Skip to Content
  • オフィス

    オフィス

    北米・南米
    • Atlanta
    • Austin
    • Bogota
    • Boston
    • Buenos Aires
    • Chicago
    • Dallas
    • Denver
    • Houston
    • Los Angeles
    • Mexico City
    • Minneapolis
    • Monterrey
    • Montreal
    • New York
    • Rio de Janeiro
    • San Francisco
    • Santiago
    • São Paulo
    • Seattle
    • Silicon Valley
    • Toronto
    • Washington, DC
    ヨーロッパ・中東・アフリカ
    • Amsterdam
    • Athens
    • Berlin
    • Brussels
    • Copenhagen
    • Doha
    • Dubai
    • Dusseldorf
    • Frankfurt
    • Helsinki
    • Istanbul
    • Johannesburg
    • Kyiv
    • Lisbon
    • London
    • Madrid
    • Milan
    • Munich
    • Oslo
    • Paris
    • Riyadh
    • Rome
    • Stockholm
    • Vienna
    • Warsaw
    • Zurich
    アジア・オーストラリア
    • Bangkok
    • Beijing
    • Bengaluru
    • Brisbane
    • Ho Chi Minh City
    • Hong Kong
    • Jakarta
    • Kuala Lumpur
    • Manila
    • Melbourne
    • Mumbai
    • New Delhi
    • Perth
    • Shanghai
    • Singapore
    • Sydney
    • Tokyo
    全てのオフィス
  • アルムナイ
  • メディア
  • お問い合わせ
  • 東京オフィス
  • Japan | 日本語

    地域と言語を選択

    グローバル
    • Global (English)
    北米・南米
    • Brazil (Português)
    • Argentina (Español)
    • Canada (Français)
    • Chile (Español)
    • Colombia (Español)
    ヨーロッパ・中東・アフリカ
    • France (Français)
    • DACH Region (Deutsch)
    • Italy (Italiano)
    • Spain (Español)
    • Greece (Elliniká)
    アジア・オーストラリア
    • China (中文版)
    • Korea (한국어)
    • Japan (日本語)
  • Saved items (0)
    Saved items (0)

    You have no saved items.

    後で閲読、共有できるようにするためにブックマークしてください

    Explore Bain Insights
  • 業界別プラクティス
    メインメニュー

    業界別プラクティス

    • 航空宇宙、防衛、政府関連
    • 農業
    • 化学製品
    • インフラ、建設
    • 消費財
    • 金融サービス
    • ヘルスケア
    • 産業機械、設備
    • メディア、エンターテインメント
    • 金属
    • 採掘・鉱業
    • 石油、ガス
    • 紙、パッケージ
    • プライベートエクイティ
    • 公共、社会セクター
    • 小売
    • テクノロジー
    • 通信
    • 交通
    • 観光産業
    • 公益事業、再生可能エネルギー
  • 機能別プラクティス
    メインメニュー

    機能別プラクティス

    • カスタマー・エクスペリエンス
    • サステイナビリティ、 社会貢献
    • Innovation
    • 企業買収、合併 (M&A)
    • オペレーション
    • 組織
    • プライベートエクイティ
    • マーケティング・営業
    • 戦略
    • アドバンスド・アナリティクス
    • Technology
    • フルポテンシャル・トランスフォーメーション
  • Digital
  • 知見/レポート
  • ベイン・アンド・カンパニーについて
    メインメニュー

    ベイン・アンド・カンパニーについて

    • ベインの信条
    • 活動内容
    • 社員とリーダーシップ
    • プレス・メディア情報
    • クライアントの結果
    • 受賞歴
    • パートナーシップを結んでいる団体
    Further: Our global responsibility
    • ダイバーシティ
    • 社会貢献
    • サステイナビリティへの取り組み
    • 世界経済フォーラム(WEF)
    Learn more about Further
  • キャリア
    メインメニュー

    キャリア

    • ベインで働く
      キャリア
      ベインで働く
      • Find Your Place
      • ベインで活躍する機会
      • ベインのチーム体制
      • 学生向けページ
      • インターンシップ
      • 採用イベント
    • ベインでの体験
      キャリア
      ベインでの体験
      • Blog: Inside Bain
      • キャリアストーリー
      • 社員紹介
      • Where We Work
      • 成長を後押しするサポート体制
      • アフィニティ・グループ
      • 福利厚生
    • Impact Stories
    • 採用情報
      キャリア
      採用情報
      • 採用プロセス
      • 面接内容
    FIND JOBS
  • オフィス
    メインメニュー

