Cybersecurity

Cyber security: checks are still sporadic in more than half of all companies

Cybersecurity must be integrated into corporate governance, extending beyond IT functions to protect the value of the business

La sicurezza è un aspetto fondamentale della difesa informatica, in quanto garantisce protezione a livello di dispositivo da minacce, violazioni dei dati e accessi non autorizzati.  (Adobe Stock)

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

The digital age is over. Or rather, it has entered a new phase. IT infrastructure has become the nervous system of organisations, business processes and relationships with customers, suppliers and institutions, but this consolidation has not been matched by equivalent progress in security, which has historically been treated as a separate function, delegated to a technical department and assessed using criteria that date back to when the Internet was, albeit very promising, still just one channel amongst many. But if everything is digital today, cybersecurity cannot remain confined to a single department; it must be embedded in the organisation’s processes, decision-making and governance.

Cybersecurity unfortunately suffers from an original sin, namely that it has always been a discipline focused on protecting data, databases and networks, and confined to IT departments. Companies, managers and boards of directors have always treated it as a technical issue, and anything perceived as technical rarely features among business priorities. Consequently, two parallel worlds have developed — the world of security, which talked about firewalls, vulnerabilities, patches and compliance, and the world of management, which talked about growth, customers, markets and results — which at a certain point ceased to communicate with one another. But in doing so, we have built giants with feet of clay.

Loading...

Cybersecurity: checks in companies remain sporadic

A study we have just completed as Strategic Management Partners involving 80 large Italian companies confirms just how wide the gap between awareness and operational governance really is. In more than half of the companies, cyber risk assessments are carried out sporadically: 45 per cent conduct assessments only once a year, and one in ten does not even have a set frequency for such assessments. In two out of three cases, there are no KPIs to measure the level of security achieved — which means that boards discuss cybersecurity without having any metrics to assess it.

The most critical finding, however, concerns the supply chain: only 12 per cent of businesses regularly check the security of their suppliers, 25 per cent carry out no checks at all, and 63 per cent do so only occasionally. This is despite the fact that the European regulatory framework — NIS2, DORA, AI Act — has shifted responsibility across the entire supply chain, making the supply chain the effective perimeter of security. The problem is that many organisations continue to view security as a necessary cost, if not a bureaucratic burden, and merely as a function for protecting data. Yet the reality tells a different story. Over 80 per cent of the most damaging incidents in Europe are linked to ransomware and digital extortion, the aim of which is not the data itself, but rather to disrupt the organisation’s ability to operate. Data is not the end goal, but the means; the real target is business continuity and the value generated by the organisation: in a word, the business in its entirety.

This is all the more urgent with the advent of iartificial intelligence, which acts as a catalyst for the problem: integrating AI and cloud models into business processes means multiplying the attack surfaces, yet our research shows that awareness of this specific risk is still lagging behind. Companies invest in cybersecurity primarily to comply with regulations, without turning compliance into a tool for governance and organisational efficiency. This is why we must stop viewing cybersecurity as an IT function and start integrating it into business strategies, shifting from data protection to value protection, and from technological control to organisational resilience.

Regulatory developments are seeking to keep pace with this ‘cyber transformation’. NIS2 has extended cyber risk management obligations well beyond traditional strategic sectors, introducing direct accountability for governing bodies; DORA imposes digital operational resilience requirements on banks, insurance companies and fintech firms, extending them for the first time to their ICT suppliers; the AI Act introduces obligations regarding governance, transparency and human oversight of high-risk systems. The common thread is the centrality of the process: no one is asking for one-off compliance in the run-up to an audit any more; everyone is asking for evidence that risk governance exists, is documented, is monitored and evolves over time. Compliance, in operational terms, has become a continuous process.

The convergence of these regulations marks a turning point that Italian management cannot afford to underestimate. In practical terms, this means that compliance models must evolve from an event-driven approach — sporadic preparation for audits, certificates hung on the wall, and closed archives — to one of continuous compliance, with constant monitoring, updated controls and traceability of decisions; that safety, quality, risk and AI management systems must be designed to communicate with one another, rather than being managed in functional silos; and that the accountability introduced by NIS2 for governing bodies definitively shifts the focus from the technical-operational level to the strategic-decision-making level.

Cyber security and corporate governance

Following the years of digital transformation, we are entering a new era – that of cyber transformation – where cyber security is no longer merely a technical issue but has become an integral part of corporate governance — encompassing everything to do with growth, customers, markets and results. The shift is from digital security to business security: it is no longer about protecting the IT system, but about safeguarding the business’s ability to generate value and striving for Total Business Resilience.

Italian businesses are not yet organised to make this leap, and those who fail to do so risk discovering that the digital world, without cyber governance, is a fragile construct.

Achieving Total Business Resilience means working simultaneously to make one’s governance and compliance model resilient through a continuous process of centralisation, integration and simplification, so as not to be overwhelmed by compliance itself, whilst integrating resilience with cybersecurity, thereby ensuring business continuity and avoiding the creation of digital giants with feet of clay.

Loading...

*co-founder and equity partner at Strategic Management Partners

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti