Survey: CISOs Continue to Struggle to Strike Right Risk Balance
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”这样的开头。好的,我先看看文章的主要内容。 文章是关于422位CISO的调查结果。首先,超过一半的人认为他们的组织在网络安全和弹性方面很强,但不到一半的人觉得风险管理与风险偏好对齐得很好。虽然他们认为沟通渠道有效,但只有53%的人准备好应对AI驱动的威胁,37%的人在项目初期就把预算考虑进去。 LevelBlue的调查显示,CISO们最关注的是机器学习、数据加密、应用安全等技术。但他们在软件供应链安全方面存在盲点,只有25%的人认为供应商的信任度很重要。此外,他们的职责范围扩大了,但风险意识可能还不够高。 最后,文章提到网络攻击因AI而增加,CISO们面临如何平衡安全投入和经济环境的挑战。 现在我要把这些要点浓缩到100字以内。先确定主要数据:61%认为能力强,45%风险管理对齐,53%准备应对AI威胁。投资重点是机器学习、数据加密等。盲点是供应链安全和职责扩展带来的风险意识不足。最后提到AI带来的攻击增加和投入平衡问题。 这样组织一下:调查发现CISO们认为组织在网络安全方面能力强,但风险管理与风险偏好对齐不足。他们准备应对AI威胁的比例较低,并且在项目初期考虑预算的比例更低。投资重点包括机器学习、数据加密等技术。然而,在软件供应链安全方面存在盲点,并且职责范围扩大导致风险意识不足。此外,随着AI驱动的网络攻击增加,CISO们需要在有限资源下平衡安全投入。 </think> 调查发现CISO们认为组织在网络安全方面能力强,但风险管理与风险偏好对齐不足,准备应对AI威胁比例较低,且预算未充分嵌入项目初期。投资重点包括机器学习、数据加密等技术,但在软件供应链安全方面存在盲点,职责范围扩大导致风险意识不足。同时,随着AI驱动攻击增加,CISO需平衡有限资源下的安全投入。 2026-3-9 20:7:31 Author: securityboulevard.com(查看原文) 阅读量:4 收藏

A survey of 422 CISOs finds that while well over half (61%) believe their organizations are highly competent when it comes to cybersecurity and cyber resilience, less than half (45%) said their organization’s risk appetite is effectively aligned with cybersecurity risk management even though 57% claimed their communications channels with the line of business units is effective.

Conducted by LevelBlue, a provider of managed security services, the survey also finds only 53% of respondents feel their organization is prepared to defend against adversaries that are enabled by artificial intelligence (AI) and even fewer (37%) said cybersecurity budgets are embedded into projects from the start.

LevelBlue CISO Kory Daniels said the results suggest there is still a significant gap between an organization’s ability to secure emerging technologies such as AI prior to it being embedded within business workflows. The issue with AI is that pace of adoption is already faster than any previous class of emerging technologies, he added.

However, that gap may be narrowing, with 69% of CISOs identifying machine learning for pattern matching as the top investment priority, followed closely by data encryption (67%), application security (66%), cyber resilience (66%), generative AI for social engineering attacks (65%), advanced threat detection technologies (64%), enhanced software supply chain security (62%) and attack-specific defenses (59%). Lower down on that list of priorities are neural networks for predictions (39%) and zero-trust architectures (34%), the survey finds

Overall, the survey finds the biggest challenges CISOs face are now data security and privacy (55%), data storage for increased volumes (48% ​), data loss prevention (44%), data fragmentation and siloed access (42%), cost management and optimization (42%), lack of interoperability between systems (37%) and data latency or inconsistencies (33%), the survey finds.​

Additionally, the survey suggests many CISOs have a potential blind spot. Just 25% say that the need to assign or create a confidence level of suppliers is an important factor in improving software supply chain visibility. Only 31% say that the biggest security risk they face today could come from within the software supply chain, and between half and two-thirds said some aspects of the software supply chain pose no particular risk to the business.

Many CISOs are now also seeing the scope of the responsibilities being assigned them expand into new areas when their appreciation for the level of risk might not yet be as high as it might need to be, noted Daniels.

Regardless of the scope of those responsibilities, cyberattacks being launched are increasing in both volume and sophistication thanks to the rise of AI. The amount of time cybersecurity teams have to detect and thwart those attacks before there are catastrophic consequences has at the same time been sharply reduced. In effect, CISOs now find themselves locked in an arms race with adversaries that tend to have much larger financial resources at their disposal.

The challenge, as always, is determining how much to spend to mount an appropriate defense based on actual levels of risk that doesn’t ultimately result in an organization spending more on security than it can ill afford in a global economic environment that remains uncertain at best.

Recent Articles By Author


文章来源: https://securityboulevard.com/2026/03/survey-cisos-continue-to-struggle-to-strike-right-risk-balance/
如有侵权请联系:admin#unsafe.sh