This page was machine-translated and may differ from the original. View original
Fortinet and IDG Korea Announce Survey Results on 'Domestic APT Security Awareness and Adoption Status'
The greatest threat to organizations is attacks
Malware such as ransomware and spyware was cited (45.2%)
Fortinet Korea announced today the results of a survey on the "Current Status of Domestic APT Security Awareness and Adoption," conducted jointly with IDG Korea.
Fortinet Korea and IDG Korea conducted this survey to determine how much domestic corporate security personnel know about and respond to APTs, and collected and analyzed responses from 405 domestic security leaders and managers through the IDG Tech Survey (http://www.itworld.co.kr/techsurvey) from December 14, 2015, to January 12, 2016.
Looking at the size of the respondent companies, large organizations with 500 or more employees accounted for 193 people (48%), and small and medium-sized organizations with 500 or fewer employees accounted for 212 people (52%). By industry, IT accounted for 229 people (57%), public/finance sector 53 people (13%), manufacturing/distribution/service sector 81 people (20%), and others (10%).
The full text of this survey can be downloaded for free via the website (http://www.itworld.co.kr/techlibrary/97966).
The attacks that organizations perceive as the greatest threat are malware and APT attacks

In this survey, the attacks that organizations perceive as the greatest threat are malware such as ransomware and spyware (45.2%). APT threats such as detection evasion attacks and spear phishing attacks (25.4%) followed in second place.
There were differences in perspective regarding the attacks perceived as the greatest threat depending on the size of the company. About half (49%) of small and medium-sized organizations with 500 or fewer employees and 41% of large enterprises cited malware as the top threat, while 24% and 27%, respectively, cited APT attacks.
The biggest security problem: lack of security technology and monitoring personnel.
Organizations cited a lack of security technology and monitoring personnel (26%) as the biggest problem regarding security issues, followed by a lack of security solutions to address the root cause of the problem (19%), a lack of security awareness among employees (18%), and an increase in cyber attack points such as BYOD (14%).
This survey revealed that only 14% of organizations have established and are implementing APT response measures. 86% of all respondents answered that they do not have an APT response plan. This figure was low for small and medium-sized organizations (8%), and even for large organizations, only 19% responded that they have established and are implementing a response plan.
It was found that 55% are well aware of APT but lack sufficient response measures, with responses including: knowing about APT but not currently having response measures in place (26%), planning to establish measures while learning (21%), and knowing about it and having prepared response measures but unable to implement them (8%).
However, the level of APT awareness was found to be very high (69% overall, 78% for large enterprises). In contrast, small and medium-sized organizations showed a relatively low awareness rate regarding APT (64%). Although overall APT awareness was high, 42% of respondents stated they were unaware they were under attack. Even large organizations showed a response rate of only 37%, revealing an urgent need to secure security visibility. While 14% experienced breaches, only 8% of companies were attacked and managed to defend themselves.
Security Measures Show Disparities by Size and Industry
In response to a question regarding the strategies organizations are adopting for security—specifically, the status of security measures implementation—it was found that, overall, organizations prioritize the adoption of network defenses (64%) and detection and response functions (58%). Large organizations showed significantly high adoption rates for strengthening network defenses (73%) and detection and response functions (76%), averaging 2.62 units. In contrast, small and medium-sized organizations showed relatively low adoption rates for strengthening network defenses (57%) and establishing detection and response functions (42%), averaging 1.98 units.
There were also significant differences in adoption rates by industry. The public and financial sectors showed the highest adoption rate (270%), and the IT sector (235%) also exceeded the average. The manufacturing, distribution, and service sectors (212%) had a relatively low adoption rate, which was also reflected in their confidence regarding APT response.
The survey revealed that organizations have adopted approximately 3.1 security solutions. The order was firewalls (77%), antivirus (74%), spam filtering solutions (51%), and IPS (45%), while the adoption of next-generation firewalls (25%), DLP (22%), and APT response solutions (19%) was insufficient. By industry, the public and financial sectors showed the highest adoption rate (394%), but the adoption rate of APT response solutions was low.
