UK cyber-security preparedness lags behind awareness
Awareness of cyber-security threats and the need to address it is unprecedentedly strong among global organisations. However, the awareness has not translated into preparedness, said NTT’s global survey. The disparity is stark in European companies, particularly those in the UK, said the report.
More than 90 percent respondents in the UK believe that strong cyber-security is more important than growing revenue and profit (78 percent) to their business over the next 12 months, said the survey.
"Far too few companies – only 58 percent – have a formal security policy. That’s up just one percent from last year," said the report. Of those, only 48 percent said that their employees were fully aware of the policy, putting the total number of companies with fully-understood policies at just 28 percent.
There is still a shocking failure of security policy being understood – or even known about – in the wider workforce, said Maxine Holt, enterprise technology research director at UK-based cyber-security company Ovum.
"At an IT event recently, I witnessed 60 percent of laptops left unlocked whilst unattended – this was in an environment where those individuals worked for rival companies. On a train last month I saw someone had left their locked laptop on a seat – with their user ID and password on a post-it note stuck to the laptop," she recalled.
Budgetary concerns and lack of qualified staff complicates the situation. More than 40 percent of organisations lack the necessary skills and resources to cope with the number of cyber-security threats, found the survey. The figure was 46 percent for the UK, while only 38 percent of Swiss and French companies reported a lack of qualified staff.
"Large organisations with deep pockets frequently attract skilled security people, leaving smaller enterprises to struggle with security challenges with little in-house expertise. There are pockets of initiatives taking place around the country (and indeed the globe) to build security expertise, but this is in no way sufficient to deal with today’s workforce shortages," said Ovum’s Holt.
Exacerbating the situation is the lack of coordination in cyber-security efforts, with only 72 percent of the respondents acknowledging it as a boardroom issue. "Nearly half of all respondents (45 percent) say that cyber-security is the IT department’s problem. This rises to 57 percent for C-level respondents, which demonstrates an alarming hands-off attitude to cyber-risk in the organisations concerned," said the report.
The chinks in the cyber-defence armour are increasing, so is the willingness to surrender to ransom demands. The organisations that would consider paying a ransom in 2019 remained unchanged at 33 percent, while a higher number (36 percent) conceded that they would rather pay a ransom than get a fine for non-compliance.
"Cyber-criminals have developed a more diverse and stealthy network of ransomware operations by devising intelligent ways of using the leak data for commercial and national security implications," said Azeem Aleem, VP at NTT Security. "Cyber-criminals are not bound by any rules; their attacks are shielded and hidden across the organisational network."
The monetary value of the attacks prove the gravity of the situation. According to the respondents, it will cost more than 12 percent of the organisation’s revenue to recover from a breach, up from 10.3 percent in 2018 and 9.9 percent in 2017. Respondents estimated recovery time of 66 days on average, up nine days from 57 days last year.
There is still a lack of confidence in law enforcement agencies’ capabilities to tackle these advanced attacks, Aleem observed. "Incidents have shown in the past that the moment organisations approach law enforcement agencies, cyber-criminals leak their data online, therefore undermining confidence in the security of the company."
"Security is not a do-once project. It is a culture, an approach, an ethos in an organisation. UK companies should pay more than lip-service to security, despite the challenges they should focus on developing the ability to prevent, detect, and respond to cyber-attacks, devote time and resources to building expertise in-house," said Holt.
- Head of Penetration Testing, UK based, Flexible location.
- United Kingdom
- Upto £100,000 plus excellent benefits
Head of Penetration Testing needed to join a security consultancy that are delivering client facing penetration testing services around Web app and Infrastructure. Looking for someone hands on that is able to manage a highly skilled technical team of testers. 50-60% of the time is expected to be hands on, other duties will include, but not be limited to; leading and managing the day to day running of the team, mentoring, team upskill, recruitment, reporting, escalation, process improvement etc. Flexible location although south east is preferred. Anyone with Check / CREST experience is highly desirable. MUST be able to achieve SC clearance. UK based role. All details kept in confidence.
- Technical Security Analyst. Immediate opportunity,
- Newcastle upon Tyne
Technical Security Analyst. Immediate opportunity, Technical Security Analyst needed to join a specialist security team. This role will require travel into the office in a hybrid model once industry returns back to the working environment. The Security Analyst must be commutable to Newcastle upon Tyne. This is an Immediate opportunity. An essential requirement of the role is to be able to engage with internal stakeholders so a blend off technical hands on analytical and consultative communication skills. The role will include, but not be limited to; managing and handling incidents end to end, log review, incident analysis, escalation, vulnerability assessment, Automation, Malware Analysis, Threat intelligence, etc All details kept in confidence. https://calendly.com/chris-holt/call-with-chris-holt-dcl-search
- Security Analyst, London. Financial Services. End user.
CH7885. Security Analyst, London. Financial Services. End user. Immediate role. £55,000 Security Analyst needed to monitor and manage a security suite of tools within Financial Servicecs end user . The Security Analyst will be responsible monitoring, configuring, fine tuning, incident management and generally improving the security tool capability. Specific experience with CyberArk, Tripwire Log Center and Tripwire Enterprise is highly desirable). Current experience with Vulnerability management and penetration testing is highly desirable. Specifically the ability to effectively manage 3rd party pen tests. You will be working within a specialist security team reporting to the CISO. Experience working within a regulated end user environment within financial services is highly desirable. This role will run a hyrbid working schedule, partly remote, partly office based in London (once permitted) This is an exclusive role to DCL Search & Selection. https://calendly.com/chris-holt/call-with-chris-holt-dcl-search
- IAM Consultant- Identity Governance
- United Kingdom
- Upto £80,000 plus benefits
Identity and Access Management Consutlant is required for this established business who put their employees first. the role entails • Develop and maintain IAM services. • Further develop IAM tool integration with Service Now to provide automated JML processes and application access requests and fulfilment. • Provide guidance over Role Based Access in terms of Location based Roles, Application Roles and Business Roles and act as SME over any future RBAC project. • Work closely with our other Technology teams on integrating IAM services with Technology and business systems to increase efficiency through automation around areas such as JML processes, application access request fulfilment and attestation. • Work with the Governance Risk & Compliance (GRC) team to provide application access attestations and toxic combination alerting and reporting. • Involvement with Identity Management initiatives such as Single Sign On (SSO) and Privileged Access Management (PAM), to ensure security and business processes are in line with industry best practice. • Assist in ensuring that all IAM capabilities are mapped to internal processes, policies, and standards. Develop metrics to measure and improve the alignment. • Complete monthly review and report on sensitive group access, i.e., service accounts, admin accounts, etc. validating I&O processes are effective. • Provide information to both internal and external Auditors in response to findings. • Collate audit evidence for AAF audit and control reviews, taking responsibility for identifying service and process improvements to ensure compliance with our controls and standards. We are looking for someone with Hands on technical experience with the IAM tools, you need to have been involved in the integration of the IAM solution into 3rd party software like Servicenow, You will have worked with an IAM tools that are focused into Identity Goveranance, like RSA, CA Identity Suite, Fischer Identity, Hid Global, IBM IGL, Net IQ Identity Goverance, Omada, Ping or Oracle Post covid, this role will invovle a mix of home and office work, the business have a number of office spread across the UK so locaton is flexible for this position