    オフィス

    • 北米・南米
      オフィス
      北米・南米
      • Atlanta
      • Austin
      • Bogota
      • Boston
      • Buenos Aires
      • Chicago
      • Dallas
      • Denver
      • Houston
      • Los Angeles
      • Mexico City
      • Minneapolis
      • Monterrey
      • Montreal
      • New York
      • Rio de Janeiro
      • San Francisco
      • Santiago
      • São Paulo
      • Seattle
      • Silicon Valley
      • Toronto
      • Washington, DC
    • ヨーロッパ・中東・アフリカ
      オフィス
      ヨーロッパ・中東・アフリカ
      • Amsterdam
      • Athens
      • Berlin
      • Brussels
      • Copenhagen
      • Doha
      • Dubai
      • Dusseldorf
      • Frankfurt
      • Helsinki
      • Istanbul
      • Johannesburg
      • Kyiv
      • Lisbon
      • London
      • Madrid
      • Milan
      • Munich
      • Oslo
      • Paris
      • Riyadh
      • Rome
      • Stockholm
      • Vienna
      • Warsaw
      • Zurich
    • アジア・オーストラリア
      オフィス
      アジア・オーストラリア
      • Bangkok
      • Beijing
      • Bengaluru
      • Brisbane
      • Ho Chi Minh City
      • Hong Kong
      • Jakarta
      • Kuala Lumpur
      • Manila
      • Melbourne
      • Mumbai
      • New Delhi
      • Perth
      • Shanghai
      • Singapore
      • Sydney
      • Tokyo
    全てのオフィス
  • アルムナイ
  • メディア
  • お問い合わせ
  • 東京オフィス
  • Japan | 日本語
    メインメニュー

    地域と言語を選択

    • グローバル
      地域と言語を選択
      グローバル
      • Global (English)
    • 北米・南米
      地域と言語を選択
      北米・南米
      • Brazil (Português)
      • Argentina (Español)
      • Canada (Français)
      • Chile (Español)
      • Colombia (Español)
    • ヨーロッパ・中東・アフリカ
      地域と言語を選択
      ヨーロッパ・中東・アフリカ
      • France (Français)
      • DACH Region (Deutsch)
      • Italy (Italiano)
      • Spain (Español)
      • Greece (Elliniká)
    • アジア・オーストラリア
      地域と言語を選択
      アジア・オーストラリア
      • China (中文版)
      • Korea (한국어)
      • Japan (日本語)
  • Saved items  (0)
    メインメニュー
    Saved items (0)

    You have no saved items.

    後で閲読、共有できるようにするためにブックマークしてください

    Explore Bain Insights
  • 業界別プラクティス
    • 業界別プラクティス

      • 航空宇宙、防衛、政府関連
      • 農業
      • 化学製品
      • インフラ、建設
      • 消費財
      • 金融サービス
      • ヘルスケア
      • 産業機械、設備
      • メディア、エンターテインメント
      • 金属
      • 採掘・鉱業
      • 石油、ガス
      • 紙、パッケージ
      • プライベートエクイティ
      • 公共、社会セクター
      • 小売
      • テクノロジー
      • 通信
      • 交通
      • 観光産業
      • 公益事業、再生可能エネルギー
  • 機能別プラクティス
    • 機能別プラクティス

      • カスタマー・エクスペリエンス
      • サステイナビリティ、 社会貢献
      • Innovation
      • 企業買収、合併 (M&A)
      • オペレーション
      • 組織
      • プライベートエクイティ
      • マーケティング・営業
      • 戦略
      • アドバンスド・アナリティクス
      • Technology
      • フルポテンシャル・トランスフォーメーション
  • Digital
  • 知見/レポート
  • ベイン・アンド・カンパニーについて
    • ベイン・アンド・カンパニーについて

      • ベインの信条
      • 活動内容
      • 社員とリーダーシップ
      • プレス・メディア情報
      • クライアントの結果
      • 受賞歴
      • パートナーシップを結んでいる団体
      Further: Our global responsibility
      • ダイバーシティ
      • 社会貢献
      • サステイナビリティへの取り組み
      • 世界経済フォーラム(WEF)
      Learn more about Further
  • キャリア
    人気検索キーワード
    • デジタル
    • 戦略
    前回の検索
      最近訪れたページ

      Content added to saved items

      Saved items (0)

      Removed from saved items

      Saved items (0)

      論説

      Why Cybersecurity is a Strategic Issue

      Why Cybersecurity is a Strategic Issue

      Is your business one hack away from disaster?

