Most Organisations Lack Cyber Resilience

Despite increasing threats, many organisations continue to run with only token cybersecurity and resilience. 

According to Ernst & Young's Global Information Security Survey 2018-19, over half of organisations fail to make organisational protection a key part of their strategic plans. After soliciting the opinions of approximately 1,400 C-suite leaders, EY concludes that larger firms are somewhat more prone to fall short in this area than smaller ones (58% versus 54%). 

Overall, EY reports, a solid 77% of organisations still operate with only lackluster cyber security and resilience.

They may even lack a clear idea of what their most critical information assets are and where they're located, never mind having adequate safeguards in place to protect them.

Fortunately, cyber-security budgets are increasing, though bigger firms are more likely to increase their investments in 2019 (63%) and 2020 (67%) than smaller companies (50% and 66%).

System Outages
Whether it's because of the convergence of operational technology (OT) and IP-based IT networks or the growing use of cloud computing, corporate reliance on the availability of global IT infrastructure is ballooning. And the consequences are rising as well.

Cyber-attacks to disrupt the business are now ranked as the third-biggest threat, after phishing (No. 1) and malware (No. 2). This comes as no surprise because distributed denial-of-service (DDoS) attacks, for instance, can trigger a major service interruption that will bring the business to a standstill. 

Outages have always been painful, but given the trend toward moving workloads and applications off-premises, and operating revenue-critical platforms, business operations virtually come to a stop if the IP network collapses.

"Importantly, more organisations are now beginning to recognize the broad nature of the threat," says Richard Watson, EY's Asia-Pacific cybersecurity head. 

"One thing that has changed for the better over the past 12 months, partly because of some of those big cyber-attacks we've seen at a global level, is a growing realisation that security is also about maintaining the continuity of business operations, and not only about the security of data and privacy."

No Room for Russian Roulette
Given this reality, it's jaw-dropping that many organizations seem to think they shouldn't beef up their cybersecurity practices or dedicate more money to IT unless they're hit by a major security incident. For 63% of organisations, a security breach that results in no harm wouldn't lead to higher spending (although, typically, seemingly innocuous breaches can cause harm that doesn't manifest until later). Still, many organisations are unclear about whether they're successfully identifying breaches and incidents.

These firms are playing with fire. As noted in the EY report, the Ponemon Institute estimates the average cost of a security breach to be $3.62 million per incident.

Tackling Corporate Governance
A mere 18% of organisations say that information security has a regular bearing on business strategic plans, a finding that reveals a basic disconnect between cyber-security and the C-suite. Over half of the EY survey respondents say that information security only somewhat or does not influence their business strategy.

Today, when the digital age and cyber-crime is in full bloom, this is somewhere between unwise and unacceptable. In fact, cyber-security and business strategy must go hand-in-hand and be a continuing agenda item for all executive and non-executive boards, as many of board decisions will influence how well the organisation is positioned to deal with a prospective cyber-attack.

That said, increasingly, the ultimate responsibility for information security lies with the people at the top levels of the company. For 40% of organisations, the CIO assumes this responsibility. 

However, in 60% of organisations, the person directly responsible for information security does not sit on the board. Some 70% of organisations report that their senior leaders have a thorough grasp of security or are taking positive steps to better their knowledge of it. Without question, this trend will increase as security becomes a key driver of growth. 

Right now, smaller organisations are better at keeping their board informed about information security matters than larger organisations. That said, larger organisations have made more progress: 73% have at least a limited understanding of information security, compared with 68% of their smaller counterparts.

Swinging in the Dark
Less than one in 10 organisations says its information security function fully meets its needs, and many are concerned that much-needed improvements are not yet underway.  Seventy-eight percent of larger organisations say their information security function is at least partially meeting their needs, but that number drops to just 65% among their smaller counterparts.

Overall, 92% of organisations are concerned about their information security capabilities in certain important areas. For instance, resources: 30% of organisations are grappling with skills shortages, while 25% report that their budgets are constrained. 

