The race to secure flexible working
Our conversations with business leaders about cyber security and new post-pandemic working patterns highlighted three key challenges.
Challenge 3: Valuing cybersecurity
Sometimes the low-key success of IT security can undermine its perceived value. When cybersecurity is working correctly it’s invisible. This can lead to a lack of perceived value, which in turn can make it hard to get buy in from the board/senior managers for some parts of the IT security budget. Businesses face the challenge of defining what good security looks like for them. And communicating the benefits to their board.
Boardroom attitudes to cyber security may be changing for the better, though. Technology executives we interviewed said that information security had risen in the board’s agenda in the past few decades. The pandemic has underscored the importance of strong cyber security, especially when more employees are working from home.
“This pandemic has created a different way of thinking about information security, and we can’t do the same things and expect different results,” says Selva Vinothe Mahimaidas - CISO at Houghton Mifflin Harcourt, an education and learning company. “Our company has almost doubled the investment in information security spending as a percentage of our overall IT spend.”
Other executives we interviewed echoed this view that the pandemic, and surge in remote working, had pushed cyber security even further up the boardroom agenda.
“It used to be the case that we were on the board’s agenda, but maybe we’d get the last five minutes,” says Jon Winbow of GSK. “We’re now the 30 minutes at the start of the meeting. They absolutely get it. They’ve driven some security measures that we have to have out there.”

Jon Winbow,
Director of Information Security
| GlaxoSmithKline

It used to be the case that we were on the board’s agenda, but maybe we’d get the last five minutes. We’re now the 30 minutes at the start of the meeting. They absolutely get it. They’ve driven some security measures that we have to have out there.
How can organisations estimate return on investment (ROI) from cyber-security spending?
Cyber insurance premiums are sometimes a “forgotten element” of ROI calculations, says Donal Munnelly, Security Proposition Manager at BT Ireland. Having a robust Cyber security policy backed up by defence in depth can dramatically reduce your cyber insurance premiums, he says.
“Obviously, the costs to a cyber-attack depend on the nature of the attack. If the attackers target your critical business operations, there’s a huge cost to the business when output stops. If the attack has targeted sensitive information there can be additional fines levied by regulators that could be substantial.
“If intellectual property is compromised there can be a cost in terms of competitive advantage. Avoiding these costs are a substantial ROI for cyber security.”
Cyber security threats are changing constantly. Just keeping track of them could be a full-time job. C-suite executives are more interested in solutions. What technologies and security policies and procedures can mitigate security threats and, ideally, improve an organisation’s productivity? The exact security threats will be different in each organisation, but in our interviews with business leaders, a consensus emerged about what action organisations should take to secure their more fluid network perimeters and workforces.

Donal Munnelly,
Security Proposition Manager
| BT Ireland

If intellectual property is compromised there can be a cost in terms of competitive advantage. Avoiding these costs are a substantial ROI for cyber security
Share this page