GRC leaders lack confidence in security data they provide to regulators
LONDON and NEW YORK, Sept. 23, 2020 /PRNewswire/ -- Senior risk and compliance professionals within financial services company's lack confidence in the security data they are providing to regulators, according to Panaseer's 2020 GRC Peer Report. Results from a global external survey of over 200+ GRC leaders* reveal concerns on data accuracy, request overload, resource-heavy processes and lack of end-to-end automation.
The results indicate a wider issue with cyber risk management. If GRC leaders don't have confidence in the accuracy and timeliness of security data provided to regulators, then the same holds true for the confidence in their own ability to understand and combat cyber risks.
Less than half (41%) of risk leaders feel 'very confident' that they can fulfil the security-related requests of a regulator in a timely manner. Just over a quarter (27.5%) are 'very satisfied' that their organization's security reports align to regulatory compliance needs.
GRC leaders cited their top challenges in fulfilling regulator requests, as:
- Getting access to accurate data (35%)
- The number of report requests (29%)
- The length of time it takes to get information from security team (26%)
The issue has been perpetuated by the limitations of traditional GRC tools, which rely on qualitative questionnaires to provide evidence of compliance. This does not reflect the current challenges from cyber. 92% of senior risk and compliance professionals believe would be valuable to have quantitative security controls assurance reporting (vs qualitative) and 93.5% believe it's important to automate security risk and compliance reporting. However, only 11% state that their risk and compliance reporting is currently automated end to end.
96% said it is important to prioritize security risk remediation based on its impact to the business, but most can't isolate risk to critical business processes composed of people, applications, devices. Only a third (33.5%) of respondents are 'very confident' in their ability to understand all the asset inventories.
Charaka Goonatilake, CTO, Panaseer: "Faced with increasing requests from regulators, GRC leaders have resorted to throwing a lot of people at time-sensitive requests. These manual processes combined with lack of GRC tool scalability necessitates data sampling, which means they cannot have complete visibility or full confidence in the data they are providing. The challenge is being exacerbated by new risks introduced by IoT sensors and endpoints, which rarely consider security a core requirement and therefore introduce greater risk and increase the importance of controls and mitigations to address them."
Andreas Wuchner, renowned GRC leader and Panaseer Advisory Board member: "To face the new reality of cyberthreats and regulatory pressures requires many organizations need to fundamentally rethink traditional tools and defences. GRC leaders can enhance their confidence to accurately and quickly meet stakeholder needs by implementing Continuous Controls Monitoring, an emerging category of security and risk, which has just been recognised in the 2020 Gartner Risk Management Hype Cycle."
To read Panaseer's full 2020 GRC Peer Report, please visit: https://panaseer.com/reports-papers/report/2020-grc-peer-report/
* 200+ senior risk and compliance professionals (including Chief Compliance Officers, VPs of GRC, VPs of Compliance and Heads of Compliance) working in companies within the financial services industry with 5,000 – 25,000 employees in the UK and US, were surveyed by Censuswide in 2020.
Panaseer is the first Continuous Controls Monitoring platform for enterprise security. It helps businesses make informed risk-based security decisions. The company is aiming to become the security measurement platform of choice for security, risk and IT leaders that are shifting to data-driven programmes.
Established in 2014 by Nik Whitfield – a thought leader with extensive cyber-security and FinTech experience. Panaseer's clients include the world's largest financial institutions and critical infrastructure enterprises.
Panaseer recently scooped the award for 'Best Regulatory Compliance Tools and Solutions' at the SC Awards Europe. Last year it was named Europe's Hottest CyberTech Startup at the Europa awards, which is held in partnership with TechCrunch. Its total funding to date is $15.6 million and its backers include Evolution Equity Partners, Notion Capital, Albion Capital, Winton Ventures, Paladin Capital Group and Cisco Investments.
For more information: www.panaseer.com