Story image

IT decision makers unsure about their security maturity

11 Apr 2018

IT-decision makers in Asia Pacific, the United Kingdom, and the United States are only ‘moderately’ confident they are able to protect their organisations against hackers, and it might take time to find out when they have been breached.

LogRhythm’s 2018 Cybersecurity Benchmark Survey polled 751 decision makers – of which less than half were able to detect a major cybersecurity incident within one hour.

Even those who did detect a major incident would be unable to contain the breach within an hour.

“Cyber threats continue to grow in volume and intensity. Seemingly every month, another massive security breach dominates the headlines,” comments LogRhythm’s VP of marketing and business development, Matt Winter.

Organisations may be feeling the pressure – despite the desire to grow their security maturity, more than half of respondents say they have just 10 or fewer people in their security teams.

Security maturity is also benchmarked by the number of threat detection programs organisations have in place. The survey found that more than 70% have programs to detect specific threats like ransomware and employee threats.

More than a quarter use at least 10 security software solutions to manage security threats. Working with budgets may influence the number of tools businesses use.

Respondents in Asia Pacific put forth the highest IT budget allocation to security, but overall executives allocate security less than 10% of their budget.

A quarter of executives are not comfortable with such low levels of funding, however 57% said they were ‘moderately comfortable’.

Half of polled respondents still believe a determined hacker can breach their organization. In Asia Pacific, 39% had experienced a breach in the last year.

60% of respondents are sceptical about their security software can detect all major breaches.

However, confidence in security is also influenced by other factors, including targeted threat protection solutions.

“For instance, decision makers who did not report having programs to protect against threats such as ransomware, insider threats, and service denial attacks are less confident in their security programs. Unsurprisingly, that same segment reported slower rates of detection, response, and containment,” LogRhythm says.

When respondents were asked to consider how their organization operates from a threat lifecycle management perspectives, respondents were not optimistic. One third said they need help at all stages in the lifecycle, particularly with detection, investigation, neutralization, and recovery from cyber threats.

“To combat these threats, organizations need to carefully plan their budgets and strategies, while developing effective programs that tackle specific threats and keep them one step ahead of cyberattackers,” Winter concludes.

IoT and DDoS attacks: A match made in heaven
A10 Network’s Adrian Taylor uses findings from a number of reports to illustrate his point that advances in technology are facilitating cybercrime.
ForgeRock launches Sandbox-as-a-Service to facilitate compliance
The cloud-based testing environment for APIs enables banks to accelerate compliance with Open Banking and PSD2 deadlines.
Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
Flashpoint: APAC companies must factor geopolitics in cyber strategies
The diverse geopolitical and economic interests of the states in the region play a significant role in driving and shaping cyber threat activity against entities operating in APAC.
Expert offers password tips to aid a stress-free sleep
For many cybersecurity professionals, the worries of the day often crawl into night-time routines - LogMeIn says better password practices can help.