sb-eu logo
Story image

Organisations not testing incident response plans – IBM Security

15 Apr 2019

IBM Security has announced the results of a global study exploring organisations’ preparedness when it comes to withstanding and recovering from a cyberattack.

The study, conducted by the Ponemon Institute on behalf of IBM, found that the majority of organisations surveyed are still unprepared to properly respond to cybersecurity incidents, with 77% of respondents indicating they do not have a cybersecurity incident response plan applied consistently across the enterprise.

While studies show that companies who can respond quickly and efficiently to contain a cyberattack within 30 days save over $1 million on the total cost of a data breach on average, shortfalls in proper cybersecurity incident response planning have remained consistent over the past four years of the study.

Of the organisations surveyed that do have a plan in place, more than half (54%) do not test their plans regularly, which can leave them less prepared to effectively manage the complex processes and coordination that must take place in the wake of an attack.

The difficulty cybersecurity teams are facing in implementing a cybersecurity incident response plan has also impacted businesses’ compliance with the General Data Protection Regulation (GDPR).

Nearly half of respondents (46%) say their organisation has yet to realise full compliance with GDPR, even as the one-year anniversary of the legislation quickly approaches.   

“Failing to plan is a plan to fail when it comes to responding to a cybersecurity incident."

"These plans need to be stress tested regularly and need full support from the board to invest in the necessary people, processes and technologies to sustain such a programme,” says, IBM Resilient co-founder and product management vice president Ted Julian.

“When proper planning is paired with investments in automation, we see companies able to save millions of dollars during a breach.”  

Automation still emerging

For the first time, this year’s study measured the impact of automation on cyber resilience.

In the context of this research, automation refers to enabling security technologies that augment or replace human intervention in the identification and containment of cyber exploits or breaches. These technologies depend upon artificial intelligence, machine learning, analytics and orchestration.

When asked if their organisation leveraged automation, only 23% of respondents said they were significant users, whereas 77% reported their organisations only use automation moderately, insignificantly or not at all. 

Organisations with the extensive use of automation rate their ability to prevent (69% vs. 53%), detect (76% vs. 53%), respond (68% vs. 53%) and contain (74% vs. 49%) a cyberattack as higher than the overall sample of respondents.

According to the 2018 Cost of a Data Breach Study, the use of automation is a missed opportunity to strengthen cyber resilience, as organisations that fully deployed security automation saved $1.5 million on the total cost of a data breach, contrasted with organisations that did not leverage automation and realised a much higher total cost of a data breach. 

Skills gap still impacting cyber resilience

The cybersecurity skills gap appears to be further undermining cyber resilience, as organisations reported that a lack of staffing hindered their ability to properly manage resources and needs.

Survey participants stated they lack the headcount to properly maintain and test their incident response plans and are facing 10-20 open seats on cybersecurity teams. 

In fact, only 30% of respondents reported that staffing for cybersecurity is sufficient to achieve a high level of cyber resilience.

Furthermore, 75% of respondents rate their difficulty in hiring and retaining skilled cybersecurity personnel as moderately high to high. 

Adding to the skills challenge, nearly half of respondents (48%) said their organisation deploys too many separate security tools, ultimately increasing operational complexity and reducing visibility into overall security posture.

Privacy growing as a priority

Organisations are finally acknowledging that collaboration between privacy and cybersecurity teams can improve cyber resilience, with 62% indicating that aligning these teams is essential to achieving resilience.

Most respondents believe the privacy role is becoming increasingly important, especially with the emergence of new regulations like GDPR and the California Consumer Privacy Act, and are prioritising data protection when making IT buying decisions.

When asked what the top factor was in justifying cybersecurity spend, 56% of respondents said information loss or theft.

This rings especially true as consumers are demanding businesses do more to actively protect their data.

According to a recent survey by IBM, 78% of respondents say a company's ability to keep their data private is extremely important, and only 20% completely trust organisations they interact with to maintain the privacy of their data.

In addition, most respondents also reported having a privacy leader employed, with 73% stating they have a Chief Privacy Officer, further proving that data privacy has become a top priority in organisations.

Story image
Malware and email scams targeting employees spread rapidly in Q2
"Businesses must stay alert and should employ defense-in-depth tactics and equip themselves with multilayered security mechanisms, including high-sensor spam filters and a VPN connection, which would prevent malicious pages from opening."More
Story image
CrowdStrike integrates with ServiceNow program to bolster incident response
As part of the move, users can now integrate device data from the CrowdStrike Falcon platform into their incident response process, allowing for the improvement of both the security and IT operation outcomes.More
Story image
High-tech heist: why fending off ransomware attacks is more challenging than ever in 2020
The COVID-19 crisis has unleashed a wave of sophisticated and disruptive ransomware attacks, and the onus is on businesses to ramp up their security measures if they’re to avoid falling victim, writes Attivo Networks regional director for A/NZ Jim Cook.More
Story image
Gartner predicts 75% of CEOs to be liable for cyber-physical security incidents by 2024
The nature of CPSs means incidents can quickly lead to physical harm to people, destruction of property or environmental disasters – and Gartner’s new research indicates that these incidents will increase drastically in the next few years if the lack of spending on these assets continues.More
Story image
Yubico launches latest YubiKey with NFC & USB-C support
Yubico has released a new hardware authentication key, designed to provide security through both near-field communication (NFC) and USB-C connections and smart card support.More
Story image
Exabeam and Code42 partner up to launch insider threat solution
The solution will give customers a fuller picture of their environment, and will leverage automated incident response to obstruct insider threat before data loss occurs.More