54% of firms will increase their cyber-security budgets in 2019
Over half of all organisations will increase their cyber-security spending this year, with almost a third of them planning to boost their cyber-security budgets by 10 to 20 percent, eSecurity Planet's 2019 State of IT Security survey has found.
The detailed survey of CEOs, CIOs and IT security professionals at a large number of organisations of all sizes also noted that over half of all organisations (57 percent) are also planning to hire additional IT security professionals this year. The renewed spending on cyber-security has been driven mostly by the fear of data breaches and the arrival of new privacy regulations such as GDPR.
Michael Kerner, a senior security editor for eSecurity Planet, said that the responses to the survey indicate that organisations are responding to the challenges and are not idly sitting by waiting for the next breach. According to the report, in order to counter increasingly sophisticated attacks and protect data from breaches that could lead to steep fines under the EU's GDPR, organisations have begun purchasing security products in large numbers.
CEOs, CIOs and security professionals interviewed by eSecurity Planet said that while IT services companies are looking to buy the latest web gateways, network access control, DLP, deception technology, UEBA, phishing simulation and patch management solutions, leading business services firms are going for DLP, SIEM and DDoS protection solutions.
While one in four CEOs, CIOs, and security professionals at organisations trust network access controls the most, 24.2 percent of them are planning to deploy DNS filtering solutions, 20.8 percent are planning to deploy antivirus solutions and another 20 percent are planning to deploy web gateways.
However, many organisations are also shunning some security solutions as they believe such solutions are ineffective against emerging cyber-threats. While one in four IT security professionals do not trust phishing simulation products, 20 percent are unconvinced about the effectiveness of breach and attack simulation (BAS) technology.
The report also noted that while two-thirds of organisations are conducting penetration testing at least once a year, another 60 percent are also conducting threat-hunting exercises annually to prepare for cyber-attacks. They are doing so to address their concerns about database security, advanced persistent threats (APTs), DDoS attacks, insider threats and ransomware.
Even though it is encouraging to note that over half of organisations are willing to invest their money in securing and protecting customer data, almost 70 percent of organisations that are hiking their budgets are mid-sized or large organisations, indicating that a vast majority of small businesses that process customer data are either unwilling or unable to increase their cyber-security budgets or hire additional IT security personnel.
Security Planet also noted that of those organisations that will be unable to increase their cyber-security budgets this year, 62 percent are companies that employ fewer than 100 staff.
Commenting on the survey's findings, Ilia Kolochenko, CEO of High-Tech Bridge, told SC Media UK that spending more does not necessarily means spending better as doing so lures organisations into a false sense of security considering that many organisations still do not have a risk-based, long-term cyber-security strategy to allocate necessary resources and authority within the security team in a consistent and coherent manner.
"Few organisations have an up-to-date and comprehensive inventory of their digital assets, leaving many systems and applications without maintenance or updates. The problem is aggravated by IoT proliferation, BYOD, cloud and data sharing with third-parties. Ultimately, today very few organisations have a holistic control over their data.
"They increasingly spend more, but often the increase is spent on general expansion of IT infrastructure (eg, they need more or upgraded licenses from the same vendors), rather than the higher priority of cyber-security in their corporate risk mitigation plan.
He added that scared by exorbitant FUD (fear, uncertainty and doubt) in the media and from some vendors, organisations’ desultory spend on various consultants to attain paper-based compliance often ignore practical aspects of security. They distract their security personnel from more important tasks thereby skyrocketing their susceptibility to data breaches.
"Eventually, cyber-security professionals start suffering from burnout and their productivity falls. I believe that with a proper cyber-security strategy, most organisations will not only manage to handle their cyber-security without new hires, but will manage to cut [unnecessary] cyber-security spending," he added.
Latest Jobs
-
- Azure Identity Consultant
- Netherlands
- discussed on applications
-
Are you a cybersecurity expert passionate about identity and access management? We are seeking a talented IAM Technical Specialist to join our Sec Ops team. In this role, you will play a pivotal part in developing and maintaining our IAM infrastructure, ensuring the highest levels of security and compliance. What you'll do: Design, implement, and maintain IAM solutions for both on-premise and cloud environments. Collaborate with cross-functional teams to integrate IAM systems into various applications and processes. Conduct security assessments and risk analysis to identify and mitigate vulnerabilities. Stay up-to-date with the latest IAM technologies and industry best practices. What we're looking for: Experience: experience as a technical specialist with expertise in AD management. IGA concepts: Experience with Identity Governance and Administration (IGA) concepts such as RBAC, PAM, SIEM, SSO, segregation of duties (SoD), data classification, and recertification. Azure Identity Management: Minimum 2 years of demonstrable experience with Azure identity management, specifically within complex organizations. IT knowledge: Good general knowledge of IT environments such as Active Directory, Azure Cloud, Office 365, SharePoint Online, etc. Protocol knowledge: Familiar with SAML, OIDC, OAuth, and SCIM. Programming languages: Minimum 3 years of experience with development languages such as PowerShell; knowledge of Java or C# is a plus.
