<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic More investment needed in CyberSecurity in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/More-investment-needed-in-CyberSecurity/m-p/60866#M911</link>
    <description>&lt;P&gt;For many years&amp;nbsp;New Zealand has believed it is shielded from main security and privacy issues because it isn't the subject of mandatory reporting i.e. legislation.&lt;/P&gt;&lt;P&gt;Some protection is provided in business for external threats but not for a high degree of security.&lt;/P&gt;&lt;P&gt;This continues to undermine the efforts of the security team to ensure cohesive and effective security controls.&lt;/P&gt;&lt;P&gt;Small business are investing but in a way that suggests they underestimate the issues around CyberSecurity as in this report from 2020.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&amp;amp;objectid=12363068" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&amp;amp;objectid=12363068&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fast forward to 2023 and the same issues exist with a threat of Security staffing being reduced due to financial pressures post Covid.&amp;nbsp; Many small businesses share a security manager and rely on outsourced IT operations which may not even reside in New Zealand.&lt;/P&gt;&lt;P&gt;More investment is being made but there are only a finite number of experienced security professionals in the country and some are likely to migrate to better employment in e.g. Australia.&lt;/P&gt;&lt;P&gt;Also compliance with required legislation in the country and binding financial requirements such as PCIDSS are still not being met despite having been established since 2004.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://securitybrief.co.nz/story/more-action-needed-to-plug-critical-gaps-in-cybersecurity" target="_blank"&gt;https://securitybrief.co.nz/story/more-action-needed-to-plug-critical-gaps-in-cybersecurity&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 10:38:15 GMT</pubDate>
    <dc:creator>linzeeb</dc:creator>
    <dc:date>2023-10-09T10:38:15Z</dc:date>
    <item>
      <title>More investment needed in CyberSecurity</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/More-investment-needed-in-CyberSecurity/m-p/60866#M911</link>
      <description>&lt;P&gt;For many years&amp;nbsp;New Zealand has believed it is shielded from main security and privacy issues because it isn't the subject of mandatory reporting i.e. legislation.&lt;/P&gt;&lt;P&gt;Some protection is provided in business for external threats but not for a high degree of security.&lt;/P&gt;&lt;P&gt;This continues to undermine the efforts of the security team to ensure cohesive and effective security controls.&lt;/P&gt;&lt;P&gt;Small business are investing but in a way that suggests they underestimate the issues around CyberSecurity as in this report from 2020.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&amp;amp;objectid=12363068" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&amp;amp;objectid=12363068&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fast forward to 2023 and the same issues exist with a threat of Security staffing being reduced due to financial pressures post Covid.&amp;nbsp; Many small businesses share a security manager and rely on outsourced IT operations which may not even reside in New Zealand.&lt;/P&gt;&lt;P&gt;More investment is being made but there are only a finite number of experienced security professionals in the country and some are likely to migrate to better employment in e.g. Australia.&lt;/P&gt;&lt;P&gt;Also compliance with required legislation in the country and binding financial requirements such as PCIDSS are still not being met despite having been established since 2004.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://securitybrief.co.nz/story/more-action-needed-to-plug-critical-gaps-in-cybersecurity" target="_blank"&gt;https://securitybrief.co.nz/story/more-action-needed-to-plug-critical-gaps-in-cybersecurity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:38:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/More-investment-needed-in-CyberSecurity/m-p/60866#M911</guid>
      <dc:creator>linzeeb</dc:creator>
      <dc:date>2023-10-09T10:38:15Z</dc:date>
    </item>
  </channel>
</rss>