This survey revealed that confidence in security levels is proportional to the number of current security measures and solutions. When asked whether their company could adequately respond to APTs, overall views were balanced, with 52% negative and 48% positive. However, confidence in APT response varied by organizational size. While 64% of respondents from large organizations were positive and 36% were negative, 34% of respondents from small and medium-sized organizations were positive and 66% were negative. There were also differences by industry. In the public/finance and IT sectors, 72% and 54%, respectively, held positive views, whereas only 31% of respondents in the manufacturing/distribution/service sectors answered positively. Notably, 17% of respondents in the manufacturing/distribution/service sectors stated that they were unable to respond at all.
Selection Criteria When Purchasing an APT Solution

According to this survey, the primary selection criterion when purchasing an APT solution was detection accuracy (59%). The responses that followed, such as rapid analysis capabilities (14%), price (11%), support for analyzing various file types (11%), and provision of comprehensive reporting (6%), showed a significant gap compared to the top-ranked detection accuracy (59%).
Regarding these results, Cho Hyun-je, CEO of Fortinet Korea, stated, “Today’s cybercrime, such as intelligent evasion attack methods, is becoming increasingly sophisticated, and malware concealment techniques are also becoming more advanced and diversified. In a situation where cyber threats are evolving day by day, solutions that merely combine individual products have limitations in preventing APT threats. Since there are multiple attack vectors that hackers or cybercriminals can use simultaneously to infiltrate networks, APT solutions must focus on maximizing security effectiveness through the collaboration of all elements.” “To effectively respond to APT attacks, a multipath defense strategy is required for each attack path, including reconnaissance, vulnerability identification, infiltration, attack, backdoors, C&C, and exfiltration,” he emphasized. “Security effectiveness is maximized only when solution components interact, and this is the core of Fortinet’s ATP solution. Based on FortiGate’s integrated security capabilities, the Fortinet ATP ecosystem neutralizes APT attacks to the maximum extent through end-to-end, comprehensive network security against email APT, web APT, and client APT. Furthermore, secondary defense against APT attacks is possible by integrating user authentication servers and log servers to track malware and identify real-time infection status information.”
Malware such as ransomware and spyware was cited (45.2%)
Fortinet Korea announced today the results of a survey on the "Current Status of Domestic APT Security Awareness and Adoption," conducted jointly with IDG Korea.
Fortinet Korea and IDG Korea conducted this survey to determine how much domestic corporate security personnel know about and respond to APTs, and collected and analyzed responses from 405 domestic security leaders and managers through the IDG Tech Survey (http://www.itworld.co.kr/techsurvey) from December 14, 2015, to January 12, 2016.
Looking at the size of the respondent companies, large organizations with 500 or more employees accounted for 193 people (48%), and small and medium-sized organizations with 500 or fewer employees accounted for 212 people (52%). By industry, IT accounted for 229 people (57%), public/finance sector 53 people (13%), manufacturing/distribution/service sector 81 people (20%), and others (10%).
The full text of this survey can be downloaded for free via the website (http://www.itworld.co.kr/techlibrary/97966).
The attacks that organizations perceive as the greatest threat are malware and APT attacks

In this survey, the attacks that organizations perceive as the greatest threat are malware such as ransomware and spyware (45.2%). APT threats such as detection evasion attacks and spear phishing attacks (25.4%) followed in second place.
There were differences in perspective regarding the attacks perceived as the greatest threat depending on the size of the company. About half (49%) of small and medium-sized organizations with 500 or fewer employees and 41% of large enterprises cited malware as the top threat, while 24% and 27%, respectively, cited APT attacks.
The biggest security problem: lack of security technology and monitoring personnel.
Organizations cited a lack of security technology and monitoring personnel (26%) as the biggest problem regarding security issues, followed by a lack of security solutions to address the root cause of the problem (19%), a lack of security awareness among employees (18%), and an increase in cyber attack points such as BYOD (14%).
This survey revealed that only 14% of organizations have established and are implementing APT response measures. 86% of all respondents answered that they do not have an APT response plan. This figure was low for small and medium-sized organizations (8%), and even for large organizations, only 19% responded that they have established and are implementing a response plan.
