Security industry losing the cyberwar: RSA
The IT security industry is losing the cyberwar and companies are still woefully unprepared for the threats they face, with 30% of companies still lacking a formal incident response plan.
These are among the findings of a survey by EMC's RSA, answered by 170 respondents from 30 countries.
Even among those companies with a response plan, 57% report never reviewing or updating this plan.
Despite the discovery of high-profile exploits such as Heartbleed and POODLE, 40% of survey respondents also lack an active vulnerability management program.
Results were compared by research from the Security for Business Innovation Council (SBIC), a group of security leaders drawn from the Global 1000.
RSA noted that the number of reported security incidents worldwide increased some 48% in 2014 and financial losses from cybersecurity incidents grew 34% to $2.7 million over the same period.
This indicates that despite growing information security spending, the industry is failing to keep pace with cybercriminals.
Issues holding back the industry include a lack of situational awareness - or a failure to assess the methods, meaning and impact of cyber attacks, exacerbated by companies failing to objectively assess their security stance.
RSA also suggested that organisations do not focus enough spending on detection and response, and noted that many are struggling with a shortage of internal cybersecurity expertise and resources.
Accelerating the adoption of passkeys without compromising user experience
We need authentication methods that remove the human element from the equation, and that's...
Modern CISOs must throw out the traditional cybersecurity playbook
The primary imperative for today's CISOs should be to align the security agenda with business...
AI agents: securing the 'artificial workforce'
Just as they would with new employees, security teams will need to define access policies for...