40 Percent Of Companies Risking Cyber Security Catastrophe

The overwhelming majority of businesses (86 percent) feel they are prepared for security breach, but almost 40 percent of them do not even have a response plan in place.

This was the finding of a study by Pierre Audoin Consultants (PAC), which uncovered a notable gap in Incident Response (IR) preparedness among EU companies.

Lack of testing

Additionally, only 30 percent of those with IR plans test and update them regularly (more than once a month).

The study was co-sponsored by Resilient Systems, the leading Incident Response Platform (IRP) provider for security professionals, along with FireEye, HP and Telefonica.

Bruce Schneier, CTO at Resilient Systems, said: “As the cyber threat landscape becomes more challenging, businesses need enhanced response plans to ensure they’re able to survive and thrive in the face of these threats. For decades, companies have focused on preventing and detecting attacks, but they haven’t focused enough on Incident Response. This is critical to good security.”

The survey also identified an increase of cybersecurity spending for Incident Response. According to the survey, businesses spend 77 percent of their security budgets on prevention and detection technology. However, spend is moving towards Incident Response capabilities – growing from 23 percent today to 39 percent in two years.

Duncan Brown, Research Director at PAC and lead author of the study, said: “Organisations are realising that cyber breaches are inevitable – but focusing on improving response can ensure breaches are survivable. We’re encouraged to see that organisations are investing more in the tools, processes, and people needed for effective and fast Incident Response.”

Additional key findings include:
· 67 percent experienced a breach in the last year. 100 percent have experienced a breach at some point in the past
· 22 percent of organisations have no technology in place to assist with incident response
· Organisations require between one and six months to recover from a breach
· The average direct costs of a data breach (not including internal staffing and loss of business and reputation) is €75000
· 77 percent are either ‘very’ or ‘somewhat’ concerned at the prospect of mandatory breach notification

The study questioned 200 respondents at CISOs/CIO/VP IT level from companies with more than 1000 employees in the UK, France and Germany.

How much do you know about hacking and viruses? Take our quiz!

Duncan Macrae

Duncan MacRae is former editor and now a contributor to TechWeekEurope. He previously edited Computer Business Review's print/digital magazines and CBR Online, as well as Arabian Computer News in the UAE.

Recent Posts

Spyware Maker NSO Group Found Liable In US Court

Landmark ruling finds NSO Group liable on hacking charges in US federal court, after Pegasus…

2 days ago

Microsoft Diversifying 365 Copilot Away From OpenAI

Microsoft reportedly adding internal and third-party AI models to enterprise 365 Copilot offering as it…

2 days ago

Albania Bans TikTok For One Year After Stabbing

Albania to ban access to TikTok for one year after schoolboy stabbed to death, as…

2 days ago

Foldable Shipments Slow In China Amidst Global Growth Pains

Shipments of foldable smartphones show dramatic slowdown in world's biggest smartphone market amidst broader growth…

2 days ago

Google Proposes Remedies After Antitrust Defeat

Google proposes modest remedies to restore search competition, while decrying government overreach and planning appeal

2 days ago

Sega Considers Starting Own Game Subscription Service

Sega 'evaluating' starting its own game subscription service, as on-demand business model makes headway in…

2 days ago