It was found that 55% are well aware of APT but lack sufficient response measures, with responses including: knowing about APT but not currently having response measures in place (26%), planning to establish measures while learning (21%), and knowing about it and having prepared response measures but unable to implement them (8%).
However, the level of APT awareness was found to be very high (69% overall, 78% for large enterprises). In contrast, small and medium-sized organizations showed a relatively low awareness rate regarding APT (64%). Although overall APT awareness was high, 42% of respondents stated they were unaware they were under attack. Even large organizations showed a response rate of only 37%, revealing an urgent need to secure security visibility. While 14% experienced breaches, only 8% of companies were attacked and managed to defend themselves.
Security Measures Show Disparities by Size and Industry
In response to a question regarding the strategies organizations are adopting for security—specifically, the status of security measures implementation—it was found that, overall, organizations prioritize the adoption of network defenses (64%) and detection and response functions (58%). Large organizations showed significantly high adoption rates for strengthening network defenses (73%) and detection and response functions (76%), averaging 2.62 units. In contrast, small and medium-sized organizations showed relatively low adoption rates for strengthening network defenses (57%) and establishing detection and response functions (42%), averaging 1.98 units.
There were also significant differences in adoption rates by industry. The public and financial sectors showed the highest adoption rate (270%), and the IT sector (235%) also exceeded the average. The manufacturing, distribution, and service sectors (212%) had a relatively low adoption rate, which was also reflected in their confidence regarding APT response.
The survey revealed that organizations have adopted approximately 3.1 security solutions. The order was firewalls (77%), antivirus (74%), spam filtering solutions (51%), and IPS (45%), while the adoption of next-generation firewalls (25%), DLP (22%), and APT response solutions (19%) was insufficient. By industry, the public and financial sectors showed the highest adoption rate (394%), but the adoption rate of APT response solutions was low.
This survey revealed that confidence in security levels is proportional to the number of current security measures and solutions. When asked whether their company could adequately respond to APTs, overall views were balanced, with 52% negative and 48% positive. However, confidence in APT response varied by organizational size. While 64% of respondents from large organizations were positive and 36% were negative, 34% of respondents from small and medium-sized organizations were positive and 66% were negative. There were also differences by industry. In the public/finance and IT sectors, 72% and 54%, respectively, held positive views, whereas only 31% of respondents in the manufacturing/distribution/service sectors answered positively. Notably, 17% of respondents in the manufacturing/distribution/service sectors stated that they were unable to respond at all.
Selection Criteria When Purchasing an APT Solution

According to this survey, the primary selection criterion when purchasing an APT solution was detection accuracy (59%). The responses that followed, such as rapid analysis capabilities (14%), price (11%), support for analyzing various file types (11%), and provision of comprehensive reporting (6%), showed a significant gap compared to the top-ranked detection accuracy (59%).
Regarding these results, Cho Hyun-je, CEO of Fortinet Korea, stated, “Today’s cybercrime, such as intelligent evasion attack methods, is becoming increasingly sophisticated, and malware concealment techniques are also becoming more advanced and diversified. In a situation where cyber threats are evolving day by day, solutions that merely combine individual products have limitations in preventing APT threats. Since there are multiple attack vectors that hackers or cybercriminals can use simultaneously to infiltrate networks, APT solutions must focus on maximizing security effectiveness through the collaboration of all elements.” “To effectively respond to APT attacks, a multipath defense strategy is required for each attack path, including reconnaissance, vulnerability identification, infiltration, attack, backdoors, C&C, and exfiltration,” he emphasized. “Security effectiveness is maximized only when solution components interact, and this is the core of Fortinet’s ATP solution. Based on FortiGate’s integrated security capabilities, the Fortinet ATP ecosystem neutralizes APT attacks to the maximum extent through end-to-end, comprehensive network security against email APT, web APT, and client APT. Furthermore, secondary defense against APT attacks is possible by integrating user authentication servers and log servers to track malware and identify real-time infection status information.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













