Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Organisations think "only a matter of time" before an APT hits

by The Gurus
July 9, 2014
in Editor's News
Share on FacebookShare on Twitter

Only 15 per cent of information security professionals say that they are “very prepared” for a targeted attack, yet one in five have experienced such an incident.
 
According to a study of 1,220 security professionals by ISACA, 66 per cent believe it’s only a matter of time before their enterprise is hit by an APT. Despite one in five being a victim, only one in three could determine the source.
 
Steven Babb, international vice president of ISACA, said: “Work remains to be done to ensure that APT’s are fully understood and that investment to mitigate this risk is focused in the right areas. ISACA’s recently launched Cybersecurity Nexus programme has been devised to help address Cybersecurity challenges, including APT’s.”
 
The ISACA survey found that the majority of responding organisations say their primary APT defense is technical controls such as firewalls, access lists and anti-virus, which it said are not sufficient for preventing APT attacks.
 
Also nearly 40 per cent of enterprises report that they are not using user security training and controls to defend against APTs, yet less than 30 per cent are not using mobile controls, even though 88 per cent of respondents recognise that employees’ mobile devices are often the gateway to an APT attack.
 
Mark Sparshott, director of EMEA at Proofpoint, said: “The fact that 50 per cent of security professionals who responded to the survey do not see APTs as highly differentiated from traditional attacks means that 50 per cent of those interviewed should consider a career change.”
 
While more enterprises report that they are adjusting vendor management practices (23 percent) and incident response plans (56 percent) to address APTs this year, the numbers still need significant improvement.
 
Rory Innes, head of cyber security at the Salamanca Group, told IT Security Guru that nine out of ten businesses do not need to buy new technology to defend themselves, as they can work with what they have already got. “They have got people and process, but they need to convince the C-suite to spend on IT security, and there is always a feeling that they do not know if it makes a difference, but they have to build it into their risk appetite,” he said.
 
“There is a certain amount of cycnicism on the latest trends and what the press write about APTs and breaches, but APTs are not necessarily complex as it can be with basic methods and the attacker is just looking for a return on investment as most organisations don’t know how to good change or patch management.”

Tags: APTattack
ShareTweet
Previous Post

Third of security professionals do not encrypt communications

Next Post

While businesses still run XP, Microsoft prepares end of Windows 7

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol