• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
NewslettersCFO Daily

‘CFOs naturally understand risk’ making them key cybersecurity advocates

Sheryl Estrada
By
Sheryl Estrada
Sheryl Estrada
Senior Writer and author of CFO Daily
Down Arrow Button Icon
Sheryl Estrada
By
Sheryl Estrada
Sheryl Estrada
Senior Writer and author of CFO Daily
Down Arrow Button Icon
July 13, 2021, 5:00 AM ET

Good morning,

The mass ransomware attack earlier this month exploited a flaw in an IT management software system and affected up to 1,500 U.S. businesses. And in May, the Colonial Pipeline cyber attack temporarily stopped fuel supplies across the east coast of the U.S. Cyber attacks will remain a consistent threat, Pam Nigro, vice chair of the board of directors at ISACA, told me. 

“I don’t see it stopping anytime soon,” says Nigro, who is also vice president of information technology and security officer at Home Access Health Corporation. “I think folks know that they’ve gotten a foothold. They’ve gotten rewarded for their bad behavior. And I think that’s going to increase bad behavior.”

ISACA is a global association of IT governance professionals founded in 1969. It has 150,000 members in 188 countries, and 220 chapters worldwide. Although cyber attacks are taking place, there are still companies using patchwork efforts to support technology from the early 2000s that leaves them vulnerable, Nigro says. “Organizations really need to invest in digital transformation to start to get off of these older systems” that expose them to risk, Nigro says. “Not saying new systems are perfect,” but they can be more difficult to infiltrate, she says.  

CFOs need to be engaged in the upgrade of technology and security systems, including providing an understanding of cyber insurance and the related costs, Nigro says. “CFOs naturally understand risk and understand what is acceptable in terms of thresholds for dollars,” she says. Financial leaders “carry that message up to the CEO and ultimately to the board, and help the board understand the level of risk,” Nigro says. 

Many information security and IT professionals around the world actually worry about effectively securing the rapidly rising amount of cloud services and API-centric applications amid digital transformations, according to Fastly. Reaching the Tipping Point of Web Application and API Security, a report released on July 12 by the cloud platform provider, found that outdated offerings are among the main causes for concern. Traditional security tools often block “harmless business traffic,” resulting in 91% of businesses surveyed running the tools in log or monitoring mode, or even turning it off entirely. 

At the same time, the demand for professionals adept in cybersecurity may be greater than the supply. ISACA’s State of Cybersecurity 2021 Part 1 report released in May found that 61% of the 3,600 information security professionals surveyed said their cybersecurity teams are understaffed.

 ISACA is “tool agnostic,” meaning the organization doesn’t “propagate or push any particular” application, or software, for its members to use, Nigro says. “But we really do try to show what are the best practices,” she says. One of the most common ways to share information is through online communities.

However, it’s not enough for just IT leaders and professionals to stay informed about cybersecurity—all employees should have basic knowledge of security measures, Nigro says. 

“If [employees] are not educated, and they don’t understand what a phishing email looks like; if they don’t understand that clicking on a link could misdirect you to someplace else and expose [your system], that is where the troubles really kind of align and really come to fruition,” she says. 

See you tomorrow.

Sheryl Estrada
sheryl.estrada@fortune.com

****

We’re ranking the most influential young people in business. The deadline for 40 Under 40 submissions is July 19. Click here for more information.

Big deal

A new study by Haystack Analytics found that 83% of software developers surveyed have suffered from workplace burnout. Almost half (47%) attributed the stress to increased workload.

Courtesy of Haystack

Going deeper

A new report in Harvard Business Review, Boards Are Undergoing Their Own Digital Transformation, explores how boards in various countries and regions around the world have approached the challenges of the past year. "While 80% of global directors said they believed digital transformation should be led at the board level rather than relegated to the IT department, boards in different regions differed dramatically in terms of follow-through," according to the report. 

Leaderboard

Jonathan D. Alspaugh was named CFO at Aeglea BioTherapeutics, Inc., a clinical-stage biotechnology company. Alspaugh joins Aeglea from Evercore where he most recently served as a managing director in the corporate advisory business.

Andy Schmidt was named CFO at Sientra, Inc., a medical aesthetics company, effectively immediately. Most recently, Schmidt served as the CFO of Guardion Health Sciences.

Overheard

“While some see higher prices as a way to constrain demand, rising costs in the energy sector will only sow greater economic inequality and a world of ‘haves and have-nots.’”

—BlackRock Inc. Chief Executive Officer Larry Fink, in prepared remarks to the Venice International Conference on Climate, as reported by Fortune. 

About the Author
Sheryl Estrada
By Sheryl EstradaSenior Writer and author of CFO Daily
LinkedIn iconTwitter icon

Sheryl Estrada is a senior writer at Fortune, where she covers the corporate finance industry, Wall Street, and corporate leadership. She also authors CFO Daily.

See full bioRight Arrow Button Icon

Latest in Newsletters

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Newsletters

NewslettersMPW Daily
Can Sheryl Sandberg’s Lean In take on tradwives and the manosphere?
By Emma HinchliffeMarch 27, 2026
1 day ago
NewslettersTerm Sheet
VC firms rarely reinvent themselves. Kleiner Perkins did—and has a new $3.5 billion to show for it
By Allie GarfinkleMarch 27, 2026
1 day ago
Abstract business graph of AI growth. market growth, analysis, and future projections.
NewslettersCFO Daily
Why CFOs—not chief AI officers—are the secret to getting real value from AI
By Sheryl EstradaMarch 27, 2026
1 day ago
NewslettersFortune Tech
Anthropic data leak reveals powerful, secret Mythos AI model
By Alexei OreskovicMarch 27, 2026
1 day ago
NewslettersCEO Daily
Chubb’s CEO 25-page shareholder letter touches on China, AI, and the fragility of democracy: ‘I am both optimistic and I’m concerned’
By Diane BradyMarch 27, 2026
1 day ago
Water storage construction on the Meta data center site in Holly Ridge, Richland Parish, Louisiana.
AIEye on AI
Inside Meta’s chaotic AI boomtown in rural Louisiana
By Sharon GoldmanMarch 26, 2026
2 days ago

Most Popular

Success
Meetings are not work, says Southwest Airlines CEO—and he’s taking action by blocking his calendar every afternoon from Wednesday to Friday 
By Fortune EditorsMarch 27, 2026
1 day ago
Personal Finance
Current price of gold as of March 27, 2026
By Fortune EditorsMarch 27, 2026
1 day ago
AI
Exclusive: Anthropic acknowledges testing new AI model representing ‘step change’ in capabilities, after accidental data leak reveals its existence
By Fortune EditorsMarch 26, 2026
2 days ago
Personal Finance
Current price of silver as of Friday, March 27, 2026
By Fortune EditorsMarch 27, 2026
1 day ago
Success
This AI-proof career faces a 250,000-worker shortage—now the Trump administration is trying to revive the job millennials abandoned
By Fortune EditorsMarch 27, 2026
1 day ago
Commentary
The Treasury just declared the U.S. insolvent. The media missed it
By Fortune EditorsMarch 23, 2026
5 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.