Report: 67 Percent of Businesses Lack Confidence of Full Recovery After Cyber Attack

New research commissioned by Cohesity reveals the majority of businesses do not have the necessary cyber resilience strategies or data security capabilities required to address today’s escalating cyber threats and maintain business continuity. Furthermore, their cyber resilience efforts are not keeping pace with cyber threats, with data security and recovery technology deficiencies reducing cyber insurance eligibility and increasing the fallout of a successful attack.

In comparing the cybersecurity outlook for 2023 to 2022, 93% of respondents said they felt the threat of ransomware attacks to their industry had increased in 2023. Alarmingly, almost half of respondents (45%) confirmed their business had been the victim of a ransomware attack in the prior six months. Respondents also revealed that their business’ cyber resilience and data security capabilities have not kept pace, with 80% expressing concerns about their organization’s cyber resilience strategy and whether it can ‘address today’s escalating cyber challenges and threats’.

Business continuity is critical even when adverse cyber events arise, however, businesses are slow to respond because they lack the capability to recover data and restore business processes quickly. When asked how long their organization would take to recover data and business processes if a cyberattack occurred? Over 95% of respondents revealed their business would need over 24 hours, 71% said it would take more than 4 days, while a fourth (41%) of respondents said over a week would be required.

Unsurprisingly, two-thirds respondents (67%) lack full confidence that their company could recover their data and critical business processes in the event of a system-wide cyberattack. Diving deeper into cyber resilience and data recovery expectations versus reality, 90% of respondents said their business would consider paying a ransom, with close to 3 in 4 (74%) saying ‘Yes’ their organization would pay, if it meant being able to recover data and business processes, or recover faster.

“Companies cannot afford to be offline and unable to maintain operations, especially for more than a day. However, the stark reality is that many organizations are vulnerable to leverage from cyber criminals because they are incapable of rapidly recovering their data and business processes when necessary,” said Brian Spanswick, chief information security officer and head of IT, Cohesity. “Therefore, it’s no surprise that 9 in 10 respondents said their business would consider paying a ransom to maintain continuity.”

When asked about the biggest barriers to their organization being able to get back up and running in the event of a successful cyberattack, respondents said their top three challenges were integration between IT and security systems (34%), a lack of coordination between IT and security (33%) and antiquated backup and recovery systems (32%). Further clarity was provided by respondents regarding their ability to secure their data estates, with less than half stating they are confident all their data stored in the cloud (44%) or at the edge (42%) is secure and protected, and less than 3 in 10 (28%) are confident data stored on-premises is secure and protected.

“IT and SecOps must co-own organizations’ cyber resilience outcomes to identify sensitive data and protect, detect, respond, and recover from cyberattacks,” said Spanswick. “Relying on traditional backup and recovery systems, which lack modern data security capabilities, in today’s sophisticated cyber threat landscape is a recipe for disaster. Instead, organizations should seek out data security and management platforms that integrate with their existing cybersecurity solutions and provide visibility into their security posture and improve cyber resilience.”

“It’s not a surprise that over half of organizations still struggle with securing data in the cloud. The reality is most organization’s data is scattered across different environments and varies by type,” said Tyler Young, CISO of BigID. “That’s why solutions like BigID that enable organizations to know and control their data become ever more critical.”

Consequently, 87% of respondents said that to help win the war against ransomware, data and cybersecurity vendors must collaborate to provide complete and integrated anti-ransomware solutions, and 9 in 10 respondents feel their business would benefit from a data security and management platform that provides insights on their overall security posture and cyber resilience.

“The only way to achieve cyber resilience is by prioritizing proactive security measures that will prevent cyberattacks in the first place,” said Ray Komar, vice president of technology and cloud alliances, Tenable. “This approach should also extend to backup and recovery measures to ensure business continuity in the event of a cybersecurity incident. This requires organizations to not only manage their cyber risk, but better understand their exposure to risk by leveraging vulnerability and exposure data to make informed decisions on remediation efforts.”

This is especially urgent given that adequate data backup and recovery services are critical to have in order to qualify for cyber insurance – and not all solutions are created equal. While almost 3 in 4 (74%) respondents confirmed their company has cyber insurance, close to half (46%) of all respondents said it is now harder to obtain cyber insurance than it was in 2020. Respondents also shared the three most critical technologies or capabilities required to secure cyber insurance are: “strong encryption” (40%), the “ability to verify the integrity of backups” (38%) and MFA (37%) as their top needs.

Featured

  • Meeting Modern Demands

    Door hardware and access control continue to be at the forefront of innovation within the security industry, continuously evolving to meet the dynamic needs of commercial spaces. Read Now

  • Leveraging IoT and Open Platform VMS for a Connected Future

    The evolution of urban environments is being reshaped by the convergence of Internet of Things (IoT) technology and open platform VMS. As cities worldwide grapple with growing populations and increasing operational complexities, these integrated technologies are emerging as powerful tools for creating more livable, efficient, and secure urban spaces. Read Now

  • Securing the Future

    Two security experts sit down with Security Today’s editor in chief Ralph C. Jensen to discuss what they see emerging and changing over the next several years along with how security stakeholders can harness these innovations into opportunities. Read Now

  • Collaboration Made Easy Using a Work Management Platform

    Effective collaboration between security operators, teams and other departments is critical to the smooth functioning of organizations. Yet, as organizations grow in complexity, it becomes more difficult for teams to coordinate with each other. This is compounded by staffing shortages, turnover and ineffective collaboration tools. Read Now

  • Creating a Safer World

    Managing and supporting locks and door hardware within a facility is a big responsibility. A building’s security needs to change over time as occupancy and use demands evolve, which can make it even more challenging. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.