Research by Sophos has revealed that organizations are struggling to cope with the relentless wave of malicious activities. In the past year, 94% organizations encountered some form of cyberattack. The statistics below are from a survey—conducted in January and February—of 3,000 cybersecurity and IT leaders across 14 nations.
23% of respondents stated suffering an active adversary attack in 2022. Active adversaries are threat actors who adapt their TTPs on the spot in response to security technologies and defenders.
Security control misconfigurations are the most widely reported perceived security risk, with 27.4% of organizations including it in their top three security risks.
This is followed by zero-day vulnerabilities (26.8%), shortage of in-house cybersecurity experts or skills (24.7%), and stolen credentials and access (24%).
Why this matters
With the urgent and unpredictable nature of cybersecurity, business-focused efforts are often impeded, resulting in an average of 64% of respondents wishing for more time dedicated to strategic issues rather than constant firefighting by the IT team.
An organization is financially impacted in several ways due to the challenging cybersecurity environment, with major cyber incidents incurring the highest bills, including clean-up and resource expenses.
The bottom line
Sophos recommends a three-step-approach to addressing the current situation:
Implement a more scalable incident response process that speeds up response time.
Use adaptive defenses to delay adversaries.
Create a virtuous cycle that enhances protection and reduces costs.
Organizations should promptly identify security gaps, assess their capabilities, and construct a proper cybersecurity defense to stand strong against these burgeoning threats.