CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Cybersecurity & Resilience
  • CIO Viewpoints

The Realities of Cybersecurity

Doug Mullarkey, CIO, First Choice Loan Services Inc.

Tweet

content-image
Cybersecurity, one of the biggest buzzwords and global technology challenges, can be defined as “the protection of information systems from theft or damage to the hardware, the software, and to the information on them, as well as from disruption or misdirection of the services they provide.” Cybersecurity threats and risks are everywhere and businesses all want to be secure, from the C-level and Board of Directors down through front line employees. Recent breaches that have made front page news strikes fear into the hearts of everyone. Larger companies like Target and Sony have the resources to weather the fallout of a cybersecurity event, but a breach or hack could destroy the reputation and brand of a smaller company. A breach could be especially impactful to a company that survives month to month or does the majority of its business during a particular season.

The Realities

One would think that with all of the risk associated with cybersecurity companies would do “whatever it takes” to ensure security. In speaking with industry peers at conferences and technology events, I am surprised to hear that many business leaders do not want to make the sacrifices to be secure. I like to compare cybersecurity to weight loss; being secure is like wanting to lose 10 pounds. Everyone (myself included) wants to lose 10 pounds, but doing the hard work to lose those 10 pounds takes effort and sacrifice, and only a few can really do what it takes to make that happen. I like to apply that analogy to cybersecurity. Everyone wants to be secure, but few truly put forth the effort to be secure. It’s our job as Information Technology (IT) leaders to make the strong case to the business and “close the deal” to ensure that the proper funding and resources are obtained, and most importantly that the business truly buys in. This is a huge challenge for small to midsized organizations that are not accustomed to strong controls. Larger organizations have the controls in place.

I definitely hear about resistance to doing things a new way and securely from peers all the time. The avoidance of change itself is often the root cause of anxiety and not the actual cybersecurity initiative. The following are a few examples of business resistance to cybersecurity initiatives seen industry-wide.

• Blocking Third Party Email–This is how data leaves the company and viruses get in–bypassing email filtering and controls.

• Blocking External Media like USB and CD-ROM-This too is how data leaves the company and viruses get in–bypassing controls.

• Blocking Non-Corporate Wireless–Again, a back door in and out of the corporate environment.

• Rogue Offices–Offices that do not have the proper controls are a huge corporate security risk.

• User Accounts with Admin Rights–This is a big one. Many employees want local admin rights perform tasks requiring elevated system rights.

​The goal of cybersecurity is not to change the way the business functions, but to make things more secure


Malware and viruses can easily propagate through the machine and the network using an account with elevated rights.

• Blocking Non-Corporate Application Installs–Nobody needs WeatherBug. Sorry. Application white-listing helps prevent malware from being installed.

• Secure Mobile Devices–If you want to get email on a phone, data must be encrypted and the device must be password protected.

• Strong Passwords–abc123 is not a strong password.

• Folder Restrictions–Ensuring employees have rights to just what they need helps prevent the spread of ransomware.

• Managing Social Media –Policies that define what can and can’t be posted by employees. No, you shouldn’t post a photo from your Game of Thrones script on Snapchat.

• Managing Physical Security–Lock the doors! Follow a clean-desk policy.

• Web Filtering–No, you can’t gamble online using company resources.

How to “Make The Sale” and Get Buy-In

Our job as IT leaders is to develop services to enable the business while increasing security. When one application or process is deemed insecure, it’s IT’s job to create and build a new way of doing that job or function and “sell” it to the business. It’s best to start at the top.

Board-Level Support

Start at the top. Explain to your Board the risks associated with cybersecurity, how to mitigate those risks and create a road map and business case for security initiatives. Everything starts at the top, and board approval will help drive security initiatives. Board of Directors are very focused on cybersecurity and compliance and will gladly support initiatives that keep the negative publicity away.

Cybersecurity and Compliance

Cybersecurity concerns are not only technology related but also bridge the gap with compliance. “Nobody” cares about cybersecurity until a breach has occurred or until examiners and regulators are onsite doing their audit and exam. Compliance and cybersecurity go hand-in-hand and a strong relationship with compliance helps drive the business acceptance of new policies and procedures.

Policies and Procedures

Board approved policies and procedures that detail the crucial “do’s and don’ts” are the cornerstone of any cybersecurity program. It should be built on industry standards such as NIST or ISO 27001 to name two. It is always great to refer the policy when a questionable request comes into IT. Policies can be used as a “bully pulpit”.

Company-wide Training

Formal employee training goes a long way towards allowing staff to understand the risks. Training helps explain the “why’s” to employees who are not tech savvy or simply don’t understand why we can’t do things the old way. Our employees are our greatest strength and can be our greatest weakness. When an employee does something wrong, it’s not due to malicious intent, but because of not knowing. Employee signature of new policies allows for the enforcement of new policies.

Culture Change

Gradual implementation of new policies will allow employees to ease into a new way of doing things. Culture change is a gradual process that improves over time.

Conclusion

To conclude, the goal of cybersecurity is not to change the way the business functions, but to make things more secure. Company resources belong to the company and are tools for the business to function. As technology leaders, we need to get buy-in from our Board of Directors and create a culture change that is security-centric. If a process or tool is eliminated as being insecure, a more secure method must replace it. At the end of the day, cybersecurity is not just an IT concern, it’s an “everyone” concern, and we all need to work together to embrace security.

Check Out Review Of CIOReview: Crunchbase, Glassdoor

Check This Out: CIOReview Overview, Muckrack

Check this out: Top Fraud And Breach Protection Companies

See Also: ComplianceQuest | CIOReview

Weekly Brief

loading
cioviewpoint
TOP VENDORS
Top 25 Cyber Security Companies - 2017
  • Adopting And Driving AI Across an...

    Dr. Yves Gorat Stommel, Deputy Head of Function Evonik Digital, Evonik [ETR: EVK]

  • Challenges under the Hood: Cloud...

    Ivan Romero, Global Head Of Public Cloud, Wealth Management & Insurance, Banco Santander(BME: SAN)

  • Evolving Role of the CISO

    Christos Syngelakis, Group Chief Information Security Officer, Motor Oil[Fra: Mhz]

  • EU Cyber Challenges For The Private...

    Paulo Moniz, Director- Information Security and It Risk, EDP [ELI: EDP]

  • Inspiring Extraordinary Customer Success

    Alexander Bender, Global Head of Client and Broker Relationship Management, Allianz

  • Unveiling the Power of Data Visibility

    Muhammad Saleem, Head of Data Architecture, Bae Systems [LON: BA]

  • Transforming The Trucking Industry...

    Jair Ribeiro, Data Analytics and AI Leader, Volvo Group

  • The Transforming Landscape of...

    Cameron Farrar, Vice President - Head Of Software Asset Management, Marsh Mclennan(NYSE: MMC)

RECENT EDITIONS
‹ ›

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security-and-resilience.cioapplicationseurope.com/cioviewpoint/the-realities-of-cybersecurity-nid-3.html