• About
  • Subscribe
  • Contact
Wednesday, May 7, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

PodChats for FutureCIO: Top challenges for CISOs in Asia

Allan Tan by Allan Tan
September 5, 2021
PodChats for FutureCIO: Top challenges for CISOs in Asia

PodChats for FutureCIO: Top challenges for CISOs in Asia

The chief information security officer (CISO) is the executive responsible for an organization's information and data security. The CISO position first came into being with the appointment of Steve Katz to the role at Citigroup.

The role continues to evolve as enterprises expand their borders to include e-business partnerships, mirroring institutional changes. According to IDG's 2020 Security Priorities Study, 61% of surveyed companies have a CISO, though that rate goes up to 80% for large enterprises.

Jeffrey Kok, VP solution engineers APJ for CyberArk, admitted that prior to 2005, the CISO title was a rarity in the Asia-Pacific region. “But from about 2005 to 2008, we start seeing the first few CISOs in the market, and it's been gradually ramping up,” he added.

He noted that in the present, all the top banks, multinationals and enterprises would already have a CISO. He called out the CISO as a subject matter expert who can take the focus out of the CIOs hands to really focus on IT security for the organisation.

“This is especially so in the past couple of years given that there is a huge increase in cybercrime such as ransomware. The need for CISO is rising. We are seeing, even smaller organisations looking to appoint CISO or hire CISO to put their cybersecurity plans in place,” he continued.

In addition to Ransomware-as-a-Service (RaaS) he noted the acceleration of other forms of disruptive attacks as well as nation-based attacks.

“You can see that the threat landscape is accelerating. Most organisations need someone that can really take focus and know about IT security so that he or she can lead the organisation, put together a program and navigate it. Through this cybersecurity plan, the organisation can reduce the risk of data breaches and business disruption from increased cyber threats,” he continued.

Operational challenges

Kok acknowledged another challenge for CISOs that of evolving regulatory compliance-driven in part by the rise of cyberattacks.

“Organisations are quickly moving to the cloud. With COVID and a remote workforce, a lot of the traditional strategy, which used to focus on perimeter security and protecting everybody within the company boundary, now needs to be extended to protect remote workers who are using cloud services,” he explained.

He raised the need to modernise security strategies, including technology, people and processes. To which he acknowledged that a prevailing talent shortage.

“The CISO cannot do all of these security programs on their own. They need to hire people. And with COVID, it makes it a lot harder to hire in this modern-day,” said Kok.

Architect of security

Asked who decides on the information security strategy for the organisation, and more importantly, how it is executed, CyberArk’s Kok said it depended on the organisation.

“For organisations that do not have a chief risk officer, which many organisations don't, usually the CIO would take this role and set the direction and a strategy. Typically, the Chief Security Officer will set the direction of the general security.

“The CISO will work between the CIO and the CSO to determine what is the cybersecurity strategy and direction. Now, if there is a CRO, the chief risk officer and a CSO is reporting to the chief risk officer, then typically, the risk management team typically determines the direction, together with the CISO,” he elaborated.

When is separating CISO from IT a good strategy?

Kok said the CISO role is typically found in more mature organisations. He explained that the CISO’s top priority might not be fully aligned to the CIO, because some of the security initiatives or security directions might put a damper on the CIO’s overall direction and strategy.

“In those cases, we see that it might be more effective to put the CISO into a separate reporting line in the organisation, where they will be able to work as a parallel stream, together with the CIO to drive better efficiency and results for the organisation,” he explained.

CISO priorities in 2021-2022

While Kok is optimistic that the threat of the pandemic will evolve to an endemic, he believed that the risks of a hybrid workforce will continue.

“We see a lot of CISOs continue to accelerate their digital transformation which will not end by the second half of this year. The digital transformation cycle will continue to next year as well, with the same level of acceleration, to handle all the new problems that they probably haven't figured out.

“For organisations that are in the early days of digital transformation, they will need to quickly learn and solve the workforce challenge. A lot of the same things that we'll see in the second half of 2021, will continue to play out into 2022, as well,” concluded Kok.

Click on the podchat player and listen to Kok share his views on the challenges ahead of CISOs in Asia in 2021 and beyond.

  1. Is the CISO a common occurrence? Or are there more of them coming in late, especially lately?
  2. What is driving the need for a CISO, especially in these couple of years?
  3. Beyond the threat landscape that you've just highlighted. What are the operational challenges facing a CISO and the enterprise he or she represents?
  4. What would be the composition of the team that reports to the CISO, and is there a dotted line to the CIO or perhaps somebody else in the C suite?
  5. Given the role of the CISO, CSO, CRO and the CIO. Who decides on the information security strategy for the organisation, and more importantly, how it is executed?
  6. When is separating CISO from IT a good option for an organisation?
  7. Coming where we are halfway through 2021, what do you see will be governance and security challenges or any challenges that will be facing the CISO for the remainder of the year?
  8. What do you see will be CISO priorities for next year? 2022?
Related:  PodChats for FutureCIO: Securing the enterprise from the Internet of Threats
Tags: CyberArkcybersecuritycyberthreatPodchatsRansomware as a Service
Allan Tan

Allan Tan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe