Security industry losing the cyberwar: RSA
The IT security industry is losing the cyberwar and companies are still woefully unprepared for the threats they face, with 30% of companies still lacking a formal incident response plan.
These are among the findings of a survey by EMC's RSA, answered by 170 respondents from 30 countries.
Even among those companies with a response plan, 57% report never reviewing or updating this plan.
Despite the discovery of high-profile exploits such as Heartbleed and POODLE, 40% of survey respondents also lack an active vulnerability management program.
Results were compared by research from the Security for Business Innovation Council (SBIC), a group of security leaders drawn from the Global 1000.
RSA noted that the number of reported security incidents worldwide increased some 48% in 2014 and financial losses from cybersecurity incidents grew 34% to $2.7 million over the same period.
This indicates that despite growing information security spending, the industry is failing to keep pace with cybercriminals.
Issues holding back the industry include a lack of situational awareness - or a failure to assess the methods, meaning and impact of cyber attacks, exacerbated by companies failing to objectively assess their security stance.
RSA also suggested that organisations do not focus enough spending on detection and response, and noted that many are struggling with a shortage of internal cybersecurity expertise and resources.
Australia is building AI faster than it can secure it
The pace of AI adoption is being set by competitive pressure and internal demand, and security is...
Why Australia's ransomware spike misses the bigger story
The apparent rise and fall in Australia's ranking tells a broader story about how ransomware...
Anthropic's Claude Mythos: how can security leaders prepare?
Advanced exploit development is no longer an artisan craft performed by seasoned experts with...
