25% of security leaders replaced after ransomware attack
CISOs have a one in four chance of their job surviving a successful ransomware attack, according to a recent Sophos report. The report’s findings are a wakeup call for CISOs regardless of whether they are found at fault or have any meaningful authority to block such attacks, industry experts say.
“That stat isn’t surprising, but it reflects a growing frustration at the board level when the security function fails to deliver results, regardless of how fair that judgment may be,” contends Erik Avakian, technical counselor at the Info-Tech Research Group. “Even if the attack came from factors outside of their direct control, there’s still an expectation from stakeholders that [CISOs] need to be able to prevent any worst-case scenario.”
Avakian adds that the move to oust a CISO after a ransomware attack is sometimes necessary and appropriate, but companies often jump to termination decisions too quickly.
Read more at CSO Online