Iโm not the greatest fan of Change Your Password Day, Security Awareness Day or any of the arbitrary labels attached once a year that are meant to somehow magically make us all more secure. But of all the days, Safer Internet Day – Tuesday this week, for those who care – sucks hardest.
Maybe we need a My Network Has Been Hacked Day? I can even think of the right day for it: Every. Bloody. Day. Seriously, letโs stop this silly “awareness is important” for a few days each year charade and get serious. Security is a 24/7, 365 days of the year thing. And if it isnโt, then you are doing it wrong.
Iโm kind of coming to the same conclusion about reports and surveys, to be honest. Look, I love a good stats-overload as much as the next security geek, but one does wonder exactly what good they do. Other than be useful to market one vendor solution or another.
Mea culpa, Iโm as guilty as the next cybersecurity writer for using report after report, statistic after statistic, in my articles. Sources are need in stories, and these provide them. They give me a hook on which to anchor my words. But who else is actually taking notice?
Reports schreports
On Safer Internet Day, a new report from Zscaler landed on my desk. Iโm not knocking Zscaler, which does fine work, nor this report in particular, itโs just timely.
The title of ‘Unlock the Resilience Factor: Why Resilient by Design is the Next Cyber Security Imperativeโ sort of gives away the marketing intent behind it, but the statistics within are a fascinating demonstration of just how far we have to go in the journey to secure our networks and data:
- 60% of organisations expect to experience a significant cyber failure in the next 12 months
- 94% of IT leaders believe their cyber resilience measures are effective, but only 45% have updated their strategy to address AI-based threats
- Less than half of organisations have C-suite involvement in resilience planning
- 49% of IT leaders say their current investment levels don’t match escalating cyber threats
โThe possibility of a major failure scenario for organizations is not an โifโ but โwhenโ, as the statistics in our report show,โ said Jay Chaudhry, Zscaler’s CEO, Chairman and Founder.
โWith the growing threat landscape including AI-based attacks and continued pressure to digitize not likely to abate any time soon, our attack surfaces are still expanding beyond our control,โ contributed James Tucker, Head of EMEA CISOs in Residence at Zscaler.
How many Safer Internet Days do we need?
This is not rocket science, nor is it anything we havenโt heard before. The not-if-but-when mantra is older than David Attenboroughโs teeth. “The attack surface is constantly evolving…” Well, duh. I mean, COME ON. This is 2025, and we are still getting numbers like that and messages like these?
How many Safer Internet Days is it going to take before things get better? None. Zilch, Nada. It makes no difference.
What makes a difference is taking ownership of your cybersecurity destiny, and that means ownership across the enterprise from the shop floor to the top floor. Can we at least agree that maybe today is the day youโll start doing that?
5 articles by Davey that will keep you safer every day