      著者:Syed Ali, Vishy Padmanabhan and Jim Dixon

      • min read

      論説

      Why Cybersecurity is a Strategic Issue
      en

      When you think of the billions of dollars organizations spend to protect their digital assets, it’s amazing that hardly a week goes by without news of a major security breach. We see not only more attacks, but larger, more complex and targeted incursions on organizations for financial gain (see Figure 1). Some enterprises face advanced persistent threats (APTs), a highly sophisticated form of malware that permeates the organization, mutates into variants, remains innocuous and undetected for a long time, and stealthily accesses and transmits corporate assets. The sought-after digital assets include intellectual property (IP), trade secrets, and customer and financial data (see Figure 2).


      why-cybersecurity-is-a-strategic-issue-fig-01_embed


      why-cybersecurity-is-a-strategic-issue-fig-02_embed

      Organizations are having a tougher time mitigating security breaches, and the average financial impact of each breach on an organization is increasing (see Figure 3). What’s more, it’s becoming harder to keep these attacks out of the news. Often, clients or regulatory agencies require companies to disclose breaches; in other cases, attackers themselves distribute the pilfered information online. In many cases, the consequences for organizations can be devastating in terms of lost revenue, impugned reputations and financial repercussions.

      For example, an October 2013 attack on Adobe resulted in the theft of customer data from 38 million accounts and of valuable source code behind some of Adobe’s most widely used products, including Reader, PhotoShop and ColdFusion.

      The immediate consequences for a company dealing with a customer data breach are severe and may include negative press, sales and stock price decline (at least immediately after the breach), the threat of lawsuits from customers and partners, and long legal investigations. When attackers gain access to the source code of software products, they can find and exploit new vulnerabilities (so-called zero-day attacks) that could affect corporate and customer systems, data and devices.


      why-cybersecurity-is-a-strategic-issue-fig-03_embed

      Only two months later, in December 2013, Target Corporation confirmed that it suffered a massive security breach resulting in the loss of credit and debit card data on 40 million customers over a 19-day period. The data may have been harvested by malware affecting physical point-of-sale systems at nearly 2,000 Target stores.

      With stakes so high, CEOs and boards must begin to think about security in a new way. IT security—a task that could once be delegated to the IT staff—has become a top-level strategic issue because the consequences of failure can ruin a business. Any organization may be only a few hacks away from disaster.

      And yet, every organization that found itself on the wrong end of a security breach already had some form of cybersecurity in place. The names in recent headlines include banks, technology and media companies, retailers, research universities as well as security agencies—none of which are new to the game of protecting information. So how is it that they found themselves ill-equipped to deal with the rising tide of threats?

      In our experience working with many leading enterprises on this important and sensitive issue, we see too many organizations that fail to align their IT security capabilities with their larger goals and appetite for risk. At some companies, business and IT don’t discuss emerging threats or the relative importance of different classes of digital assets. Not surprisingly, we frequently see disconnects between an organization’s risk-management efforts and the development of necessary cybersecurity capabilities. And too often, we see fits and starts, as teams take an inconsistent approach to security planning, operations and funding. Taken together, these mistakes create gaps in strategy and operations that leave the organization vulnerable.

      New challenges for cybersecurity

      Cybersecurity has never been more essential, for at least four major reasons. First, companies have more digital assets than they did 10 years ago, and these assets are worth more than they were before. They include customers’ personal, financial and transaction information; proprietary assets, including source code for products; automated business processes; sensitive communications with suppliers and partners; and other data. The security around these assets varies greatly depending upon the perceived (as opposed to the actual) financial and strategic value to the business, as well as the effectiveness of the security technologies and processes in place.

      What’s more, organizations are shifting to hybrid cloud architectures as they continue to adopt software, security and other solutions as services (SaaS, SECaaS and so on). Historically, digital assets were protected within the company’s data center, where it was easier to guard the perimeter and manage user access, authorization and authentication from known locations and devices. Today, corporate and customer data resides in the organization’s own data centers as well as public and private clouds, distributed across remote locations. While hybrid cloud architectures offer significant economic benefits, their adoption requires a more sophisticated approach to cybersecurity, including security management at the level of individual digital assets and integrated monitoring and management capabilities across the hybrid cloud environment.

      Further complicating the challenge is the pervasive use of mobile devices by staff and executives. Corporate IT now has to manage the security of many more platforms and devices, some owned by the company and others that belong to employees who use them under bring-your-own-device (BYOD) plans. A recent survey by ISACA1 found that up to 66% of organizations will soon adopt BYOD policies, yet half of IT staff members remain concerned about the inherent security risks. To manage these policies effectively, IT organizations will need to provide ubiquitous security across many devices and comprehensively manage user identity and access to sensitive corporate data.

