This page was machine-translated and may differ from the original. View original
75% of Security Survey Respondents Say 'Our Organization Is Highly Exposed to Cyber Security Risks'
EMC Releases 'RSA Cybersecurity Vulnerability Index' Report
Insufficient detection and response, the organization's security priority limited to prevention
EMC Korea (CEO Kim Kyung-jin) announced the 'RSA Cybersecurity Poverty Index' report.
Published for the second time following last year, this report covers the maturity and status of cybersecurity across key areas such as organization size, industry, and region, based on a survey of IT professionals worldwide conducted by RSA, EMC's security business unit. A total of 878 participants from 81 countries—including 240 from Europe, the Middle East, and Africa; 200 from the Asia-Pacific region; and 438 from North and South America—participated in the survey for this report.
In this self-assessment-based survey, 75% of all respondents answered that their organizations are significantly exposed to risk due to insufficient security capabilities. Only 18% of respondents rated their organization's security capabilities relatively highly, and only 7% said they had top-level capabilities.

EMC 'RSA Cybersecurity Vulnerability Index' Report
In response to questions regarding the key areas of cybersecurity—Identify, Protect, Detect, Respond, and Recover—66% of respondents assessed that all aspects were inadequate. Among these, the most lacking areas were Detect and Respond, which have recently emerged as core elements of security strategies, while Protect was found to be the most mature. This indicates that organizations' security priorities are still focused on Protect, or preventive policies.
In terms of specific capabilities, the ability to identify, investigate, and mitigate risk types was found to be the most lacking. Only 24% of respondents reported possessing mature or proficient capabilities in this area. As organizations fail to properly assess risk factors, it is highly likely that investments to improve security levels are not being prioritized correctly. Threat detection capabilities were also found to be relatively lacking. Only 28% of companies were properly equipped with the capabilities to monitor networks, endpoints, servers, and applications to detect potential security issues. On the other hand, the Identity and Access Management (IAM) section showed a relatively high level of maturity (37%).
67% of respondents experienced a security incident within the past year, and by industry, the government and energy sectors showed low maturity.
It was also found that there are significant differences in cybersecurity capability levels depending on company size. Among respondents from organizations with 10,000 or more employees, 33% rated their organization's security maturity as high or top-tier. This figure is about 10% higher than the 24% for organizations with 1,000 to 10,000 employees and 23% for respondents from organizations with fewer than 1,000 employees.
67% of respondents reported experiencing a security incident within the last 12 months that could have a negative impact on their business. Of these, only 24% rated their security strategy as mature, indicating that organizations lacked proper security strategies and capabilities even after experiencing incidents. However, the more security incidents an organization experienced, the more its security levels improved. Organizations that experienced 21 or more incidents over the past 12 months were 65% more likely to rate their security maturity highly compared to organizations that experienced 10 or fewer incidents.
By industry sector, the aerospace and defense industry had the highest level of security maturity. 39% of employees in the aerospace and defense industry rated security maturity highly, surpassing the high-tech industry (31%). Financial services, which are the primary targets of cyber attacks, stood at only 26%, while the government and energy industries showed the lowest security maturity (18%).

EMC 'RSA Cybersecurity Vulnerability Index' Report
Meanwhile, the most notable change compared to last year is that the number of companies with the most mature security capabilities increased by 51%, from 4.9% to 7.4%. In addition, in terms of individual capabilities, the maturity level in the field of 'conducting security education and training for employees, executives, and partners' improved significantly, demonstrating that security awareness is spreading.
"This survey shows that the capabilities of many companies are still insufficient to respond to rapidly increasing cyber threats," said Kim Kyung-jin, President of EMC Korea. "Businesses must enhance stability by determining the correct security investment priorities through security risk analysis and strategy formulation, and by focusing on improving capabilities in detection and response, which have recently become major issues."
Meanwhile, this survey was evaluated based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework (hereinafter CSF). Developed in the United States to reduce risks to critical infrastructure, the CSF is used as a standard to evaluate management and security capabilities regarding major cyber risks. CSF defines the five major functions of security as Identify, Protect, Detect, Respond, and Recover.
