Check Point Research revealed that the number of global cyberattacks in Q3 2024 increased by a staggering 75% compared to 2023. At the same time, a Commvault survey found that just 13% of global organizations are considered ‘cyber mature’ despite the continuing rise in threats. Given the rapid growth and evolution in cyberattacks, these are concerning statistics.
Cyber mature organizations can recover from an attack 41% faster than those companies at the lowest end of the scale, thanks to several key resilience markers. These explain why some companies could restore data quickly and resume business as usual while others couldn’t.
Top of the priority list for organizations looking to improve their cyber resilience are security tools, which provide early warning alerts using preset runbooks, roles, and processes. Also critical is an isolated stable, clean, dark-site or secondary backup solution to store vital immutable data. Regular testing of cyber recovery procedures to keep them up-to-date is another key resilience marker. However, the onus is on the CISO to make these things happen so how does the CISO role tend to develop alongside cyber resilience maturity?
Measuring CISO maturity
CISOs exist to defend operations from cyberattacks, however, their authority can vary, with a direct impact on the overall cyber maturity of an organization. The least mature CISOs are acting on the orders of seniors while those at the other end of the scale are engaging with the board to guarantee that cybersecurity is integrated across the business. This maturity cycle can be broken into five phases:
Box-tickers
In the least developed companies, mainly small, private organizations, security leaders are rarely policy makers and usually do not have a dedicated CISO role. Instead, cybersecurity is managed by the IT department, which reports into an IT director or CIO. Daily routines, such as patching software upgrades, configuring servers, and setting up laptops act as way to also handle cybersecurity at a low level.
For these companies, other priorities, such as sales, leave cybersecurity overlooked. As a result, key safeguards like multi-factor authentication, might not be deployed because they are seen as a hindrance and annoyance. Thus, cybersecurity is downgraded to a mere check box exercise.
Introducing the CISO
As an organization expands so does its attack surface, becoming a bigger target for malicious actors. An increase in employees, customers, and suppliers, with more processes and applications, means more exploitable vulnerabilities. This is when cybersecurity begins to climb the board’s agenda and they start to consider a dedicated senior cybersecurity leader or CISO.
At this point, the role is largely a technical post with the CISO expected to spend time working with the development team rather than planning and executing a company-wide cyber strategy. This is also when compliance demands become more important with a need to deploy formal monitoring and auditing solutions. IT and security must build clear security channels with mutually agreed objectives to prevent gaps from appearing.
Beyond the technical CISO
It soon becomes clear that the CISO must have the authority to assess and implement security controls and processes across the company. While the CISO should already be responsible for defending, detecting, and recovering from attacks, they should also be able to deploy more wide-ranging procedures to protect cloud systems or ensure control via access management solutions.
While some senior executives might complain about such measures slowing down time to market, this is the point where leaders must support the CISO and the roll out of vital new cybersecurity projects.
Empowering the CISO
When a company reaches full maturity, the CISO is engaging in strategic planning with the board, inputting on cybersecurity risks, resilience, and recovery. In collaboration with the leadership, the CISO should establish the company’s risk tolerance levels and supply analysis to show any changes in the risk profile with policies in place to stay within agreed levels.
With this degree of maturity, CISOs are also consulting on the benefits and drawbacks of emerging technologies, such as AI, making cybersecurity a foundational part of strategic planning.
Security by design
For organizations at the final maturity stage, security is woven tightly into the fabric of the business, with employees expected to follow strict security processes and policies. At this point, cybersecurity is baked into the foundations of the organization, informing every aspect of business. Continuous testing and monitoring of corporate systems is par for the course and security teams are well-versed in incident response and data recovery.
Planning for maturity
Every company has its own unique IT infrastructure, security policies, and strategic objectives, depending on size, leadership, public or private status, and so forth. Therefore, calculating the progress through the cybersecurity maturity cycle is not simple. However, by understanding each stage’s characteristics, leaders can more robustly align the development of internal candidates or find the right external equivalent. This will assist in the development of cyber maturity to match the company’s risk tolerance levels and leave it well positioned to withstand the ongoing wave of attacks.
More details on Commvault’s 5 Proven Resiliency Markers of Cyber-Ready Organizations






