TechCentralTechCentral
    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Dimension Data to be renamed NTT Data

      27 October 2023

      Karpowership gets green light for Richards Bay plant

      27 October 2023

      Why people wave on Zoom

      27 October 2023

      Microsoft gaining ground in cloud race with AWS, Google

      27 October 2023

      Black Friday to create an extra R26.6-billion in retail turnover

      26 October 2023
    • World

      Huawei sees growth in cloud, digital power segments

      27 October 2023

      Intel beats expectations; manufacturing momentum builds

      27 October 2023

      Google CEO to testify on Monday in antitrust trial

      27 October 2023

      China rushes to swap Western tech for domestic options

      26 October 2023

      Alphabet, Meta deliver solid financial performances

      26 October 2023
    • In-depth

      Quantum computers in 2023: what they do and where they’re heading

      22 October 2023

      How did Stephen van Coller really do as EOH CEO?

      19 October 2023

      Risc-V emerges as new front in US-China tech war

      6 October 2023

      Get ready for a tidal wave of software M&A

      26 September 2023

      Watch | A tour of Vumatel’s Alexandra fibre roll-out

      19 September 2023
    • TCS

      TCS | Mesh.trade’s Connie Bloem on the future of finance

      26 October 2023

      TCS | Rahul Jain on Peach Payments’ big funding round

      23 October 2023

      TCS+ | How MiWay uses conversation analytics

      16 October 2023

      TCS+ | The story behind MTN SuperFlex

      13 October 2023

      TCS | The Information Regulator bares its teeth – an interview with Pansy Tlakula

      6 October 2023
    • Opinion

      Big banks, take note: PayShap should be free

      20 October 2023

      Eskom rolling out virtual wheeling – here’s how it works

      4 October 2023

      How blockchain can help defeat the scourge of counterfeit goods

      29 September 2023

      There’s more to the skills crisis than emigration

      29 September 2023

      The role of banks in Africa’s digital future

      22 August 2023
    • Company Hubs
      • 4IRI
      • Africa Data Centres
      • Altron Document Solutions
      • Altron Systems Integration
      • Arctic Wolf
      • AvertITD
      • CoCre8
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • E4
      • Entelect
      • ESET
      • Euphoria Telecom
      • iKhokha
      • Incredible Business
      • iONLINE
      • LSD Open
      • Maxtec
      • MiRO
      • NEC XON
      • Next DLP
      • Ricoh
      • Skybox Security
      • SkyWire
      • Velocity Group
      • Videri Digital
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud computing
      • Consumer electronics
      • Cryptocurrencies
      • E-commerce
      • Education and skills
      • Energy
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Metaverse and gaming
      • Motoring and transport
      • Open-source software
      • Public sector
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Top cybersecurity challenge is inadequate identification of key risks

    Top cybersecurity challenge is inadequate identification of key risks

    Promoted | Some 40% of chief security officers say their organisations are not well prepared for today’s rapidly evolving threat landscape, new findings from the largest cybersecurity benchmarking study of global executives show.
    By Skybox Security17 August 2022
    Facebook Twitter LinkedIn WhatsApp Telegram Email

    Skybox Security has released new findings from the largest cybersecurity benchmarking study of global executives. The research shows that traditional security approaches that rely on reactive, detect-and-respond measures and tedious manual processes can’t keep pace with the volume, variety and velocity of current threats. As a result, 27% of all executives and 40% of chief security officers (CSOs) say their organisations are not well prepared for today’s rapidly shifting threat landscape.

    For full research citations and in-depth analysis, download the report

    In summary

    • 25% increase in 2021 in material cybersecurity breaches – those generating a large loss, compromising many records or having a significant impact on business operations
    • Top four causes of breaches are avoidable, according to cybersecurity researchers
    • 48% of organisations with no breaches in 2021 were risk-based cybersecurity leaders

    A tipping point

    On average, organisations experienced 15% more cybersecurity incidents in 2021 than in 2020. In addition, “material breaches”— defined as “those generating a large loss, compromising many records or having a significant impact on business operations” — jumped 24.5%.

    The top four causes of the most significant breaches reported by the affected organisations were:

    • Human error
    • Misconfigurations
    • Poor maintenance/lack of cyber hygiene
    • Unknown assets

    “What’s notable about this list is that all of these conditions result from mistakes or manual processes inside organisations — which means they are all, in principle, avoidable,” said Ran Abramson, threat intelligence analyst at Skybox Research Lab. “The clear implication is that, however pernicious external threats have become, cybersecurity teams still have the power to repel them. And that’s the good news: with the right practices and tools – including automation to maximise efficiency and get the most out of limited staff – breaches can be prevented.”

