Report: 67 Percent of Businesses Lack Confidence of Full Recovery After Cyber Attack

New research commissioned by Cohesity reveals the majority of businesses do not have the necessary cyber resilience strategies or data security capabilities required to address today’s escalating cyber threats and maintain business continuity. Furthermore, their cyber resilience efforts are not keeping pace with cyber threats, with data security and recovery technology deficiencies reducing cyber insurance eligibility and increasing the fallout of a successful attack.

In comparing the cybersecurity outlook for 2023 to 2022, 93% of respondents said they felt the threat of ransomware attacks to their industry had increased in 2023. Alarmingly, almost half of respondents (45%) confirmed their business had been the victim of a ransomware attack in the prior six months. Respondents also revealed that their business’ cyber resilience and data security capabilities have not kept pace, with 80% expressing concerns about their organization’s cyber resilience strategy and whether it can ‘address today’s escalating cyber challenges and threats’.

Business continuity is critical even when adverse cyber events arise, however, businesses are slow to respond because they lack the capability to recover data and restore business processes quickly. When asked how long their organization would take to recover data and business processes if a cyberattack occurred? Over 95% of respondents revealed their business would need over 24 hours, 71% said it would take more than 4 days, while a fourth (41%) of respondents said over a week would be required.

Unsurprisingly, two-thirds respondents (67%) lack full confidence that their company could recover their data and critical business processes in the event of a system-wide cyberattack. Diving deeper into cyber resilience and data recovery expectations versus reality, 90% of respondents said their business would consider paying a ransom, with close to 3 in 4 (74%) saying ‘Yes’ their organization would pay, if it meant being able to recover data and business processes, or recover faster.

“Companies cannot afford to be offline and unable to maintain operations, especially for more than a day. However, the stark reality is that many organizations are vulnerable to leverage from cyber criminals because they are incapable of rapidly recovering their data and business processes when necessary,” said Brian Spanswick, chief information security officer and head of IT, Cohesity. “Therefore, it’s no surprise that 9 in 10 respondents said their business would consider paying a ransom to maintain continuity.”

When asked about the biggest barriers to their organization being able to get back up and running in the event of a successful cyberattack, respondents said their top three challenges were integration between IT and security systems (34%), a lack of coordination between IT and security (33%) and antiquated backup and recovery systems (32%). Further clarity was provided by respondents regarding their ability to secure their data estates, with less than half stating they are confident all their data stored in the cloud (44%) or at the edge (42%) is secure and protected, and less than 3 in 10 (28%) are confident data stored on-premises is secure and protected.

“IT and SecOps must co-own organizations’ cyber resilience outcomes to identify sensitive data and protect, detect, respond, and recover from cyberattacks,” said Spanswick. “Relying on traditional backup and recovery systems, which lack modern data security capabilities, in today’s sophisticated cyber threat landscape is a recipe for disaster. Instead, organizations should seek out data security and management platforms that integrate with their existing cybersecurity solutions and provide visibility into their security posture and improve cyber resilience.”

“It’s not a surprise that over half of organizations still struggle with securing data in the cloud. The reality is most organization’s data is scattered across different environments and varies by type,” said Tyler Young, CISO of BigID. “That’s why solutions like BigID that enable organizations to know and control their data become ever more critical.”

Consequently, 87% of respondents said that to help win the war against ransomware, data and cybersecurity vendors must collaborate to provide complete and integrated anti-ransomware solutions, and 9 in 10 respondents feel their business would benefit from a data security and management platform that provides insights on their overall security posture and cyber resilience.

“The only way to achieve cyber resilience is by prioritizing proactive security measures that will prevent cyberattacks in the first place,” said Ray Komar, vice president of technology and cloud alliances, Tenable. “This approach should also extend to backup and recovery measures to ensure business continuity in the event of a cybersecurity incident. This requires organizations to not only manage their cyber risk, but better understand their exposure to risk by leveraging vulnerability and exposure data to make informed decisions on remediation efforts.”

This is especially urgent given that adequate data backup and recovery services are critical to have in order to qualify for cyber insurance – and not all solutions are created equal. While almost 3 in 4 (74%) respondents confirmed their company has cyber insurance, close to half (46%) of all respondents said it is now harder to obtain cyber insurance than it was in 2020. Respondents also shared the three most critical technologies or capabilities required to secure cyber insurance are: “strong encryption” (40%), the “ability to verify the integrity of backups” (38%) and MFA (37%) as their top needs.

Featured

  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.