• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
CommentaryCybersecurity

How corporate America can fight cybersecurity threats

By
Bob Moritz
Bob Moritz
and
David Burg
David Burg
Down Arrow Button Icon
By
Bob Moritz
Bob Moritz
and
David Burg
David Burg
Down Arrow Button Icon
February 17, 2015, 12:07 PM ET
To match BREAKINGVIEWS-EMC/SECURITY
RSA SecureID electronic keys are pictured in a photo illustration taken in Singapore June 8, 2011. This may go down as the year of the hack, with Sony and Amazon among the targets. But the compromising of information on almost 40 million RSA security tokens, which protect sensitive military and financial networks, may be the most serious instance. Cybersecurity efforts - and spending - suddenly look inadequate. RSA is the security division of EMC. To match BREAKINGVIEWS-EMC/SECURITY REUTERS/Michael Caronna (SINGAPORE - Tags: BUSINESS SCI TECH) - RTR2NFFEPhotograph by Michael Caronna — Reuters

Last week, President Obama, business leaders, consumer and privacy advocates, and law enforcement officials gathered for a summit at Stanford University to talk about cybersecurity. This conversation is long overdue. By any measure, cybersecurity is the biggest common threat organizations face. It is also the one where we see the largest gap between threat and preparedness. While companies are devoting significant resources to the problem, they must recognize that playing catch-up is inherent to tackling the problem.

While last year’s data breaches might have received plenty of attention —from corporate and celebrity hacks to government penetrations — cybersecurity has been a problem for several years now. For companies, these breaches cause strategic setbacks, harm business operations, affect their customers, and take profits directly from the bottom line.

U.S. CEOs now understand this. In PwC’s 18th Annual CEO Survey, 90% of U.S. CEOs say cybersecurity is strategically important, 87% are concerned about cyber threats, and 45% are extremely concerned about them. Knowing that a problem exists is only half the battle; fixing that problem is the other half.

And in this case, it’s particularly hard. One of the most vexing aspects of cyber threats is that they are constantly evolving. Organized criminals, hacktivists, and some nation states are almost always developing new techniques and tools. As Lisa Monaco, assistant to the president for Homeland Security and Counterterrorism, explained at Stanford last Friday, “We face more attacks, more methods, more actors, and more victims, and no one is immune.”

This is why it is so important for businesses to combine vigilance with preparedness and action.

So what are the principal steps companies can take?

First, they must prioritize this issue from the top down and from the bottom up. It is not enough for CEOs, CFOs, CIOs, and other key officers and employees to engage; we need boards of directors to do so from a governance perspective. Oversight is always important, but cybersecurity is becoming such a strategic imperative that just as companies seek outside expertise for legal and financial matters, they should now be looking for experts in cybersecurity and data privacy.

From the bottom-up perspective, employee training and awareness are essential because the weakest link is often human error (and understandably so). Companies should invest in employee security-training programs. To keep their data and networks safe, it is essential to arm even the most junior employees with the tools they need to contribute.

Second, companies must recognize that minimizing their risks requires a holistic approach — technology is not enough. When asked what technological capabilities were strategically important to their organization, 75% of U.S. CEOs said cybersecurity was very important, according to PwC’s CEO Survey.

However, companies must also address the non-technological tools of cybersecurity. For example, current and former employees are the most frequently-cited culprits in cyber breaches. That’s why companies at the forefront of tackling the problems are going beyond a compliance checklist approach to an information security approach. They are developing broader data governance policies and practices to protect sensitive information. Thus, rather than key in on defending themselves from external threats, these companies are developing and implementing policies for the creation, use, storage, and deletion of information.

The leading U.S. banks, many of the largest defense contractors, and many other companies in technology, transportation, pharmaceuticals, as well as other industries, are also addressing the fact that breaches via third-party partners are on the rise. Consequently, they are establishing security standards for third parties, performing risk assessments, monitoring for adherence to policies, and enforcing those policies.

Third, the private and public sectors must come together and address the cybersecurity challenge. When asked about the impact of collaboration among government and businesses on working closer together on cybersecurity strategies, only 34% of U.S. CEOs said they were seeing changes in international policies and regulations; 50% said they did not see any changes. This needs to change, and will only do so if both sides work together. As the CEO of eBay John Donahoe told us, “When you step back and look at the role of a company versus the role of a government, clearly if we’re going to provide the safest possible [customer] experience in [the] aggregate, government and companies need to work together.”

One thing is certain—regulatory compliance alone is not enough to address the cybersecurity challenge that America faces today. Companies must keep their processes up-to-date, train personnel, and use tools to detect, analyze, and respond to incidents. They must work together with the government and non-governmental organizations to find the right policies and strategies to protect organizations and citizens from hacks and other cyber threats.

Bob Moritz is chairman of PricewaterhouseCoopers and David Burg is the leader of PwC’s cybersecurity practice.

About the Authors
By Bob Moritz
See full bioRight Arrow Button Icon
By David Burg
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

gen z
CommentaryGen Z
Gen Z is using ChatGPT to practice salary negotiations and tough conversations before they happen
By Phillip MillerMarch 22, 2026
14 hours ago
world
CommentaryCapitalism
Our economy has been living in an Adam Smith world since 1776. Something different is coming
By Ravi ChaudhryMarch 22, 2026
15 hours ago
david
CommentaryScience
The one skill that separates people who get smarter with AI from everyone else
By David Rock and Chris WellerMarch 21, 2026
2 days ago
war
CommentaryMiddle East
Companies are now on the front lines of war. They need to act like it
By Jeremy BashMarch 21, 2026
2 days ago
powell
CommentaryFederal Reserve
The Strait of Hormuz is the fourth large supply shock this decade. Welcome to the new era of global disorder
By Jon HilsenrathMarch 21, 2026
2 days ago
gen z
CommentaryCareers
The entry-level job market is the worst it’s been in 37 years. Stop blaming Gen Z
By Janelle Jones and Nia LawMarch 21, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.