Unlocking cyber excellence: CISO strategies for the TMT industry has been saved


Current challenges: Attrition among cybersecurity professionals; gaps in specialized knowledge of cyber risks; significantly higher spending than competitors
Deloitte’s approach: We provided a dedicated delivery team, which helped the client enhance its technology stack by identifying root causes for performance and compatibility issues, improving legacy technologies and bringing in our integrated solutions. Our 24/7, 365-days-a-year Cyber Operations and Infrastructure Management team was able to help the client address its talent issues by providing access to specialists that the client was struggling to hire and retain.
Results for client: Reduced incident frequency, allowing shift to a more strategic security operations focus. Integrated cross-team processes to help the client improve workflows, accelerate responses, identify emerging risks, and improve overall security.


Current challenges: Regulatory concerns; assessing developers’ practices against client’s terms for service providers and data security, use, and deletion; managing and maintaining developer risk assessments (DRAs)
Deloitte’s approach: Assembled a team of 25 cyber and cloud security and application development specialists to help the client transform its program from manual, email-based DRAs to automated workflow, engaging with client product teams to help them align the process with business requirements. Redefined the approach to handling client escalations with their most significant on-platform vendors to help them improve adherence to program standards. Implemented follow-the-sun model by leveraging Deloitte’s onshore and offshore resources for live and offline communications.
Results for client: Completed more than 6,000 unique DRAs in 10 months. Efficiently cleared a backlog of more than 5,000 DRAs while implementing process and tool improvements.


Current challenges: Enterprisewide effort to reduce costs in demonstrable and measurable ways; large privacy programs needed to mature to meet regulatory obligations while attaining greater efficiency and reducing overall costs
Deloitte’s approach: Deployed a diverse, multidisciplinary team of subject-matter advisers and service delivery managers to help the client achieve its strategic and operational compliance needs. Our approach offered breadth and depth along with agility and adaptability. The team worked with the client to identify and analyze processes that could be redesigned, automated, and offshored.
Results for client: Helped to convert 40% of existing process support by leveraging offshore capabilities and by automating repetitive tasks. Client gained a more mature privacy program while reducing costs by 27% without any impact on productivity. Automation also enabled the client to shift focus toward more value-added strategic tasks.


Current challenges: Reduce $50M from the overall annual cybersecurity spend in 2 years, without compromising on security posture and quality of service
Deloitte’s approach: We evaluated the client's current spending on cybersecurity, analyzed their technology infrastructure, and assessed the composition of their workforce. Extensive data analysis was also performed across various spending dimensions. Leveraging our industry experience and a robust cost-optimization framework, we identified several cost-saving levers. These were strategically developed into hypotheses that spanned people, processes, and technology, aiming to enable the client to either maintain or enhance their existing security posture while reducing overall security spending.
Results for client: Deloitte enabled the client to make informed decisions, identifying cost optimization opportunities that could result in up to 30% overall savings in annual cyber spending. These savings were distributed across labor (25-35%), process (3-5%) and technology licensing costs (3-5%), without compromising cybersecurity effectiveness.