Cyber and privacy leaders' agenda

Cyber and privacy leaders must act now to tackle today’s most pressing security challenges.

Join the conversation 



 Linked in twitter

The COVID-19 crisis has been a wake-up call for CISOs. The business has looked to the cybersecurity team to protect it from an evolving cyber threat, while enabling urgent technology transformation and new growth.

Now more than ever, you need to get your strategies and priorities right. Here's how in four steps:  

  • Reassess your alignment with the business

    Cybersecurity teams have traditionally been strongest when it comes to assessing their capabilities, identifying risk, and building roadmaps for the future. CISOs should focus attention on the elements of cybersecurity where many have been weaker in the past. Specifically, they should look to strengthen their engagement with stakeholders, ensure their alignment to core business goals and objectives, and assess their business partners’ satisfaction with the performance and delivery of security services.

    As their relationships with business partners have deteriorated in recent years, CISOs may now lack the visibility they need to operate in sync with other functions and pursue a strategy that aligns with the business. Explore next steps for CISOs in the articles below.

    Cybersecurity: How do you rise above the waves of a perfect storm?

    The EY Global Information Security Survey 2021 finds CISOs and security leaders battling against a new wave of threats unleashed by COVID-19.

    22 Jul 2021 EY Global

    Why cybersecurity could be the missing link to growth

    In the wake of the pandemic, CISOs can reposition themselves as enablers of growth. But early findings from the latest EY Global Information Security Survey suggest they must first overcome four deep-seated barriers.

    20 May 2021 EY Global

    How next-generation CISOs can become agents of change

    Forward-looking CISOs are pursuing a new role, building stronger cross-functional relationships to support innovation and transformation.

    22 Jan 2020 EY Global

  • Review your talent profile

    To respond to the organizational challenges highlighted by EY research, as well as the sophisticated nature of recent high-profile attacks, CISOs need the support of versatile, multi-skilled professionals.

    However, the breadth of skills needed in today’s function is expanding in several directions at once. There is no such thing as a “standard” cybersecurity profile. CISOs need individuals with advanced technical skills, as well as the ability to build interdepartmental relationships. 

    We outline in this article some of the many cybersecurity executive profiles that have emerged in recent years, despite the profession’s relative newness. Each profile has its own area of focus, relies on its own range of soft skills and professional qualifications, and plays an important role in meeting the changing needs of the business.

    Cybersecurity: How do you rise above the waves of a perfect storm?

    The EY Global Information Security Survey 2021 finds CISOs and security leaders battling against a new wave of threats unleashed by COVID-19.

    22 Jul 2021 EY Global

    How do you see more clearly when cyber threats cross boundaries?

    Chief information security officers across Europe should focus on four areas to shift from protecting data to enabling transformation and growth

    11 Jun 2021 Mike Maddison

  • Focus on four key stakeholder groups

    CISOs are familiar with the principle of “shifting left,” striving to involve cybersecurity earlier on in the transformation and product development lifecycle. The challenges of COVID-19 indicate, however, that shifting left is no longer all that is required. Our suggestion to CISOs is that they shift north, east, south, and west. In practice, this means navigating four key stakeholder groups.

    Addressing the concerns of management, at “north,” means focusing on reporting and accountability, as well as budgeting and resource allocation. Shifting the focus “east,” to regulators, is a case of prioritizing certifications and attestations, along with regulatory mapping. Shifting south is about enhancing standards and testing. And shifting west involves focusing on security and privacy by design, along with certifications and continuous testing.

    If CISOs can position themselves in the center of these four vital stakeholders, they will be in the right place to take their function to the next level of strategic influence.

    Cybersecurity: How do you rise above the waves of a perfect storm?

    The EY Global Information Security Survey 2021 finds CISOs and security leaders battling against a new wave of threats unleashed by COVID-19.

    22 Jul 2021 EY Global

    How CIOs can put humans at the center of their agendas

    As CIOs drive technology transformation within the organization, working with the CHRO to put humans at the center of change is vital.

    2 Dec 2021 Kok Yong Lee

    Why the CIO and CMO must collaborate to drive business transformation

    The CIO and CMO must work together to better identify, understand and serve the customer —the highest priority for any business.

    30 Apr 2021 Janet Balis

  • Build a strong culture of Security by Design

    In the best of times, security is introduced into a digital transformation program late in the process – generally as a compliance item. With inevitable changes associated with greater use of cloud services, third-party outsourcing of core business functions, and/or reduction of internal staff, it is critical that the security team is introduced into the discussion as a business risk function.

