Brian Sims
Editor

Essential cyber security tasks “challenging” finds Sophos survey

CYBER SECURITY-as-a-Service company Sophos has published its report entitled ‘The State of Cyber Security 2023: The Business Impact of Adversaries on Defenders’, which finds that, globally, 93% of those organisations surveyed find the execution of some essential cyber security tasks (such as threat hunting) to be “challenging”.

The challenges encountered include understanding how an attack happened, with 75% of respondents stating they have challenges when it comes to identifying the root cause of an incident. This can render proper remediation difficult, leaving organisations vulnerable to repetitive and/or multiple attacks perpetrated by the same or different adversaries.

Further, 71% of those organisations surveyed have reported challenges with timely remediation. The same percentage experience challenges in understanding which signals/alerts to investigate, and the same percentage again have reported challenges in terms of prioritising investigations.

John Shier, field CTO for the commercial sector at Sophos, commented: “Only one-fifth of respondents considered vulnerabilities and remote services to be a foremost cyber security risk for 2023, yet the ‘on the ground’ truth is that these are routinely exploited by active adversaries. This cascade of operational issues means that these organisations are not seeing the full picture and, potentially at least, acting on incorrect information. There’s nothing worse than being confidently wrong. Having external audits and monitoring in place helps to eliminate blind spots.”

Additional findings

Additional findings of the Sophos survey include the following:

*52% of those organisations surveyed suggested that cyber threats are now too advanced for them to deal with on their own

*64% wish the IT team could spend more time on strategic issues and less time on firefighting

*55% noted that the time spent on cyber threats has impacted the IT team’s work on other projects

*94% of respondents are working with external specialists to scale their operations, but the majority still remain involved with managing threats rather than adopting a fully outsourced approach

Co-ordinated response

“Today’s threats require a timely and co-ordinated response,” explained Shier. “Unfortunately, too many organisations are stuck in reactive mode. Not only is this having an impact on core business priorities, but it also has a sizeable human toll, with over 50% of respondents stating that the threat of cyber attacks is keeping them awake at night.”

According to Shier, eliminating the guesswork and applying defensive controls based on actionable intelligence will allow IT teams to focus their attentions on enabling the business instead of “trying to douse the eternal flame” of active attacks.

*Download ‘The State of Cyber Security 2023: The Business Impact of Adversaries on Defenders’ by visiting the Sophos website

**Data from ‘The State of Cyber Security 2023: The Business Impact of Adversaries on Defenders’ was realised from an independent study of 3,000 leaders responsible for IT/cyber security in businesses spanning 14 countries and was conducted in January and February 2023

Company Info

Sophos Ltd

The Pentagon
Abingdon Science Park
The Pentagon; Abingdon Science Park; Bar
Oxford
OX14 3YP
UNITED KINGDOM

Login / Sign up