UK cyber-security preparedness lags behind awareness
.jpg)
Awareness of cyber-security threats and the need to address it is unprecedentedly strong among global organisations. However, the awareness has not translated into preparedness, said NTT’s global survey. The disparity is stark in European companies, particularly those in the UK, said the report.
More than 90 percent respondents in the UK believe that strong cyber-security is more important than growing revenue and profit (78 percent) to their business over the next 12 months, said the survey.
"Far too few companies – only 58 percent – have a formal security policy. That’s up just one percent from last year," said the report. Of those, only 48 percent said that their employees were fully aware of the policy, putting the total number of companies with fully-understood policies at just 28 percent.
There is still a shocking failure of security policy being understood – or even known about – in the wider workforce, said Maxine Holt, enterprise technology research director at UK-based cyber-security company Ovum.
"At an IT event recently, I witnessed 60 percent of laptops left unlocked whilst unattended – this was in an environment where those individuals worked for rival companies. On a train last month I saw someone had left their locked laptop on a seat – with their user ID and password on a post-it note stuck to the laptop," she recalled.
Budgetary concerns and lack of qualified staff complicates the situation. More than 40 percent of organisations lack the necessary skills and resources to cope with the number of cyber-security threats, found the survey. The figure was 46 percent for the UK, while only 38 percent of Swiss and French companies reported a lack of qualified staff.
"Large organisations with deep pockets frequently attract skilled security people, leaving smaller enterprises to struggle with security challenges with little in-house expertise. There are pockets of initiatives taking place around the country (and indeed the globe) to build security expertise, but this is in no way sufficient to deal with today’s workforce shortages," said Ovum’s Holt.
Exacerbating the situation is the lack of coordination in cyber-security efforts, with only 72 percent of the respondents acknowledging it as a boardroom issue. "Nearly half of all respondents (45 percent) say that cyber-security is the IT department’s problem. This rises to 57 percent for C-level respondents, which demonstrates an alarming hands-off attitude to cyber-risk in the organisations concerned," said the report.
The chinks in the cyber-defence armour are increasing, so is the willingness to surrender to ransom demands. The organisations that would consider paying a ransom in 2019 remained unchanged at 33 percent, while a higher number (36 percent) conceded that they would rather pay a ransom than get a fine for non-compliance.
"Cyber-criminals have developed a more diverse and stealthy network of ransomware operations by devising intelligent ways of using the leak data for commercial and national security implications," said Azeem Aleem, VP at NTT Security. "Cyber-criminals are not bound by any rules; their attacks are shielded and hidden across the organisational network."
The monetary value of the attacks prove the gravity of the situation. According to the respondents, it will cost more than 12 percent of the organisation’s revenue to recover from a breach, up from 10.3 percent in 2018 and 9.9 percent in 2017. Respondents estimated recovery time of 66 days on average, up nine days from 57 days last year.
There is still a lack of confidence in law enforcement agencies’ capabilities to tackle these advanced attacks, Aleem observed. "Incidents have shown in the past that the moment organisations approach law enforcement agencies, cyber-criminals leak their data online, therefore undermining confidence in the security of the company."
"Security is not a do-once project. It is a culture, an approach, an ethos in an organisation. UK companies should pay more than lip-service to security, despite the challenges they should focus on developing the ability to prevent, detect, and respond to cyber-attacks, devote time and resources to building expertise in-house," said Holt.
source scmagazineuk

Latest Jobs
-
- Contact 12 month- Security Operations- Crowdstrike Falcon Insight EDR / Analyst.
- United Kingdom
- Dependent on experience
-
Security Operations engineer / Analyst with Crowdstrike Falcon Insight EDR experience for a 12 month contract. Experienced Contractor with Crowdstrike Falcon Insight: Endpoint detection and Response (EDR) experience needed - 12 month rolling project. Implementation, configuration and Analyst experience needed with Crowdstrike Falcon Insight: (EDR) Migration project- relocating capability internationally. technically implementing, configuration of that that migration and then transition to BAU role monitoring. DCL Search exclusive associate Project.
-
- SailPoint Consultant
- London
- Upto £75,000 plus benefits
-
SailPoint Consultant is needed for an expanding Financial Service business, this is an exciting time to join the Business as they are in the Process of deploying both IAM and PAM solutions and this consultant will form a key part of the IAM team Location can be flexible but would require the individual to come into the London office a couple of times a month for team meetings and face to face project reviews Duties include · Engage in the Identity & Access Management project to deliver SailPoint IdentityNow and Privileged Access Management · On-board applications and users into IAM tools and customise or configure integrations as required · Regularly review, secure and recertify privileged roles in applications, databases and operating systems · Implement least privilege, just-in-time access, password rotation and vaulting wherever possible · Migrate application authentication to Single Sign-On through the use of SAML and OAuth · Implement and enforce the use of MFA where possible, focusing on critical applications and risky sign-ins · Provide technical support to Centrify and SailPoint users Key experience required: Previous experience with SailPoint, including integrating and deploying into a business, onboarding users and applications, supporting users and performing manual administration tasks. Experience with SAML and OAuth to migrate applications to Single Sign-on. If you are interested in hearing more please reach out to me for more information
-
- Centrify Consultant
- London
- Upto £75,000 plus benefits
-
A Privileged Access Management Consultant is needed for an expanding Financial Service business, this is an exciting time to join the Business as they are in the Process of deploying a Centrify PAM solution,, this consultant will form a key part of the team Location can be flexible but would require the individual to come into the London office a couple of times a month for team meetings and face to face project reviews Duties include · On-board applications and users into PAM tools and customise or configure integrations as required · Regularly review, secure and recertify privileged roles in applications, databases and operating systems · Implement least privilege, just-in-time access, password rotation and vaulting wherever possible · Migrate application authentication to Single Sign-On through the use of SAML and OAuth · Implement and enforce the use of MFA where possible, focusing on critical applications and risky sign-ins · Provide technical support to Centrify users You would also gain expsoure with the IAM toolset as part of an Identity Access deployment. Key experience required: Previous experience with a PAM tool (Centrify would be an added bonus but not essential) including integrating and deploying into a business, onboarding users and applications, supporting users and performing manual administration tasks. Experience with SAML and OAuth to migrate applications to Single Sign-on. If you are interested in hearing more please reach out to me for more information
-
- SOC team lead- Deputy SOC manager - Managed Security Services, Bradford. Exclusive
- Bradford
- £70,000 +
-
SOC team lead- Deputy SOC Manager - Managed Cyber Security Services, Bradford. Exclusive Identifier project. Technical team lead needed to join a Managed Cyber Security Services business. The role will be a hands on lead role and technical escalation point for the team. You will also be responsible for leading, mentoring, growing and developing the team. You will be the deputy SOC manager and be involved in the strategic growth of the capability. A managed security services background is essential, specifically within a managed security operations capability. Current hands on support experience across Firewall, SIEM, Incident Response is essential.