RiskIQ, the leader in digital threat management, today announced that it has published its 2017 State of Enterprise Digital Defence Report, available for download at https://www.riskiq.com/white-paper/state-of-digital-defense-2017/. The report, based on a survey of 465 information security decision makers in the US and UK, found that business digital transformation and the external threat landscape have outpaced enterprise security capacity. According to respondents, an average of 40 percent of organisations experienced five or more significant security incidents in the past 12 months among most cited external threats: malware, ransomware, phishing, domain and brand abuse, online scams, rogue mobile apps, and social impersonation.
Although confidence in IT security management appears optimistic, overall survey findings showed a contradiction in efficacy and likely investment compared to where incidents have been most impactful. 68 percent of respondents express no to modest confidence to manage digital threats. 70 percent of respondents have no to modest confidence in reducing their digital attack surface, expressing the least confidence in threats against web, brand, and ecosystem assessment.
The majority of those surveyed are aware that some of their digital security measures are immature or ineffective, with only 31 percent expressing high confidence in the likelihood that their organisations can mitigate or prevent digital threats—despite all respondents increasing their near-term digital security spend. Over half of survey respondents expect their near-term digital defence investment to increase between 15 to 25 percent or higher.
Correspondingly, nearly half of respondents view cyber threat intelligence as ‘very important,’ and all respondents saw cyber threat intelligence tools as being very important or somewhat important—especially in fortifying research and in reducing time to respond to external threats. When asked about the value gained by integrating digital threat intelligence and management tools to other security control tools, firewalls, security event management and logging, risk assessment, systems management, and orchestration were regarded as benefiting the most.
- 68% cited no to modest confidence to manage digital threats
- Malware, phishing, domain infringement, online scams, mobile app exposures, and brand abuse were cited as most frequently reported incidents
- Big brands in banking, retail, and consumer goods had the most prevalence of attacks
- 70% cited no to modest confidence in reducing their digital attack surface
- 69% cited no to modest confidence to mitigate or prevent external digital threats
- Digital threat management appears more progressive among organisations in financial services, manufacturing, and consumer goods, as expressed by overall expenditure
- Larger companies felt that they were better able to update control systems and collaborate across departments, perhaps showing the benefits of scale
- Smaller companies felt best able to inform others about the status of external attacks, perhaps reflecting the benefits of having a smaller base to worry about
- 24% of healthcare and pharmaceutical respondents felt little to no confidence in their ability to assess digital risk
- Across industries, an average of 35 tools are employed to thwart web, social, and mobile threats
- 44% of organisations plan to increase digital defence investment by 15-25%, and 14% will increase tool and service expenditure by more than 25%; both U.S. and U.K. have similar spending expectations
- Organisations outsource a third of digital threat management tasks to managed security service providers, and outsourcing will grow by nearly 13% CAGR over the next two years
“We are pleased to sponsor the 2017 State of Enterprise Digital Defence Report. The independent research provides a useful litmus test for the level of exposure, controls, and investment regarding external web, social and mobile threats among global industries,” said Scott Gordon, chief marketing officer at RiskIQ. “The findings validate the need for enterprises to leverage cross-channel intelligence, automation, and resource optimisation as they build out digital defences to reduce operational and reputational risk.”
About the report and research
Independent research for the report, which offers key insights into the current landscape of digital threats and the maturity of defences to protect an organisation’s digital presence, was conducted by IDG Connect. The findings quantify the security management gap and business impact of external web, social, and mobile threats. Survey respondents included 465 IT information security decision makers in organisations with more than 1,000 employees in the U.S. and U.K.
IDG Connect and RiskIQ will share research findings in a webcast entitled “State of Digital Defence – The Specter and Spectrum of Mitigating External Threats,” on Sept. 26 at 8 a.m. PT / 11 a.m. ET / 4 p.m. GMT. Visit https://www.riskiq.com/white-paper/state-of-digital-defense-2017/ to download the full report, https://www.riskiq.com/infographic/the-state-of-digital-defense-2017/ to view the infographic, and http://resources.cio.com/ccd/show/200050618/01567430185663CIOVKLGCAV5D0/ to register for the upcoming webcast.
RiskIQ is the leader in digital threat management, providing the most comprehensive discovery, intelligence, and mitigation of threats associated with an organisation’s digital presence. With more than 75 percent of attacks originating outside the firewall, RiskIQ allows enterprises to gain unified insight and control over web, social, and mobile exposures. Trusted by thousands of security analysts, RiskIQ’s platform combines advanced internet data reconnaissance and analytics to expedite investigations, understand digital attack surfaces, assess risk, and take action to protect business, brand, and customers. Based in San Francisco, the company is backed by Summit Partners, Battery Ventures, Georgian Partners, and MassMutual Ventures. Visit RiskIQ.com or follow us on Twitter.
Try RiskIQ Community Edition for free by visiting https://www.riskiq.com/community/. To learn more about RiskIQ, visit www.riskiq.com.