IT Security

Most feel more vulnerable

by Mark Rowe

Most UK organisations feel somewhat or more vulnerable than they have been to both internal and external threats to sensitive data; according to the European Edition of the 2016 Vormetric Data Threat Report (DTR). Vormetric, a Thales company, offering data protection for physical, virtual, big data, and the cloud,issued the report with analyst firm 451 Research.

Garrett Bekker, senior analyst, information security, at 451 Research and the author of the 2016 report, said: “For UK-based organisations, protecting reputation and brand integrity was the top reason for securing sensitive information at 50 percent. But IT security spending plans tell another story, with compliance the top priority at 48 percent, while reputation and brand protection spending dropped to 45 percent. Clearly, organisations are having trouble prioritising their budgets to best ensure the safety of customers and the viability of their business.”

Findings include:

89 percent of UK organisations feel somewhat or more vulnerable than they have been to both internal and external threats to sensitive data, with 23 percent feeling ‘very or extremely’ vulnerable;

When asked to pick the three most important reasons for securing sensitive data, the top answers were ‘reputation and brand protection’, given by 50 percent of UK organisations, ‘compliance requirements’, given by 47 percent and ‘implementing best security practices’, given by 41 percent;

IT security spending plans contrasted with this, with compliance requirements the top priority at 48 percent while reputation and brand protection dropped to second at 45 percent;

near half, 46 percent of UK organisations have experienced a data breach at some stage, with nearly one in five (19 percent) being breached in the last 12 months;

42 percent of UK respondents planning to adopt Internet of Things (IoT) technologies say protecting sensitive data generated by an IoT device is their biggest security concern;

Planned IT security spending by UK organisations for the next 12 months is highest for ‘network defences’ (42 percent), ‘analysis and correlation tools’ (39 percent) and ‘endpoint and mobile defences’ (38 percent)

Compliance not enough

Although there is a growing appreciation that the impact a data breach has on a brand’s reputation cannot be underestimated, UK organisations continue to strongly associate compliance with security, despite data breaches continuing to affect those that have been certified as compliant.

Compliance does not ensure security, adds Bekker. “As we learned from data theft incidents at companies that had reportedly met compliance mandates (such as TalkTalk, Morrison’s and others), being compliant doesn’t necessarily mean you won’t be breached and have your sensitive data stolen. UK organisations don’t seem to fully appreciate this, with almost half (47 percent) rating compliance as a top reason for protecting data, and with compliance the topmost IT security spending priority (48 percent).”

Spending ineffectively

With nearly one in five UK organisations experiencing a breach in the last 12 months, it is unsurprising that many are planning increased security spending over the coming year. However, most are planning investments in tools like network and endpoint defences which have been proven to be largely ineffective against current threats to company data.

“Enterprises and public sector organisations are under increasing scrutiny from stakeholders and the public where it comes to safeguarding confidential and sensitive information,” said Louise Bulman, Vice President of EMEA for Vormetric. “It’s therefore surprising and concerning that companies are continuing to over-rely on tools that consistently fail against modern, multi‐layered attacks. Technology that concentrates fundamentally on controlling access to data is a far more affective approach, and one which can bring about additional benefits by enabling technologies like cloud, big data and IoT which may otherwise have been deemed too risky.”

The research report is available from Vormetric and can be downloaded at: http://www.vormetric.com/campaigns/datathreat/2016/.

About the report

Responses were from senior IT security executives at large enterprises worldwide, including 100 from UK organisations. This edition of the fourth annual report extends earlier findings of the global report, focusing on responses from IT security leaders in European organisations, which detail IT security spending plans, perceptions of threats to data, rates of data breach failures and data security stances.

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing