Nearly half of all enterprises have sacrificed mobile security during the past year, and those organizations were twice as likely to suffer a security compromise, according to Verizon’s latest Mobile Security Index.

The operator’s third annual survey on mobile security concluded that 43% of respondents believe their organization took unnecessary risks with mobile security in 2019 and 39% of respondents experienced a mobile security compromise. Moreover, 66% of those organizations that suffered a compromise deemed the impact “major,” and 55% said it had lasting repercussions, according to Verizon.

Security compromises are also becoming more prevalent, rising from 33% in 2019 and 27% in 2018. However, some organizations appear to be taking the risk more seriously because the number of respondents that reported their organization sacrificed security dipped from a high of 48% in 2019.

While the perceived risk is being addressed more forcefully by some organizations, the reasons for sacrificing security remain. Meeting targets under the guise of expediency was the most commonly stated reason at 62%, followed by matters of convenience at 52%, and profitability targets at 46%. Less than one-third, or 27%, said lack of budget was the cause and 26% cited a lack of expertise, according to the survey.

The operator surveyed 850 people for the study and categorized the results based on industry. Information and media was the hardest hit vertical with 50% suffering a mobile-related compromise, followed by financial services at 47%, manufacturing at 41%, the public sector at 39%, health care at 38%, retail at 30%, and professional services at 27%. The number of small to midsized businesses (SMB) that reported a compromise stood at 28%.

Compromised Risk Drives Security Investment

As expected, organizations that suffered a mobile-related security compromise were also more likely to significantly increase spend on security measures as a result. Nearly half (43%) of companies that had been compromised during the last year either had or reported plans to increase spending in the next year. Meanwhile, only 15% of uncompromised organizations had upped their spending, and 17% of that cohort expected to increase spending in the next 12 months.

Multiple vendors and industry associations are targeting these security threats, equipping organizations with tools and processes to mitigate risk, but more than one-third of U.S. residents also now live in a state where comprehensive privacy legislation has been enacted or will soon become law. Despite the growing threat of regulatory penalties, only 33% of survey respondents said their organization is concerned about that outcome. However, 67% said increased legislation is leading to greater investment in security overall.

Verizon also quantified the most prevalent consequences of mobile-related compromises, lead by downtime at 59%, data loss at 56%, compromise of other devices at 46%, damage to their reputation at 37%, and loss of business at 19%.

“The types of devices, diverse applications, and further emergence of IoT devices further complicate security,” said Bryan Sartin, executive director of Verizon’s global security services division, in a prepared statement. “Everyone has to be deliberate and diligent about mobile security to protect themselves and their customers.

The cloud, which now stores or gathers the majority of new business information, remains the most likely entry point for these threats, according to Verizon. And within five years, mobile will be the primary means of accessing cloud services, according to 80% of the survey’s respondents.

The continued proliferation of cloud-based apps and services is profound. Verizon cited a report from Netskope that concluded the average enterprise uses more than 1,295 apps and cloud services, and more than 95% of those are unmanaged by IT.