As the world's technology rapidly evolved and threats skyrocketed in the cloud, the need for security and compliance teams to come together to protect organizations and their customers has never been more important. Unfortunately, this hasn't happened yet.
In partnership with Enterprise Management Associates (EMA), we polled 204 technology and business leaders in North America from more than ten industry verticals to investigate this theme. The research found that most organizations recognize the importance of managing both compliance and security functions in-house. Nearly 83% of respondents said that a corporate employee was responsible for information security and 88% said that IT audit and compliance functions are also handled internally.
Yet, while most organizations run internal compliance and security teams, their status is not weighted equally. Compliance imperatives typically drive security priorities. However, organizations' combined security and compliance postures will be better served when both teams work together, and budgets and investments should reflect that equal importance.
Key takeaways from the research include:
Security and compliance ownership and budgets are splintered
Security and compliance ownership and budgets are splintered. They often operate with different teams, budgets and investment levels, but they need to work together to better protect the organization's posture instead.
■ 47% said that IT owns the security budget, while 11% noted that compliance is the security budget owner.
■ In the future, 86% of those surveyed plan to make a significant investment in compliance solutions and data privacy, while just over half (52%) will make a significant investment in a security management suite.
Compliance challenges amplified by rapidly growing IT environments
Compliance challenges are amplified by rapidly growing and global IT environments with different regulatory climates.
■ 39% of respondents said having multiple IT environments with different requirements is their primary compliance challenge.
■ 40% of organizations have postponed security projects to address regulatory compliance concerns.
■ 68% believe their regulatory compliance programs are a competitive differentiator.
■ 75% said that they are using existing tools or evaluating new tools to address data privacy.
compliance needs driving cybersecurity priorities
Organizations' compliance needs are driving cybersecurity priorities, causing teams to alter security strategies to align with requirements.
■ 67% said that data privacy regulations like GDPR, CCPA or changing data controls were their biggest compliance challenges.
■ 38% said that data security and privacy was the greatest security challenge in their organization
■ 25% stated that information security projects are dependent on compliance projects
■ 76% said that compliance has completely or significantly shifted their security strategy
Compliance and security teams must work together
Compliance and security teams must work together to best manage a mature and robust program, while maintaining numerous attestations and controls globally.
■ 89% indicated that the priorities of the security and compliance teams were aligned.
■ 85% stated that the security tools used adequately address compliance considerations.
■ 59% indicated that data privacy regulations have impacted their approach to security.
Integrated Security and Compliance Solutions
This survey also signaled the growing demand for integrated security and compliance solutions that increase visibility while mitigating emerging threats and privacy regulations. When organizations prioritize DevSecOps, they can better maintain compliance, especially as they are expected to comply with multiple standards, including PCI, HIPAA, PII, SOC and GDPR, in highly regulated industries.
It is undeniable that all organizations will benefit from incorporating a security-centric culture and fostering better collaboration between security and compliance teams. Organizations must adopt solutions that provide real-time monitoring for continuous compliance and help maintain system security.
The Latest
Broad proliferation of cloud infrastructure combined with continued support for remote workers is driving increased complexity and visibility challenges for network operations teams, according to new research conducted by Dimensional Research and sponsored by Broadcom ...
New research from ServiceNow and ThoughtLab reveals that less than 30% of banks feel their transformation efforts are meeting evolving customer digital needs. Additionally, 52% say they must revamp their strategy to counter competition from outside the sector. Adapting to these challenges isn't just about staying competitive — it's about staying in business ...
Leaders in the financial services sector are bullish on AI, with 95% of business and IT decision makers saying that AI is a top C-Suite priority, and 96% of respondents believing it provides their business a competitive advantage, according to Riverbed's Global AI and Digital Experience Survey ...
SLOs have long been a staple for DevOps teams to monitor the health of their applications and infrastructure ... Now, as digital trends have shifted, more and more teams are looking to adapt this model for the mobile environment. This, however, is not without its challenges ...
Modernizing IT infrastructure has become essential for organizations striving to remain competitive. This modernization extends beyond merely upgrading hardware or software; it involves strategically leveraging new technologies like AI and cloud computing to enhance operational efficiency, increase data accessibility, and improve the end-user experience ...
AI sure grew fast in popularity, but are AI apps any good? ... If companies are going to keep integrating AI applications into their tech stack at the rate they are, then they need to be aware of AI's limitations. More importantly, they need to evolve their testing regiment ...
If you were lucky, you found out about the massive CrowdStrike/Microsoft outage last July by reading about it over coffee. Those less fortunate were awoken hours earlier by frantic calls from work ... Whether you were directly affected or not, there's an important lesson: all organizations should be conducting in-depth reviews of testing and change management ...
In MEAN TIME TO INSIGHT Episode 11, Shamus McGillicuddy, VP of Research, Network Infrastructure and Operations, at EMA discusses Secure Access Service Edge (SASE) ...
On average, only 48% of digital initiatives enterprise-wide meet or exceed their business outcome targets according to Gartner's annual global survey of CIOs and technology executives ...
Artificial intelligence (AI) is rapidly reshaping industries around the world. From optimizing business processes to unlocking new levels of innovation, AI is a critical driver of success for modern enterprises. As a result, business leaders — from DevOps engineers to CTOs — are under pressure to incorporate AI into their workflows to stay competitive. But the question isn't whether AI should be adopted — it's how ...