Despite ongoing uncertainty over budgets, EY research reveals that leaders expect to invest in the following areas:

  • Identity and access management

    The shift to remote working during the COVID-19 pandemic brought the importance of robust identity and access management (IAM) practices firmly into the spotlight. It has become an integral pillar of an organization’s security infrastructure as the business demands better access controls in a less controlled network environment with shared platforms.

    The increased use of personal devices and remote access to core business systems increases the threat landscape of businesses. However, adoption of new IAM controls and processes will mitigate the cyber risks and threats for organizations.

    What can security leaders do now, next and beyond?
    1. Now – solve the current crisis
      Perform an impact assessment of remote working, IAM processes, and secure access to critical and non-critical applications. Support contingency programs including IAM process simplification and work-arounds, and re-organize IAM operations to accelerate execution and monitoring of remote and privileged access.
    2. Next – steps for year-round
      Assess the appropriateness of remote access by critical/non-critical application, and review the revised access controls with your compliance teams. Also gain buy-in from your compliance team for simplified procedures, including access to business applications.
    3. Beyond – resiliency and risk management
      Enhance your IAM capability through improved contingency processes, awareness, reporting, technology and collaboration.
    How do you switch trajectory at speed when you’re under threat?

    There's a long list of organizational vulnerabilities for CISOs to contend with, but some practical steps can help mitigate these.

    6 Aug 2020 EY Global

    COVID-19: How future investment in cybersecurity will be impacted

    The COVID-19 crisis is elevating the importance and value of security leaders and teams.

    23 Jul 2020 EY Global

  • Data protection and privacy

    It is well understood that privacy needs to evolve. This is driven by technological developments as well as changes in societal attitudes and perceptions – ordinarily rooted in national and cultural factors – which are highly reactive to the perception of peripheral events. 

    Now, in the midst of the COVID-19 pandemic, we must ask ourselves … what happens next? Have consumer perceptions of privacy fundamentally changed? Have our perceptions about trustworthiness of government and business shifted? Is there an opportunity for governments and businesses to redefine approaches to collection and use of personally identifiable information (PII) moving forward?

    How to balance using data as an asset with privacy and security risks

    Realizing the true value of data requires a shift in mindset and the integration of data risk into enterprise risk management frameworks.

    26 Apr 2021 Jennifer Allermann

    Has lockdown made consumers more open to privacy?

    Findings from the EY Global Consumer Privacy Survey reveal that the pandemic is shifting consumers’ expectations of data privacy.

    23 Nov 2020

    How to successfully embed a culture of Privacy by Design

    Protecting personal data, and how it is gathered, stored and used has taken on a new urgency as a result of fast emerging technologies.

    20 Oct 2020 EY Global

  • Co-sourcing and outsourcing

    Cybersecurity is increasingly diverse and complex and is now a critical function to enterprise risk management, requiring constant proper due care. The COVID-19 pandemic has demonstrated the negative impact of rapid operational disruption. The need to temporarily redirect internal resources, to meet a surge in certain areas or obtain specialized resources, can make adding an outsourcing partner to your strategy a sound component to your business risk management efforts.

    At minimum, seeking help with critical cybersecurity operational functions, such as cyberthreat detection and response or identity and access management, might be the right decision.

    How managed services can accelerate business transformation

    As operating challenges intensify, a managed services approach to critical functions can deliver better business outcomes and drive growth.

    10 Oct 2023 Paul Clark

    COVID-19: How future investment in cybersecurity will be impacted

    The COVID-19 crisis is elevating the importance and value of security leaders and teams.

    23 Jul 2020 EY Global

CISOs call for more funding

39% of CISOs warn their organization’s budget is below what is required to manage the new challenges that have arisen in the last 12 months.

Read more

Case study: creating a smarter, safer grid for new meters

EY teams are helping a national electricity company reinforce its legacy power infrastructure for a trusted, cyber-safe future.

Read more


detail electricity meter
Young woman using laptop at dawn above the city, Barcelona, Spain

How technology fights FinCrime while enhancing regulatory compliance

EY enabled a large global bank to lead the fight against FinCrime in a way that also helped it improve efficiency and increase compliance.

Read more

Industry insights

woman walking along the road to the mountains

Transformation Realized™

Consulting at EY is building a better working world by realizing business transformation through the power of people, technology and innovation.


Discover more

Contact us

Like what you’ve seen? Get in touch to learn more.