TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Cyber

Cyber report card

by Mark Rowe

Most organisations are struggling to monitor and prevent cyberattacks on their network. More than one in four have been breached in the past 12 months, while 23 percent arenโ€™t sure if they have been breached or not. That’s all according to a ‘2017 Cybersecurity Report Card’, a survey by DomainTools, a DNS-based cyber threat intelligence product company.

When asked to grade their organizationโ€™s cybersecurity, 43 percent gave themselves a โ€œCโ€, โ€œDโ€, โ€œFโ€, or โ€œnon-existentโ€, and only 15 percent gave themselves an โ€œAโ€. While there isnโ€™t a one-size-fits-all solution to network security, the โ€œAโ€ grade companies have several attributes in common, including a high level of automation, a threat intelligence framework, and robust training for security staff.

Acohido said: โ€œGiven that the sophistication and frequency of cyberattacks are only expected to increase in the next year, any business that touches the internet โ€“ which is nearly all companies โ€“ is highly susceptible to a successful attack on their network. Based on the data from DomainTools new global survey, we know that companies are aware of the cyber dangers and are doing what they can to protect their networks, but knowing is only half the battle. As we have seen from the โ€˜Aโ€™ grade companies, organizations must move beyond human-intensive processes and disparate systems in order to more effectively mitigate potential risk.โ€

Findings include:

One-third of security pros are savvy enough to detect daily attacks, but the looming majority (66 percent) are unaware of the daily onslaught of malicious activity. While malware (76 percent) and spearphishing (56 percent) are the most common types of threat vectors, business email compromise (25 percent) and DDoS attacks (24 percent) are on the rise. Finally, nearly one-third of respondents were the recipients of attempted cyberextortion, also known as ransomware, which cost businesses more than $1 billion in 2016.

Of the 15 percent of companies that gave themselves an โ€œAโ€ grade, the vast majority (82 percent) boast a formalized training program for security staff, virtually all (99 percent) utilize some degree or a high level of automation within their security programs, and 78 percent use threat intelligence to follow up on forensic clues of an attack to protect the company. These attributes compare starkly to lower-graded companies. For example, only 37 percent of the โ€œCโ€ companies and none of the โ€œFโ€ companies have a formalized training program, 63 percent of โ€œDโ€ companies use manual processes and are more likely to think they do not need automated processes. Whatโ€™s more, when asked if they have experienced a network breach in the past 12 months, only 15 percent of โ€œAโ€ companies have, compared to 27 percent of โ€œCโ€ companies, 38 percent of โ€œDโ€ companies, and 63 percent of โ€œFโ€ companies. In addition to more budget (50 percent) and more staff (49 percent), 42 percent of companies that did not grade themselves an โ€œAโ€ said that they need more time to evaluate and install technologies in order to be successful.

The overwhelming number of ways to attack a network naturally begets the need for a variety of protections. Almost all companies use more than one cybersecurity system, including firewalls (63 percent), anti-phishing or other messaging security software (57 percent), Security Information and Event Management (SIEM) systems (52 percent), and threat intelligence platforms (42 percent). More than one quarter (26 percent) spend 26 hours or more per week hunting threats in the network, and the vast majority (78 percent) find value in threat hunting โ€“ specifically in drilling down on forensic clues from phishing emails, such as domain name, IP address, or email address, and disclose that it leads to information that makes the organization more secure. Interestingly, โ€œAโ€ and โ€œBโ€ companies were more likely to follow up on clues and evidence compared to โ€Dโ€ and โ€œFโ€ companies.

Tim Helming, director of product management at DomainTools said: โ€œWith devious hackers leveraging various tactics and threat vectors, itโ€™s clear there is no one-size-fits-all approach to protecting the network. Whatโ€™s interesting about our new global survey data is to see the actual connection between hunting threats and secure networks, as the โ€œAโ€ companies that are more likely to drill down on forensic clues were less likely to be breached compared to the other companies, pointing to some of the necessary components of a more secure network.โ€

About the survey

DomainToolsโ€™s study polled over 550 global security people, working in finance, government, healthcare, retail, and technology industries. Regions include North America, EMEA, APAC and LATAM. The survey was by DomainTools with Byron Acohido in December 2016.

Related News

  • Cyber

    How data poisoning works

    by Mark Rowe

    Data is the foundation of AI, but it could also be its undoing, writes Sam Peters, Chief Product Officer of the platform…

  • Cyber

    Human sides of cyber

    by Mark Rowe

    Most UK IT and cyber people according to a survey fear a serious breach or incident could cost them their job at…

  • Cyber

    Cyberwar documentary

    by Mark Rowe

    A cyberwar documentary Midnight in the War Room will have a premiere on Wednesday, August 5, 2026, during the information security gathering…