    Risk-based approach prevents breaches

    The study surveyed executives and analysed the cybersecurity investments, practices and performance of 1 200 companies and public-sector organisations in 16 countries and a wide range of industries. It’s the largest cybersecurity benchmarking study with C-level decision-makers ever undertaken. The research findings uncover that conventional cybersecurity approaches are falling short, and organisations that shift to modern, risk-based strategies are more successful in preventing breaches.

    Source: Skybox Security

    Though organisations, on average, saw a significant uptick in incidents and material breaches in the past two years, a distinct subset had few or no breaches at all. So, what sets these exceptional organisations apart? The researchers found that firms with fewer breaches were different from the rest of the pack in two fundamental respects:

    1. Organisations that prevented breaches ranked higher in cybersecurity progress as measured by the NIST framework. The framework, developed by the National Institute of Standards and Technology, provides guidelines that help companies evaluate and improve their cybersecurity maturity in activities such as detecting and responding to incidents.
    2. Beyond the NIST framework, organisations with no breaches took what the researchers call “a risk-based approach” to cybersecurity. Forty-eight percent of organisations with no breaches in 2021 had implemented risk-based cybersecurity management strategies. They also performed better in key cybersecurity metrics: 46% were top performers in time to respond to a breach, and 50% were top performers in time to respond.

    Looking more closely at the ingredients of a risk-based approach and the specific practices that distinguish risk-orientated organisations from their less proficient peers, the benchmark study found that risk-based leaders excelled in key areas beyond the NIST framework, including:

    • Attack surface visibility and context
    • Attack simulation
    • Exposure analysis
    • Risk scoring
    • Vulnerability assessments
    • Research (threat intelligence)
    • Technology assessments and consolidation

    “You must take a risk-based approach because you can’t secure everything 100%. There are a lot of questions to ask: what is the business of the business? What does the risk profile look like? What are the threats? What are the implications? And what is the governance process an organisation goes through to make risk-based decisions?” said Gary McAlum, board director at the National Cybersecurity Center.

    The business impact of successful risk-based security management — versus the old status-quo, detect-and-respond approach — is measured in this research. By preventing or mitigating breaches, risk-based methods could have saved companies millions annually and prevent untold damage to reputation, customer trust, company morale and market standing.

    “The cybersecurity industry is witnessing a paradigm shift in cyber risk. To prevent breaches, chief information security officers must make a strategic shift – from the traditional volume play of identifying vulnerabilities and merely adhering to cybersecurity frameworks to taking a strategic, risk-based view of reducing actual exposure,” said Gidi Cohen, CEO and founder at Skybox Security.

    “At the board level, leaders want to understand their risk profile rather than how many vulnerabilities were patched each month. CISOs need to validate and report on how they’re taking measurable, proactive steps to reduce risk systematically and reduce the financial impact a breach could have on their company.”

    For full research citations and in-depth analysis, download the report.

    About Skybox Security
    Over 500 of the largest and most security-conscious enterprises in the world rely on Skybox for the insights and assurance required to stay ahead of dynamically changing attack surfaces. Our Security Posture Management Platform delivers complete visibility, analytics and automation to quickly map, prioritise and remediate vulnerabilities across your organisation. The vendor-agnostic solution intelligently optimises security policies, actions and change processes across all corporate networks and cloud environments. With Skybox, security teams can now focus on the most strategic business initiatives while ensuring enterprises remain protected.

    • This promoted content was paid for by the party concerned
    Gidi Cohen Skybox Skybox Research Lab Skybox Security
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email
    Previous ArticleAcrobat Sign and Microsoft accelerate digital transformation
    Next Article Chip makers are flashing a big warning for the global economy

    Related Posts

    Acsa aims for carbon neutrality by 2050

    27 October 2023

    Huawei sees growth in cloud, digital power segments

    27 October 2023

    Dimension Data to be renamed NTT Data

    27 October 2023
    Add A Comment

    Comments are closed.

    Promoted

    Acsa aims for carbon neutrality by 2050

    27 October 2023

    Flutter vs React Native: a comprehensive comparison

    27 October 2023

    iKhokha, Shopstar pave the way for simpler e-commerce

    27 October 2023
    Opinion

    Big banks, take note: PayShap should be free

    20 October 2023

    Eskom rolling out virtual wheeling – here’s how it works

    4 October 2023

    How blockchain can help defeat the scourge of counterfeit goods

    29 September 2023

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2023 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.