Smaller firms are particularly worried; 28% of them say their information security function does not currently meet their needs or must be improved. Just over half (56%) report skills shortages or budget constraints.

A paltry 15% of firms say their information security reporting fully meets their expectations. Among those that suffered an incident in the past year, less than a third say their security team discovered the breach. 
Smaller companies will need to move particularly quickly to address the security reporting issue: almost a quarter (23%) don't produce information security reports, in contrast with 16% of larger organisations. Only 5% describe the financial implications of each breach.

Addressing the Skills Challenge
Although the right personnel are critical to solving information security challenges, recruiting said personnel is easier said than done. The ongoing and global IT security skills shortage won't go away anytime soon. 
Estimates project a worldwide shortfall of about 1.8 million security professionals by 2024, some studies even predict as much as 3.5 million cyber vacancies. 

The upshot is that depending on an in-house team to deal with IT security is probably an exercise in futility. Today, firms must think laterally and place much more emphasis on machine learning, automation, and AI to either replace or complement external service providers.

Dark Reading

You Might Also Read:

Business Leaders Are Ignoring Cyber Risks:

30% Of Business Leaders Would Pay Ransom:

 

 

« From Ciphers To Cyber Security
Cyber Criminals Are Targeting Latin America »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Synology

Synology

Synology provides high-performance, reliable, and secure Network Attached Storage (NAS) products.

Brit

Brit

Brit PLC is a market-leading global specialty insurer and reinsurer, focused on underwriting complex risks including cyber, privacy and technology.

Signal Sciences

Signal Sciences

Signal Sciences Web Protection Platform (WPP) provides comprehensive threat protection and security visibility for web applications, microservices, and APIs on any platform.

SynerComm

SynerComm

SynerComm is an IT solution provider specializing in network and security infrastructure, enterprise mobility, remote access, wireless solutions, audit, pentesting and information assurance.

Resilience First

Resilience First

Resilience First is a not-for-profit organisation, led and funded by business to strengthen collective business resilience in all areas, including cyber security.

TypingDNA

TypingDNA

TypingDNA uses AI to recognise people by the way they type on desktop keyboards and mobile devices.

Wise-Mon

Wise-Mon

Wise-Mon is expert in its field of network monitoring and control. We give solutions to huge organizations with tens of thousands of ports, as well as small companies with one switch.

SHIELD

SHIELD

SHIELD is an established end-to-end fraud management solution that blocks fraudulent activities such as account takeovers, fake accounts creation, fraudulent payments, loyalty fraud and more.

DataDome

DataDome

DataDome offers real-time AI protection against all OWASP automated threats, including credential stuffing, layer 7 DDoS attacks, SQL injection & intensive scraping.

Healthcare Fraud Shield (HCFS)

Healthcare Fraud Shield (HCFS)

The focus of Healthcare Fraud Shield is solely on healthcare fraud prevention and payment integrity with a successful approach based on many unique advantages we deliver to our clients.

DataCloak

DataCloak

DataCloak is an innovation company that focus on providing enterprise data-in-motion security solutions based on zero-trust security technology.

New Net Technologies (NNT)

New Net Technologies (NNT)

NNT SecureOps provides ultimate protection against all forms of cyberattack and data breaches by automating the essential security controls.

VIRTIS

VIRTIS

VIRTIS' mission is to provide today's leading organizations peace of mind that their entire digital network perimeter is safe from hackers and data breach.

PNGCERT

PNGCERT

PNGCERT is the national Computer Emergency Response Team (CERT) for Papua New Guinea.

LogicBoost Labs

LogicBoost Labs

LogicBoost Labs has the expertise, experience, funding and connections to make your startup succeed. We are always interested in new ways to change the world for the better.

Spinnaker Support

Spinnaker Support

Spinnaker Support is a premier global provider of on-premise and cloud-based enterprise software support services.