IT security personnel must therefore look beyond compliance-driven security models to deal with these threats, he said.
"I've lived through an earthquake, so I have a visceral sense for why you need earthquake insurance," Trilling said. IT security managers must have that same sense when it comes to information security, he added.
"Companies that have experienced attacks don't have that sense so they have been doing what they need to do to check the box," Trilling said.
Sign up for CIO Asia eNewsletters.