Report: 67 Percent of Businesses Lack Confidence of Full Recovery After Cyber Attack

New research commissioned by Cohesity reveals the majority of businesses do not have the necessary cyber resilience strategies or data security capabilities required to address today’s escalating cyber threats and maintain business continuity. Furthermore, their cyber resilience efforts are not keeping pace with cyber threats, with data security and recovery technology deficiencies reducing cyber insurance eligibility and increasing the fallout of a successful attack.

In comparing the cybersecurity outlook for 2023 to 2022, 93% of respondents said they felt the threat of ransomware attacks to their industry had increased in 2023. Alarmingly, almost half of respondents (45%) confirmed their business had been the victim of a ransomware attack in the prior six months. Respondents also revealed that their business’ cyber resilience and data security capabilities have not kept pace, with 80% expressing concerns about their organization’s cyber resilience strategy and whether it can ‘address today’s escalating cyber challenges and threats’.

Business continuity is critical even when adverse cyber events arise, however, businesses are slow to respond because they lack the capability to recover data and restore business processes quickly. When asked how long their organization would take to recover data and business processes if a cyberattack occurred? Over 95% of respondents revealed their business would need over 24 hours, 71% said it would take more than 4 days, while a fourth (41%) of respondents said over a week would be required.

Unsurprisingly, two-thirds respondents (67%) lack full confidence that their company could recover their data and critical business processes in the event of a system-wide cyberattack. Diving deeper into cyber resilience and data recovery expectations versus reality, 90% of respondents said their business would consider paying a ransom, with close to 3 in 4 (74%) saying ‘Yes’ their organization would pay, if it meant being able to recover data and business processes, or recover faster.

“Companies cannot afford to be offline and unable to maintain operations, especially for more than a day. However, the stark reality is that many organizations are vulnerable to leverage from cyber criminals because they are incapable of rapidly recovering their data and business processes when necessary,” said Brian Spanswick, chief information security officer and head of IT, Cohesity. “Therefore, it’s no surprise that 9 in 10 respondents said their business would consider paying a ransom to maintain continuity.”

When asked about the biggest barriers to their organization being able to get back up and running in the event of a successful cyberattack, respondents said their top three challenges were integration between IT and security systems (34%), a lack of coordination between IT and security (33%) and antiquated backup and recovery systems (32%). Further clarity was provided by respondents regarding their ability to secure their data estates, with less than half stating they are confident all their data stored in the cloud (44%) or at the edge (42%) is secure and protected, and less than 3 in 10 (28%) are confident data stored on-premises is secure and protected.

“IT and SecOps must co-own organizations’ cyber resilience outcomes to identify sensitive data and protect, detect, respond, and recover from cyberattacks,” said Spanswick. “Relying on traditional backup and recovery systems, which lack modern data security capabilities, in today’s sophisticated cyber threat landscape is a recipe for disaster. Instead, organizations should seek out data security and management platforms that integrate with their existing cybersecurity solutions and provide visibility into their security posture and improve cyber resilience.”

“It’s not a surprise that over half of organizations still struggle with securing data in the cloud. The reality is most organization’s data is scattered across different environments and varies by type,” said Tyler Young, CISO of BigID. “That’s why solutions like BigID that enable organizations to know and control their data become ever more critical.”

Consequently, 87% of respondents said that to help win the war against ransomware, data and cybersecurity vendors must collaborate to provide complete and integrated anti-ransomware solutions, and 9 in 10 respondents feel their business would benefit from a data security and management platform that provides insights on their overall security posture and cyber resilience.

“The only way to achieve cyber resilience is by prioritizing proactive security measures that will prevent cyberattacks in the first place,” said Ray Komar, vice president of technology and cloud alliances, Tenable. “This approach should also extend to backup and recovery measures to ensure business continuity in the event of a cybersecurity incident. This requires organizations to not only manage their cyber risk, but better understand their exposure to risk by leveraging vulnerability and exposure data to make informed decisions on remediation efforts.”

This is especially urgent given that adequate data backup and recovery services are critical to have in order to qualify for cyber insurance – and not all solutions are created equal. While almost 3 in 4 (74%) respondents confirmed their company has cyber insurance, close to half (46%) of all respondents said it is now harder to obtain cyber insurance than it was in 2020. Respondents also shared the three most critical technologies or capabilities required to secure cyber insurance are: “strong encryption” (40%), the “ability to verify the integrity of backups” (38%) and MFA (37%) as their top needs.

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3