Insufficient Funding, Sophisticated Threats, and Shortage of Skilled Talent Threaten Security and Put State Governments at Risk: Deloitte/NASCIO Survey - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
October 1, 2014 Newswires
Share
Share
Post
Email

Insufficient Funding, Sophisticated Threats, and Shortage of Skilled Talent Threaten Security and Put State Governments at Risk: Deloitte/NASCIO Survey

PR Newswire Association LLC

NEW YORK, Oct. 1, 2014 /PRNewswire/ -- Although nearly one-half (48 percent) of all state chief information security officers (CISOs) reported incremental increases to cyber security budgets, insufficient funding remains the leading barrier to battling cyber threats, according to the 2014 Deloitte-National Association of State Chief Information Officers (NASCIO) cybersecurity study, released today.

As used in this document, "Deloitte" means Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

The third biennial Deloitte-NASCIO survey of CISOs and their equivalents also reveals an increasing sophistication of cyber threats and inadequate availability of cyber security resources as other top barriers to achieving adequate cyber security measures within state governments.

Three-quarters (75 percent) of the respondents cited lack of sufficient funding as their top barrier and 46 percent estimated security budget to be only between 1 and 2 percent of the overall technology budget. Approximately 6 in 10 (61 percent) CISOs cited an increase in sophistication of threats, up from roughly half (52 percent) in 2012.  The number citing a shortage of qualified cybersecurity professionals jumped from 46 percent in 2012 to 59 percent in 2014.

"State CISOs and CIOs are dealing with a myriad of complex issues related to cybersecurity – budget, increasing threat sophistication, talent and stakeholder communication," said Srini Subramanian, who leads Deloitte & Touche LLP'sCyber Risk Services offering to the state government sector. "The role of the CISO itself has matured and expanded – they are charged to do a lot, with inadequate resources."

Ironically, another challenge cited in the report is a continued discrepancy in the confidence levels of state cyber security among CISOs and state officials. An accompanying survey of state business officials found that 60 percent had high levels of confidence in states' ability to protect and defend against external cyber threats. Only one-quarter (25 percent) of state CISOs expressed a similar level of confidence.

"State business leaders need to play close attention and have a better understanding about the gravity of the situation. We believe that this gap significantly undermines a CISO's ability to gain funding and support for cybersecurity programs. Communicating the cybersecurity risks and potential impact to the business and elected state leaders will likely help elevate the issue," Subramanian noted. "But despite continuing challenges, CISOs are standardizing security practices, launching broad-based awareness campaigns, and looking for ways to attract the right talent to join them in their fight against cyber threats and protecting states' critical infrastructure."

Overwhelmingly, 9 in 10 (90 percent) CISOs point to the salary and pay grade structures states offer as one of the most substantial barriers to attracting and retaining skilled cybersecurity professionals. State cybersecurity professionals are also leaving for private sector careers (71 percent), and more than two-thirds (67 percent) cite lack of defined cybersecurity career paths and opportunities at the state-level.  

"The survey provides a sobering assessment of continuing challenges of budget, talent and evolving nature of cyber threats," said Doug Robinson, chair of NASCIO. "A key challenge facing states is how to both focus on the immediate need of securing their ecosystems against imminent threat while maturing their cybersecurity program that covers protection, early detection/containment and ability to bounce back from incidents."

Key findings of the 2014 Deloitte-NASCIO Cybersecurity Study include:

  • Maturing role of the CISO: State CISO role continues to gain legitimacy in authority and reporting relationships. The responsibilities of the position are becoming more consistent across states, yet expanding. CISOs today are responsible for establishing a strategy, execution of that strategy, risk management, communicating effectively with senior executives and business leaders, complying with regulators, and leading the charge against escalating cyber threats using various security technologies.
  • Budget-strategy disconnect: The improving economy and states' growing commitment to cybersecurity have led to an increase – albeit small – in the budgets. CISOs have also been successful at tapping supplemental resources, whether from other state agencies, federal funding, or various agency and business leaders. Nevertheless, budgets are still not sufficient to fully implement effective cybersecurity programs – it continues to be the top barrier for state CISOs. In addition, survey responses show that there may be additional barriers to implementing successful initiatives: namely the lack of well-thought-out and fully vetted cybersecurity strategy and priorities.
  • Cyber complexity challenge: State information system house a wide range of sensitive citizen data, making them especially attractive targets for cyber-attacks. CISOs are concerned about the intensity, volume and complexity of cyber threats that run the gamut from malicious code to zero-day attacks. They need to stay abreast of existing and developing threats to establish and maintain the security of an information environment that now increasingly extends from internal networks to the cloud and mobile devices. State officials appear more confident than CISOs in the safeguards against external cyber threats, perhaps a result of ineffective communication of risks and impacts.
  • Talent crisis: The skill sets needed for effective cybersecurity protection and monitoring are in heavy demand across all sectors. Private sector opportunities and salaries are traditionally better that those offered by government. Not surprisingly, state CISOs are struggling to recruit and retain people with the right skills, and they will need to establish career paths and find creative ways to build their cybersecurity teams. Furthermore, as states turn to outsourcing and specialist staff augmentation as a means to bridge their cybersecurity talent gap, it's imperative for CISOs to manage third-party risks effectively.