Insufficient detection and response, the organization's security priority limited to prevention
EMC Korea (CEO Kim Kyung-jin) announced the 'RSA Cybersecurity Poverty Index' report.
Published for the second time following last year, this report covers the maturity and status of cybersecurity across key areas such as organization size, industry, and region, based on a survey of IT professionals worldwide conducted by RSA, EMC's security business unit. A total of 878 participants from 81 countries—including 240 from Europe, the Middle East, and Africa; 200 from the Asia-Pacific region; and 438 from North and South America—participated in the survey for this report.
In this self-assessment-based survey, 75% of all respondents answered that their organizations are significantly exposed to risk due to insufficient security capabilities. Only 18% of respondents rated their organization's security capabilities relatively highly, and only 7% said they had top-level capabilities.
EMC 'RSA Cybersecurity Vulnerability Index' Report
In response to questions regarding the key areas of cybersecurity—Identify, Protect, Detect, Respond, and Recover—66% of respondents assessed that all aspects were inadequate. Among these, the most lacking areas were Detect and Respond, which have recently emerged as core elements of security strategies, while Protect was found to be the most mature. This indicates that organizations' security priorities are still focused on Protect, or preventive policies.
In terms of specific capabilities, the ability to identify, investigate, and mitigate risk types was found to be the most lacking. Only 24% of respondents reported possessing mature or proficient capabilities in this area. As organizations fail to properly assess risk factors, it is highly likely that investments to improve security levels are not being prioritized correctly. Threat detection capabilities were also found to be relatively lacking. Only 28% of companies were properly equipped with the capabilities to monitor networks, endpoints, servers, and applications to detect potential security issues. On the other hand, the Identity and Access Management (IAM) section showed a relatively high level of maturity (37%).
67% of respondents experienced a security incident within the past year, and by industry, the government and energy sectors showed low maturity.
It was also found that there are significant differences in cybersecurity capability levels depending on company size. Among respondents from organizations with 10,000 or more employees, 33% rated their organization's security maturity as high or top-tier. This figure is about 10% higher than the 24% for organizations with 1,000 to 10,000 employees and 23% for respondents from organizations with fewer than 1,000 employees.
67% of respondents reported experiencing a security incident within the last 12 months that could have a negative impact on their business. Of these, only 24% rated their security strategy as mature, indicating that organizations lacked proper security strategies and capabilities even after experiencing incidents. However, the more security incidents an organization experienced, the more its security levels improved. Organizations that experienced 21 or more incidents over the past 12 months were 65% more likely to rate their security maturity highly compared to organizations that experienced 10 or fewer incidents.
By industry sector, the aerospace and defense industry had the highest level of security maturity. 39% of employees in the aerospace and defense industry rated security maturity highly, surpassing the high-tech industry (31%). Financial services, which are the primary targets of cyber attacks, stood at only 26%, while the government and energy industries showed the lowest security maturity (18%).
EMC 'RSA Cybersecurity Vulnerability Index' Report
Meanwhile, the most notable change compared to last year is that the number of companies with the most mature security capabilities increased by 51%, from 4.9% to 7.4%. In addition, in terms of individual capabilities, the maturity level in the field of 'conducting security education and training for employees, executives, and partners' improved significantly, demonstrating that security awareness is spreading.
"This survey shows that the capabilities of many companies are still insufficient to respond to rapidly increasing cyber threats," said Kim Kyung-jin, President of EMC Korea. "Businesses must enhance stability by determining the correct security investment priorities through security risk analysis and strategy formulation, and by focusing on improving capabilities in detection and response, which have recently become major issues."
Meanwhile, this survey was evaluated based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework (hereinafter CSF). Developed in the United States to reduce risks to critical infrastructure, the CSF is used as a standard to evaluate management and security capabilities regarding major cyber risks. CSF defines the five major functions of security as Identify, Protect, Detect, Respond, and Recover.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)












