working relationship handshake, I don’t know. I don’t see enough of it and definitely not in computer security.
And so, therefore, if this survey is truly true, and I believe it is and really, people who are at all levels of the brass, the C-suite, are now in on this with the CISO, then you are all the folks with the clout within the company and the knowledge and the wherewithal to be able to make the big decisions of I’m going to do what Tim said, which is I’m gonna grow from within and to fulfill some of these positions that are now important to the whole company.

