• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

PodChats for FutureCISO: Improve cyber risk outcomes in distributed ecosystems

Allan Tan by Allan Tan
September 12, 2022
PodChats for FutureCISO: Improve cyber risk outcomes in distributed ecosystems

PodChats for FutureCISO: Improve cyber risk outcomes in distributed ecosystems

Cybersecurity is turning into a social phenomenon. Investor interest, public pressure, employee demands, and governmental regulations are strengthening the incentives for organisations to track and report cybersecurity goals and metrics within their environmental, social and governance (ESG) efforts as a business requirement.

Gartner says traditional culture improvement efforts that focus exclusively on awareness are failing to facilitate secure behaviour. A key theme for security and risk management (SRM) leaders in the coming years is the increasingly distributed ecosystem that has led to a loss of direct decision-making control.

Alex Lei, VP and GM for APJ at Proofpoint, observed that in the past risk management was around protecting the data. The pandemic and the resulting hybrid work environment made it clear that ‘the person accessing the data cannot be trusted.’ He pointed to the 2022 Ponemon Cost of Insider Threats Global Report, as revealing a 44% increase in concerns regarding the threat.

Another threat that has come about from the practice of remote work is the absence of face-to-face exchanges. This presented new opportunities for attackers to take advantage of this through social engineering, advertising, services, or applications.

Supply chains are trusted relationships built over years of transactions and exchanges – many of which flowed from the physical interchange.

“As a result of the pandemic, we are seeing attackers coming in, and leveraging on the inherent trust based on the existing relationships that we already have, but they’re redirecting the money elsewhere,” said Lei.

Alex Lei

Gartner says 56% of customers expressed ‘frequent interest and concern’ in the cybersecurity posture of the organisations they do business with.

Cultural barriers against data protection

Asked to cite any prevailing cultural trends that are stopping better outcomes when it comes to data protection, Lei commented that while there are many, he picked on one barrier – lack of communication.

“In Asia, cyber security practitioners and board-level people are not communicating effectively. There are a lot of reasons for this, but if you survey the CISOs across Asia, most of them will say that the alignment between the board and cyber security practitioners is probably less than 30% in most cases. They are talking on different tangents, require different things, and communicate in different styles,” he elaborated.

He suggested that fixing this has nothing to do with technology. “It is around aligning interests: between the company interests, and the business interests between the board level and the cybersecurity level,” he opined.

Establish corporate behaviour that is secure by design

Gartner says traditional culture improvement efforts that focus exclusively on awareness are failing to facilitate secure behaviour and have led to a loss of control amid an increasingly distributed ecosystem.

Asked whether he agreed with this assessment that there is a case of failing to facilitate secure behaviour that is leading to a loss of control and awareness, Lei conceded and added further that the traditional approach to fixing a problem by brute force almost never works.

“Where things can be very effective is when we incorporate people into the process and make them part of the program. If they own up to that issue and the program, they become accountable and they are now owners of the new outcome – that can be extraordinarily powerful,” he suggested.

Strategies for sustainable risk management practices

How can organisations improve data protection outcomes for the company in today’s distributed ecosystems?

Many organisations today operate in distributed ecosystems. Large organisations have established shared services organisations that may likely be located remotely from many of the company’s front and back-office operations.

Lei cited the use of support engineers centralised in one location and providing global support. Their job necessitates that they handle sensitive data, and they're working with both upstream suppliers and downstream providers.

They are in a complex ecosystem, and the nature of their interaction is phone calls, emails, and document sharing means handling sensitive data is part of the job.

(Photo: RENDY ARYANTO/VVS.sg)

“Maybe they want to get things done faster, and they circumvent a business process to do the job. But in doing that, they open a hole in their protection. This creates a liability for the company, regulatory issues, and room for potential hackers to come in. That is the reality of the world that we live in today. We must ensure that the business process makes sense and need to be well-designed."

Alex Lei

He also posited the need to allow the right data to get to the right people in a distributed ecosystem. And equally important, according to Lei, is the ability to monitor and govern the data in use, especially if they are going out of the parameters, when they go against the policies and when they circumvent the policy.

“We must be able to identify that and enforce it somehow,” Lei concluded.

Click on the PodChat player and listen to Lei detail ways for organisations to improve cyber risk management outcomes in distributed ecosystems.
  1. Briefly provide a state of data protection today among organisations across Asia.
  2. What are prevailing cultural practices that are hindering better outcomes when it comes to data protection?
  3. Gartner says traditional culture improvement efforts that focus exclusively on awareness are failing to facilitate secure behaviour and have led to a loss of control amid an increasingly distributed ecosystem. Specific to Asia, do you agree with this assessment?
  4. Can you recommend strategies or best practices to improve how organisations can improve data protection outcomes for the company in today’s distributed ecosystem?
  5. What needs to happen to facilitate your recommendations? 
Related:  The future of advertising lies in protecting user identities
Tags: data protectionenterprise risk managementGartnerPodchatsproofpointsustainable practice
Allan Tan

Allan Tan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • ARTHALAND chooses OutSystems to advance real estate sustainability
  • Experts warn against AI-powered deepfake impersonation scams
  • Dropbox updates universal search and knowledge management product
  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe