Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

EY – Too many organisations fall short in foundational components of cyber security

by The Gurus
September 10, 2020
in Editor's News
Share on FacebookShare on Twitter

A survey of senior security practitioners has found that a third have no real-time insight on cyber risks.

The survey of 1,825 organisations in 60 countries by EY found that 43 per cent of respondents say that their organisation’s total information security budget will stay approximately the same in the coming 12 months, despite increasing threats, while 53 per cent said that a lack of skilled resources is one of the main obstacles challenging their information security program.

Mark Brown, executive director of cyber security and resilience at EY, said: “Too many organisations still fall short in mastering the foundational components of cyber security. The UK Government has attempted to fill this void by introducing the Cyber Essential Scheme. However, today’s findings highlight that organisations are not taking the basic steps, such as setting up a security operations centre or putting in place an incident response plan, and this continues to be a major cause for concern.

“Within the UK, we would recommend organisations engage with UK Government backed initiatives such as Cyber information Sharing Partnership (CISP) and UK CERT as well as establishing internal capabilities to respond to this threat.”

Marcus Ranum, senior strategist at Tenable Network Security, said: “The problem is that a lot of organisations simply aren’t fielding traditional perimeter tools correctly, and then complain that they can’t defend themselves. One company I spoke with recently declared that their firewalls were inadequate, but it turned out that they had every user behind the firewall using Internet Explorer and running with a Java Virtual machine enabled in each browser. If you bypass the firewall then it can’t protect you!

“The belief is that every threat that gets through defences is ‘advanced,’ except that it’s really not. The reality is there are a lot of failures of basic security taking place and the truly advanced stuff doesn’t even show up on the radar screen. The firewall (or anything else by itself) won’t protect you completely.

“Similarly, the traditional perimeter has advanced considerably, and I expect much more complete traffic analysis and sanitisation solutions on the perimeter – a firewall simply isn’t enough. To be successful at thwarting attacks, organisations need a mix of endpoint security, configuration control and patch management, vulnerability assessment and management, and a monitoring and analysis capability to make sure it’s all working. Before we declare any other tech obsolete or, heaven forbid, ‘dead’, could we try deploying it properly first?”

Elena Kharchenko, head of consumer product management at Kaspersky Lab, said: “People who believe that they are safe because cyber criminals will just leave them alone and won’t be interested simply don’t understand the nature of online threats. Hackers don’t usually focus on specific targets, they try to scoop up as many victims as possible.”

Tags: Cyber SecurityEYGovernmentSurvey
ShareTweet
Previous Post

Spam-sent Dyre malware targets Microsoft zero-day

Next Post

Symantec Enterprise Vault.cloud down for at least 12 hours

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol