This page was machine-translated and may differ from the original. View original
Effectiveness when using over 50 security tools▼
To enhance security recovery capabilities
Specialized security personnel and automation technology are needed
It was found that introducing more than 50 cyber security tools actually reduces the ability to respond to cyber attacks compared to not doing so.
On the 1st, IBM Security conducted a survey of approximately 3,400 security and IT professionals around the world through the Ponemon Institute.

As a result, it was found that while corporate capabilities to prepare for, detect, and respond to cyber attacks improved over the past five years, attack containment capabilities actually decreased by 13%. Furthermore, it was analyzed that the excessive use of security tools and the lack of specific action plans for major attack types were hindering corporate security response activities.
A majority (74%) of organizations do not have a security response plan at all, or if they do, it remains a stopgap measure or is applied inconsistently. The absence of a security response plan can cause significant economic damage in the event of a security incident.
It was found that companies with incident response teams that extensively test incident response plans spend an average of $1.2 million (approximately 1.44 billion KRW) less in the event of a data breach compared to companies that do not.
The main findings of the study are as follows.
Over the past five years, more companies have established enterprise-wide security response plans. In 2015, 18% of responding companies had established security response plans, but this year that figure rose to 26%, an increase of 44%. Companies that properly implement enterprise-wide security response plans were much less likely to experience serious disruptions due to cyber attacks.
The more security tools in use, the more negative effects were observed. On average, survey participants were using more than 45 security tools, and were actually adding about 19 tools whenever dealing with a security incident.
According to self-assessments by companies, groups with more than 50 security tools performed 8% worse in detection and 7% worse in attack response compared to groups using fewer tools. This suggests that having more tools does not guarantee greater effectiveness in security response activities and may even have a counterproductive effect.
Even among companies that have established official security response plans, only 17% have prepared specific action plans for major types of attacks. Preparedness for new attack methods, such as ransomware, was much worse.
◇ Action plans must be updated to counter new threats
Since each type of attack requires a corresponding response technique, companies that have established a systematic action plan in advance can cope with frequently occurring attacks through consistent and repeatable plans.
According to this survey, among companies with an official Cybersecurity Incident Response Plan (CSIRP), only 33%—one-third—had established action plans for specific types of attacks.
Among the minority group operating specific action plans for each attack, response plans for DDoS attacks (64%) and malware (57%) were the most common. While these types of attacks have been the biggest headache for companies to date, new attack types such as ransomware are also on the rise. Despite ransomware attacks surging by nearly 70% in recent years, only 45% of the groups using action plans in this survey had plans in place for ransomware attacks.
Meanwhile, more than half (52%) of the companies had security response plans but had never reviewed them or had not set aside a separate period for review and testing. This indicates that, given the reality where the business operating environment is rapidly changing due to the increase in remote work and new attack methods are constantly emerging, many companies still rely on outdated response plans that do not reflect the latest threats and business environment.
◇ Skilled security personnel and technology to resolve complexity are important
Among the important factors in effectively responding to attacks, the expertise of security personnel took the lead. 61% of survey respondents stated that they were able to strengthen security resiliency thanks to hiring skilled staff. Among respondents who said security resiliency did not improve, 41% cited the lack of skilled personnel as the biggest reason.
Technology was also a differentiating factor in strengthening cybersecurity resilience. Tools for resolving complexity, in particular, received favorable evaluations. Companies with relatively superior cybersecurity resilience stated that visibility into applications and data (57%) and automation tools (55%) play a significant role. 63% of these companies stated that they were able to respond to cyberattacks more effectively thanks to the use of open and interoperable platforms and automation technologies.
Wendi Whitmore, Vice President of IBM X-Force Threat Intelligence, said, “While more companies are developing cybersecurity plans, this is not something that can be done all at once,” adding, “You must also focus on regularly testing, practicing, and re-evaluating your response plans.”
He added, “By utilizing interoperable technologies and automation, complexity issues can be overcome and security incidents can be contained more quickly.”
To enhance security recovery capabilities
Specialized security personnel and automation technology are needed
It was found that introducing more than 50 cyber security tools actually reduces the ability to respond to cyber attacks compared to not doing so.
On the 1st, IBM Security conducted a survey of approximately 3,400 security and IT professionals around the world through the Ponemon Institute.
▲ IBM Security, Security Tools, Too Many Can Be Counterproductive [Photo = IBM]
As a result, it was found that while corporate capabilities to prepare for, detect, and respond to cyber attacks improved over the past five years, attack containment capabilities actually decreased by 13%. Furthermore, it was analyzed that the excessive use of security tools and the lack of specific action plans for major attack types were hindering corporate security response activities.
A majority (74%) of organizations do not have a security response plan at all, or if they do, it remains a stopgap measure or is applied inconsistently. The absence of a security response plan can cause significant economic damage in the event of a security incident.
It was found that companies with incident response teams that extensively test incident response plans spend an average of $1.2 million (approximately 1.44 billion KRW) less in the event of a data breach compared to companies that do not.
The main findings of the study are as follows.
Over the past five years, more companies have established enterprise-wide security response plans. In 2015, 18% of responding companies had established security response plans, but this year that figure rose to 26%, an increase of 44%. Companies that properly implement enterprise-wide security response plans were much less likely to experience serious disruptions due to cyber attacks.
The more security tools in use, the more negative effects were observed. On average, survey participants were using more than 45 security tools, and were actually adding about 19 tools whenever dealing with a security incident.
According to self-assessments by companies, groups with more than 50 security tools performed 8% worse in detection and 7% worse in attack response compared to groups using fewer tools. This suggests that having more tools does not guarantee greater effectiveness in security response activities and may even have a counterproductive effect.
Even among companies that have established official security response plans, only 17% have prepared specific action plans for major types of attacks. Preparedness for new attack methods, such as ransomware, was much worse.
◇ Action plans must be updated to counter new threats
Since each type of attack requires a corresponding response technique, companies that have established a systematic action plan in advance can cope with frequently occurring attacks through consistent and repeatable plans.
According to this survey, among companies with an official Cybersecurity Incident Response Plan (CSIRP), only 33%—one-third—had established action plans for specific types of attacks.
Among the minority group operating specific action plans for each attack, response plans for DDoS attacks (64%) and malware (57%) were the most common. While these types of attacks have been the biggest headache for companies to date, new attack types such as ransomware are also on the rise. Despite ransomware attacks surging by nearly 70% in recent years, only 45% of the groups using action plans in this survey had plans in place for ransomware attacks.
Meanwhile, more than half (52%) of the companies had security response plans but had never reviewed them or had not set aside a separate period for review and testing. This indicates that, given the reality where the business operating environment is rapidly changing due to the increase in remote work and new attack methods are constantly emerging, many companies still rely on outdated response plans that do not reflect the latest threats and business environment.
◇ Skilled security personnel and technology to resolve complexity are important
Among the important factors in effectively responding to attacks, the expertise of security personnel took the lead. 61% of survey respondents stated that they were able to strengthen security resiliency thanks to hiring skilled staff. Among respondents who said security resiliency did not improve, 41% cited the lack of skilled personnel as the biggest reason.
Technology was also a differentiating factor in strengthening cybersecurity resilience. Tools for resolving complexity, in particular, received favorable evaluations. Companies with relatively superior cybersecurity resilience stated that visibility into applications and data (57%) and automation tools (55%) play a significant role. 63% of these companies stated that they were able to respond to cyberattacks more effectively thanks to the use of open and interoperable platforms and automation technologies.
Wendi Whitmore, Vice President of IBM X-Force Threat Intelligence, said, “While more companies are developing cybersecurity plans, this is not something that can be done all at once,” adding, “You must also focus on regularly testing, practicing, and re-evaluating your response plans.”
He added, “By utilizing interoperable technologies and automation, complexity issues can be overcome and security incidents can be contained more quickly.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.













