마이크로칩 8월
This page was machine-translated and may differ from the original. View original

Over 50% of Global Companies Lack Cyberattack Response Capabilities… Automating Incident Response Platforms Is the Answer

Google 우선 소스Published2019.04.13 07:02
Survey of over 3,600 security and IT professionals
Significantly 77% of surveyed companies do not possess a CSIRP
GDPR compliance rate at only 54%


On the 12th, IBM released the '2019 Corporate Cyberattack Response' report, based on a survey of more than 3,600 security and IT professionals worldwide.
More than 50% of global companies lack cyberattack response capabilities

According to a report conducted jointly with the global security consulting firm Ponemon Institute, more than half of the surveyed companies were found to lack the capability to adequately respond to cybersecurity incidents.

The survey results showed that 77% of responding companies stated they do not have a Computer Security Incident Response Plan (CSIRP) that is consistently applied across the organization. Among the 23% of companies that said they have a response plan, 54% stated that they do not regularly test the plan. Despite it being one year since the implementation of the General Data Protection Regulation (GDPR), the percentage of companies stating they are not fully complying with the regulations reached 46%.

In addition to this, IBM and the Ponemon Institute analyzed the impact of automation on corporate cyberattack response capabilities for the first time this year. Companies utilizing automation were found to possess high capabilities in detecting, preventing, responding to, and deterring cyberattack damage. In particular, they were found to have 25% higher capabilities in cyberattack detection and prevention compared to companies that do not utilize automation. However, only 23% of companies reported utilizing automation within their organizations, while a staggering 77% stated that they utilize it at a moderate or minimal level or not at all.

It was also found that a shortage of security personnel within companies hinders their ability to respond to cyberattacks. 70% of respondents stated that the number of personnel capable of properly managing and testing incident response plans was significantly lower than necessary. Additionally, 48% of companies reported that the excessive number of security tools used within the organization increases operational complexity and reduces visibility into their overall security posture.

Hong Seong-gwang, Managing Director of IBM Korea’s Security Business Unit, said, “Through our research, IBM found that companies can save an average of over $1 million if they respond to cyberattacks within 30 days and prevent the spread of damage,” adding, “To achieve this, it is important for companies to thoroughly establish proactive incident response plans.”

He further emphasized, “We must conduct regular mock tests and secure sufficient personnel, processes, and technology,” adding, “If proper planning is established and investments are made in automation, it is possible to prevent situations where significant expenditures occur in the event of a security incident.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자