The research found an increase in both cyberattack volume and breaches during the past 12 months in the
Data for the report was compiled in March and
Key survey findings from
*98% said attack volumes have increased in the last 12 months, the survey found.
*99% said their business has suffered a security breach in the last 12 months. The average organisation said they experienced 63 breaches during this time, the survey found.
*96% said attacks have become more sophisticated, the survey found.
*6% said they plan to increase cyber defence spending in the coming year, according to the survey.
*OS vulnerabilities are the leading cause of breaches, according to the survey, but island-hopping and third-party application attacks are also contributing to breaches, the survey found.
*
Common breach causes in the
The most common cause of breaches in the
Complex multi-technology environments
Said McElroy: "Siloed, hard-to-manage environments hand the advantage to attackers from the start. Evidence shows that attackers have the upper hand when security is not an intrinsic feature of the environment. As the cyber threat landscape reaches saturation, it is time for rationalisation, strategic thinking and clarity over security deployment."
Supplemental COVID-19 survey in the
The latest research was supplemented with a survey on the impact COVID-19 has had on the attack landscape [1]. According to the supplemental survey of more than 1,000 respondents from the US,
Key findings from the supplemental
*93% said they have been targeted by COVID-19-related malware
*Inability to institute multifactor authentication (MFA) was reported as the biggest security threat to businesses during COVID-19, the survey found.
*84% reported gaps in disaster planning around communications with external parties including customers, prospects, and partners. 45% said those gaps were significant.
Said McElroy: "The global situation with COVID-19 has put the spotlight on business resilience and disaster recovery planning. Those organisations that have delayed implementing multi-factor authentication appear to be facing challenges, as 28% of
*89% of respondents reported gaps in recovery planning, ranging from slight to severe.
*88% said they had uncovered gaps in IT operations.
*83% said they encountered problems around enabling a remote workforce.
*74% said they've experienced challenges communicating with employees
*84% said they had experienced difficulty communicating with external parties.
*70% said the situation uncovered gaps around visibility into cybersecurity threats.
Said McElroy: "These figures indicate that the surveyed CISOs may be facing difficulty in a number of areas when answering the demands placed on them by the COVID-19 situation."
Risks directly related to COVID-19 have also quickly emerged, the survey found. In addition to the 93% of
Said McElroy: "The 2020 survey results suggest that security teams must be working in tandem with business leaders to shift the balance of power from attackers to defenders. We must also collaborate with IT teams and work to remove the complexity that's weighing down the current model. By building security intrinsically into the fabric of the enterprise - across applications, clouds and devices - teams can significantly reduce the attack surface, gain greater visibility into threats, and understand where security vulnerabilities exist."
Read the full executive summary here: https://www.carbonblack.com/resources/global-threat-report-extended-enterprise-under-attack-uk
-ends-
About
Security sprawl - too many products, agents, and interfaces deployed across an organization - has created complexity for security management, opening organizations to significant risk. Most security innovation over the past decade has focused on identifying and reacting to individual attacks. Little innovation has focused on hardening infrastructure itself to make it more secure or using the infrastructure to better protect an organization.
The way forward is an intrinsic security approach that combines detecting and responding to threats, in addition to hardening infrastructure.
About
Main Survey Methodology
COVID-19 Survey Methodology
[1] COVID-19 survey methodology: The COVID-19 survey was conducted by Opinion Matters in March and
Press Contact
michael@c8consulting.co.uk
+44(0)1189497750
.
(C) 2020 M2 COMMUNICATIONS, source