APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Wynyard Group

Michael Wallmannsberger, Chief Information Security Officer

The Organization's Responsibility for its Own Protection

Michael Wallmannsberger

Michael Wallmannsberger

A CISO’s job is to enable his or her organisation to execute the CEO’s strategy, within the CFO’s budget and the board’s appetite for risk. A high tolerance for risk, a large budget, and modest strategic goals make for light work.

However, most organisations face a different reality. Resources are scarce, goals are ambitious, and tolerance for risk is moderate at most. This leaves CISOs searching to find value in a crowded technology market somewhat prone to hype or, worse, leaves their organisations bearing unknown or unquantified risk.

In larger organisations and markets, managed security service providers (MSSPs) and security operations centres (SOCs) commonly take on the burden of monitoring organisations’ security systems for events that are relevant. These providers are not all created equal. However, an effective security service provider can provide customer organisations with efficient 24x7 access to operational security skills that the organisations would find it difficult to justify retaining in their own right. Mid-size organisations, in particular, stand to benefit from quality MSSP offerings.

There are a wide range of security services being offered by MSSPs today, from full outsourcing of security programmes to specialised services that focus on specific components of the enterprise’s security (such as threat monitoring, data protection, management of network security tools, regulatory compliance, or incident response and penetration testing). By outsourcing security, enterprises are often able to realise cost savings by eliminating the need to maintain a fully staffed, full-time, on-site IT security department. Many organisations also turn to MSSPs for faster deployment times and improved time-to-value on security investments.

“Organisations turn to MSSPs for faster deployment times and improved time-to-value on security investments”

Much has been said about cybersecurity since it became a popular topic. The one thing that almost everyone seems to agree is that cybersecurity is now a strategic business issue. Thinking about security as purely an IT issue is quite wrong. In the same way, a MSSP or SOC provider is not a complete answer to cybersecurity. Organisations cannot outsource responsibility for their business risk and outcomes. However, a service model is also emerging to provide advice about cybersecurity issues to businesses as a service, to substitute for or augment inhouse expertise. As demand for the experienced practitioners continues to outstrip supply, these services— sometimes called virtual CISO, CISO as a service, or shadow CISO—look set to grow.

The outsourcing of IT security must involve an in-depth discovery process. Organizations’ need to understand the risk profile associated with their operating model and be able to quantify their exposure in order to make sensible decisions on scope and cost of any potential service. It is not a decision to be solely based on price and cost.

Choosing an expert to help with a complex problem is not always easy and, whether it is a MSSP or a virtual CISO that your organisation needs, the usual makers of quality and assurances may not be present in the relatively immature cybersecurity industry.

Organisations should undertake careful due diligence on security-asa-service providers to ensure that the provider is well regarded within the industry for integrity, effectiveness, and competence.

Formed in 2012, Wynyard Group deals with high consequence crime fighting and security software, It is headquartered in NSW, Australia.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    ISS Facility Services Australia & New Zealand

    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO

  • Willis Towers Watson

    BPAY Group

    Building BPAY Group's New Digital Foundation

    Angela Donohoe, Chief Information Officer

  • Willis Towers Watson

    Bvn Architecture

    How Have Recent Advancements in Big Data Been Impacting Businesses?

    Marc Solomon, CIO

  • Willis Towers Watson

    Tassal Operations

    BI & Analytics in Aquaculture

    Matthew Leary, CIO

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cybersecurity-and-resilience.apacciooutlook.com/leadership-perspective/the-organizations-responsibility-for-its-own-protection-nwid-3876.html