-
- Cloud Architect- German Speaker
- Hungary
- Upto €48000 per year + bonus + benefits
-
As a Senior Pre-Sales Solutions Architect, you will play a pivotal role in driving our sales success by translating complex technical solutions into compelling proposals that resonate with our clients. You will collaborate closely with our sales teams to understand customer needs, design tailored solutions, and negotiate successful deals. Responsibilities: Solution Design: Develop comprehensive technical solutions that align with customer business objectives and industry best practices. Proposal Development: Create compelling proposals, including requirements gathering questionnaires, presentation materials, and Statements of Work (SOWs). Customer Engagement: Build strong relationships with clients, understanding their technical, business, and commercial requirements. Collaboration: Work closely with sales teams, delivery teams, and third-party partners to ensure successful project execution. Pricing Strategy: Define and deliver pricing strategies that align with customer needs and company objectives. Requirements: Experience in technical pre-sales or sales support roles. Proven track record in designing and delivering successful customer solutions. Strong technical foundation in areas such as VMware, Azure, AWS, cloud computing, and data center technologies. Excellent understanding of sales principles, account management, and negotiation techniques. Ability to explain complex technical concepts clearly and concisely. Experience working in international teams and supporting clients across multiple regions. Fluency in German and English is essential. Benefits: Competitive salary and benefits package Opportunity to work on challenging and rewarding projects Collaborative and supportive work environment Potential for career growth and advancement Please note that this role is focused on supporting German clients, but will also involve global client support as needed.
-
- Microsoft Sentinel Architect
- United Kingdom
- discussed on applications
-
Microsoft Sentinel Architect We're seeking a talented and experienced Microsoft Sentinel Architect to be responsible for the design, deploy of a new Sentinel solution into an expanding Services business. As a key member of our team, you'll play a vital role in driving security operations and protecting clients' assets. Responsibilities: Solution Design: Develop comprehensive Microsoft Sentinel architectures aligned with our clients' specific needs and industry best practices. Deployment and Configuration: Oversee the deployment and configuration of Sentinel components, including data connectors, analytics rules, and playbooks. Integration: Integrate Sentinel with other security tools and platforms within our MSSP ecosystem. Tuning and Optimization: Continuously monitor and optimize Sentinel performance to ensure maximum effectiveness and efficiency. Training and Mentoring: Mentor junior team members and provide training on Sentinel technologies and best practices. Required Skills and Experience: Proven experience as a Microsoft Sentinel Architect with a deep understanding of its capabilities and limitations. Strong technical skills in Azure, security operations, and data analytics. Experience designing and implementing complex security solutions, into a services environment Knowledge of threat intelligence, incident response, and compliance frameworks. Excellent communication and problem-solving skills.
-
- Network & Security Consultant
- Romania
- €54000 plus benefits
-
Senior Network & Security Engineer to join a Managed Network & Security Team in Europe. In this critical role, you will: Play a pivotal role in managing and securing network infrastructure across datacenters, customer connections, and on-premise deployments. Proactively monitor network and security devices, analyse incidents, and implement solutions to ensure optimal performance and security. Collaborate with colleagues and customers to troubleshoot issues, troubleshoot outages, and implement effective resolutions. Lead and participate in network system installations for new facilities and expansions. Develop and maintain network infrastructure procedures, recommend technical strategies, and propose improvements to enhance network capabilities. Stay up-to-date on the latest network and security technologies and trends. Work as part of a collaborative international team, contributing to team presentations and knowledge sharing. To be successful, you'll need: Proven expertise in Cisco network solutions (CCNP R&S/Sec/Wireless preferred) for both BAU and project work. In-depth knowledge of network security principles and experience with Fortinet firewalls. Experience deploying and managing large, complex network infrastructure (routing, switching, wireless, security). Solid understanding of ITIL v3 framework for incident, change, and problem management. Excellent troubleshooting skills with experience using Wireshark or similar protocol analysers. Strong communication and teamwork skills, with the ability to work independently and collaborate effectively.