Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 3 June, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

A Third of Security Professionals Under-Prepared to Defend Cyber Threats

by The Gurus
July 19, 2017
in Editor's News
Share on FacebookShare on Twitter

One in three (32%) security professionals lack effective intelligence to detect and action cyber threats, according to a new survey* from Anomali, the provider of market-leading threat intelligence platforms. The results also revealed that almost a quarter (24%) believe they are at least one year behind the average threat actor, with half of this sample admitting they are trailing by two to five years. This confirms that many organisations are not adequately mitigating cyber risks, despite detection and response being cited as the top security priority by a leading research organisation[1] this year.
 
The survey also signals that organisations struggle to detect malicious activity at the earliest stage of a breach, or learning from past exposures, which leaves numerous vulnerabilities undiscovered.

  • Almost one in five (17%) of respondents haven’t invested in any threat detection tools such as SIEM, paid or open threat feeds, or User and Entity Behaviour Analytics (UEBA)
  • Two-thirds of respondents maintain fewer than 200 days of log data online for analysis/forensics, despite hackers often lurking undetected for this length of time
  • 80% of security professionals do not consult historical logs on a daily basis to investigate past exposure to threats
  • Only 13% compare historical logs with threat feeds/indicators of compromise daily

 
Successful cyber attacks are not “smash and grab” type of events. Rather, cyber criminals typically lurk undetected inside enterprises’ IT systems for 200 days or more before discovery. During this time attackers gain access inside the network, escalate privileges, search for high value information, and ultimately exfiltrate data or perform other malicious activities. This ‘200 day problem’ is an ever-present danger, as a US governmental agency discovered last year that malware existed undetected in its network for close to a year[2]. But survey respondents rarely examine historical records to discover whether a threat actor has entered their system. Just 20% consult past logs daily, 20% weekly, 14% monthly and 22% said never or don’t even know how often. This results in multiple missed opportunities to help prevent a breach.
 
“The ‘200 day problem’ arises from the fact that logs are produced in such massive quantities that typically only 30 days are retained and running searches over long time ranges can take hours or even days to complete,” says Jamie Stone, Vice President, EMEA at Anomali. “Detecting a compromise at the earliest stage possible can identify suspicious or malicious traffic before it penetrates the network or causes harm. It’s imperative to invest in technologies security teams can use to centralise and automate threat detection, not just daily but against historical data as well.”
 
To achieve this, organisations must seek to combine streams of siloed intelligence and understand the importance of logging historical data for future analysis. It is more than likely that a bad actor will re-visit an organisation in case a new vulnerability can be found, or a new strain of threat has been developed that they want to try out. However, the survey additionally discovered that 46% of respondents do not use, or don’t know if they use a threat intelligence platform, which can analyse data in real-time and draw upon retrospective data. The primary reasons cited for not using one were lack of resources (18%) and budget (17%).
 
“Organisations must wake up to the daily reality of cyber-attacks and start viewing security as a business enabler that can support and add value to the business as it transforms and innovates. It’s all too common that IT purchase decisions are driven solely by budget rather than need. Implementing the bare minimum is not an option, bolstering cyber security postures must be prioritised. Solutions such as a threat intelligence platform will enable organisations to proactively detect and respond to the modern cyber adversary,” continued Mr Stone.
A threat intelligence platform (TIP) allows organisations to access all their intelligence feeds from one centralised solution, integrate intelligence with internal security tools, and automate the detection and response to active security threats. A TIP also enables organisations to collaborate with peers in their industry or across sectors and geographies to share threat information and help inoculate each other from new attacks.

FacebookTweetLinkedIn
Tags: CybersecurityTechnology
ShareTweet
Previous Post

WannaCry Fallout: 80% of Brits more worried about how organisations store their data following latest attacks

Next Post

White House 'rumoured to close State Department's only cyber security office' as top diplomat quits

Recent News

A Roadmap for Becoming a Penetration Tester in 2023

A Roadmap for Becoming a Penetration Tester in 2023

May 31, 2023
Electronic tablet with social media icons, hands holding screen.

Research Reveals UK Firms Plan to Embrace New Era of Digital Identity

June 1, 2023
AWS and Salt

Salt Security Attains AWS Security Competency Status 

May 31, 2023
Purple spiral circle. Text reads "Centripetal", san-serif.

Centripetal Extends Innovative CleanINTERNET® Technology to the Cloud

May 31, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information