      Finally, compliance remains the most important cybersecurity driver, especially for companies in regulated industries or with contractual obligations. In a recent Bain survey, more than 75% of CIOs identified compliance requirements as the main determinant of investment in IT security. Another recent survey of IT staff by ISACA found that outside of compliance obligations, IT has insufficient resources and limited business engagement for effective risk management.2 These findings highlight the operational approach to cybersecurity taken by many organizations. Compliance should define the lower bound for security capabilities while the upper bound should aspire to meet the organization’s strategic priorities, including IP protection, continuous operations and a secure corporate reputation.

      Protecting your data, reputation and business

      Leading organizations take a more strategic rather than an operational approach to security to respond to the new challenges.

      • Understand the organization’s key assets and appetite for risk. Align business and IT leaders on the prioritization of digital assets based on value and risk to the organization to ensure the proper design of technology, processes and supporting resources. For example, customer data, point-of-sale and order management systems are a higher priority while marketing and promotion systems may be lower.
      • Identify the security risks and gaps. Assess current security capabilities and determine the likelihood of experiencing known and emerging risks. Business and IT leaders should then align on the gaps and the estimated mitigation costs.
      • Define the cybersecurity strategy. Based on a thorough understanding of the organization’s security priorities and gaps, IT should create comprehensive technology, process and organizational designs and blueprints with strategic and operational elements that protect digital assets (see Figure 4).
      • Emphasize gaps, priorities and strategy to the CEO and board. Leadership should know about the security-related risks and gaps they face, so they can understand the importance of the investments required.
      • Engage recognized security specialists. As the threat landscape expands and attacks become more sophisticated, organizations should work closely with firms that can provide ongoing services to diagnose, redesign and monitor their cybersecurity.

      why-cybersecurity-is-a-strategic-issue-fig-04_embed

      Syed Ali is a principal with Bain & Company in Chicago. Vishy Padmanabhan is a partner with Bain & Company in Dallas. Jim Dixon is a partner in Bain’s Palo Alto office. All three work with Bain’s Global Information Technology practice.

      1 ISACA: 2013 IT Risk/Reward Barometer – Global Results

      2 ISACA: 2012 Study on Application Security


      why-cybersecurity-is-a-strategic-issue-fig-01_full

      why-cybersecurity-is-a-strategic-issue-fig-02_full

      why-cybersecurity-is-a-strategic-issue-fig-03_full

      why-cybersecurity-is-a-strategic-issue-fig-04_full
      著者
      • Headshot of Syed Ali
        Syed Ali
        パートナー, Houston
      • Vishy Padmanabhan
        Former Partner, New York
      • Headshot of James Dixon
        James Dixon
        Alumni, Silicon Valley
      関連業種
      • Cybersecurity
      関連するコンサルティングサービス
      • IT
      IT
      The new CIO's quick-start manual

      For a new CIO, learning to strike the right balance between addressing old problems and creating new capabilities is critical not only to survive but also thrive in a tough job.

      詳細
      IT
      Big Data: The Organizational Challenge

      If you don't know who (and where) your chief analytics officer is, you may already be behind the curve.

      詳細
      テクノロジー
      How to Keep Control of an IT System That's Outsourced to Multiple Suppliers

      To master increasingly complex IT, companies are turning to multiple suppliers. But that strategy creates another risk: loss of control over mission-critical functions.

      詳細
      Cybersecurity
      Quantum Computing Moves from Theoretical to Inevitable

      Quantum will likely become part of a mosaic, working with classical computing to solve big problems.

      詳細
      IT
      How Businesses Can Prepare for Post-Quantum Cybersecurity Threats

      Your company will soon face attackers armed with quantum technology. Will you be ready?

      詳細
      First published in 2月 2014
      Tags
      • Cybersecurity
      • IT

      クライアント支援事例

      Digital A European Banking Giant Rises to the Fintech Challenge

      ケーススタディを見る

      Digital How a Data-Driven Mindset Powers McAfee’s Growth

      ケーススタディを見る

      IT Salvaging a Technology Outsourcing Deal Gone Bad

      ケーススタディを見る

      お気軽にご連絡下さい

      私達は、グローバルに活躍する経営者が抱える最重要経営課題に対して、厳しい競争環境の中でも成長し続け、「結果」を出すために支援しています。

      ベインの知見。競争が激化するグローバルビジネス環境で、日々直面するであろう問題について論じている知見を毎月お届けします。

      *プライバシーポリシーの内容を確認し、合意しました。

      プライバシーポリシーをご確認頂き、合意頂けますようお願い致します。
      Bain & Company
      お問い合わせ Sustainability Accessibility Terms of use Privacy Cookie Policy Sitemap Log In

      © 1996-2026 Bain & Company, Inc.

      お問い合わせ

      How can we help you?

      • ビジネスについて
      • プレス報道について
      • 採用について
      全てのオフィス