A vast majority of global organizations reported they would “somewhat to very likely” suffer one or more serious cyberattacks in the next 12 months, according to Trend Micro’s latest Cyber Risk Index (CRI) report.
The index measures the gap between respondents’ cybersecurity preparedness and their likelihood of being attacked. It surveyed more than 3,600 organizations and industries around the world in the first half of 2021.
The findings showed that most businesses expect to be impacted by a cyberattack in the near future. And 80% of global organizations reported that they are likely to experience a data breach that impacts customer data within a year.
Meanwhile, nearly one-quarter of organizations surveyed said they suffered more than seven cyberattacks that infiltrated their networks or systems over the past year. While one-fifth reported more than seven breaches of information assets and a similar number experienced more than seven breaches of customer data, which was a slight increase from the last report.
Businesses are “realizing that this is the nature of the game today that [I will get breached],” said Jon Clay, VP of threat intelligence at Trend Micro.
Clay added that those organizations have started to think about steps to improve their preparedness and incident response process. Based on the survey results, he explained that organizations should locate all the assets and physical devices on their network and evaluate the potential impact of a key data compromised event when reviewing their current security posture and future plans.
The US has the Highest Cybersecurity Risk LevelAccording to the report, North America has the highest risk level and lowest perceived readiness compared to other regions.
Trend Micro’s CRI is based on a numerical scale of -10 to 10 (-10 representing the highest level of risk). The CRI for the U.S. jumped from -0.14 in 2018, to -1.27 in 2021. The current global average is -0.42, while Latin/South America marks the lowest level of risk with 0.06.
The Biden administration recently released an executive order on improving the nation’s cybersecurity posture. Trend Micro COO Kevin Simzer said he is thrilled to see that the U.S. administration took some steps forward. However, “there is a lot more that needs to be done,” he said.
“Personally, I subscribe to the carrot-and-stick model where there could be some incentives for companies to adopt certain frameworks,” Simzer said in an interview with SDxCentral. He noted the government could include a safe-harbor provision in the security framework as incentives. If there is a breach, the companies are protected by law from class-action lawsuits after implementing this framework.
Clay added that one of the top risks exposed in the survey is that organizations are unprepared to share threat intelligence with other companies and governments. “I think the private-public partnership needs to improve in that area,” he explained.
Top Cybersecurity RisksThe report listed organizational misalignment and complexity, along with cloud computing infrastructure and providers as the top two infrastructure security risks.
Organizations have continually added more security layers and solutions into their network, which causes challenges, Clay said. Companies should focus on their overall security framework, and utilize automation in certain areas, including artificial intelligence (AI) and machine learning (ML) practices, he suggested.
Clay added that cloud computing infrastructure is a shared responsibility model. “One of the predictions we made for 2021 is that any cloud breach this year will not be caused by the providers; it will almost all be [caused] by the organization that got victimized,” he said.
Trend Micro’s executives recommended that companies rethink cybersecurity and shift security left to to the application development process.
Comments