For a copy of the full report, "2014 Deloitte-NASCIO Cybersecurity Study," please visit: http://www.deloitte.com/us/StatesAtRisk

For more information about Deloitte's U.S. State Government practice, please visit: http://www.deloitte.com/us/stategovernment

About the Survey
Deloitte, in conjunction with NASCIO, conducted an online survey of CISOs and state officials in May of 2014. Survey respondents included CISOs or equivalents responsible for the security oversight of 49 states. Additionally, Deloitte surveyed 186 U.S. state business officials to gain states' business stakeholder perspectives about how government enterprise views, formulates, implements, and maintains its security programs.

About Deloitte & Touche LLP'sCyber Risk Services 
Deloitte's Cyber Risk Services help complex organizations more confidently leverage advanced technologies to achieve their strategic growth, innovation and performance objectives through proactive management of the associated cyber risks. With deep experience across a broad range of industries, Deloitte's more than 1600 practitioners provide advisory and implementation services, spanning executive and technical functions, to help transform legacy IT security programs into proactive Secure.Vigilant.Resilient. cyber risk programs that better align security investments with risk priorities, establish improved threat awareness and visibility, and strengthen the ability of organizations to thrive in the face of cyber incidents.  Cyber Risk Services is part of Deloitte's Advisory Services Practice, which helps organizations create value by taking a strategic risk approach to managing financial, technology and business risks.

About Deloitte's State Government practice
Deloitte has served state governments for more than 48 years, including 47 of the 50 U.S. states, as well as the District of Columbia and Puerto Rico.  With more than 3,400 professionals serving the state government sector, Deloitte focuses on six areas crucial to state governments: health and human services, finance and administration, law and justice, transportation, education, and labor and industry. To learn more, visit http://www.deloitte.com/us/stategovernment or follow us @DeloitteGov.

About NASCIO
The National Association of State Chief Information Officers is the premier network and resource for state CIOs and a leading advocate for technology policy at all levels of government. NASCIO represents state chief information officers and information technology executives from the states, territories, and the District of Columbia. The primary state government members are senior officials who have executive level and statewide responsibility for information technology leadership. State officials who are involved in agency level information technology management may participate as state members. Representatives from other public sector and non-profit organizations may also participate as associate members. Private sector firms may join as corporate members and participate in the Corporate Leadership Council. For more information about NASCIO visit http://www.nascio.org.

As used in this document, "Deloitte" means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

Logo - http://photos.prnewswire.com/prnh/20120803/MM52028LOGO-a

SOURCE Deloitte

Wordcount:  1338

Older

Inside The October Issue Of AARP Bulletin

Advisor News

  • A rising retirement challenge: The license to spend
  • Financial stress leaves less room for retirement saving
  • Giving while you’re living: 3 frequently asked questions about gifting
  • Helping clients prepare for one of their biggest retirement expenses
  • Important year-end financial conversations every advisor must have
More Advisor News

Annuity News

  • A rising retirement challenge: The license to spend
  • What lower interest rates mean to annuity payouts
  • AM Best downgrades A-Cap insurers amid financial and regulatory troubles
  • Lawsuit claims Delaware Life hid billions in insurer-linked investments
  • AM Best to Deliver Presentation at 2026 ACLI Annual Conference
More Annuity News

Health/Employee Benefits News

  • Bailey pushes back on Abbott tax message
  • Commentary: Health coverage for all
  • Healthcare workers see rising insurance costs
  • Norwood Davis, former CEO of health insurance giant Trigon, dies at 86
  • Soaring cost of health insurance also pinching healthcare workers
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Study Results from Cornell University in the Area of Insurance Reported (Regulatory Competition In the Us Life Insurance Industry): Insurance
  • AM Best Comments on Issuer Credit Ratings of Pacific Life Insurance Company’s Commercial Paper Following Amendment to Program
  • AM Best Affirms Credit Ratings of Protective Life Corporation and Its Key Subsidiaries
  • ICICI Life Insurance names Sidharatha Mishra managing director, CEO
  • Lawsuit alleges companies collected $30 million in ‘illegal wager on human life’
Sponsor
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Lauren Sinnott Named to Ragan’s Top Women in Marketing Awards, Class of 2026 
  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.