The Cyber Security Review | Wednesday, November 16, 2022
70 per cent of the organisations in the region remain confident despite the increase in attacks brought on by the Covid-19 pandemic and the quick uptake of digital services, however, nearly half agree that there is still room for improvement.
FREMONT, CA: Even though 64 per cent of businesses report having been the victim of a cyber attack, executive confidence in cyber resilience is still high in the Asia-Pacific region, according to a Marsh and Microsoft (NASDAQ: MSFT) survey released in June. This is although executive confidence is declining globally due to the massive increase in activity in recent years.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
70 per cent of the organisations in the region remain confident despite the increase in attacks brought on by the Covid-19 pandemic and the quick uptake of digital services. However, nearly half agree that there is still room for improvement. The Microsoft/Marsh study investigates whether this belief in cyber resilience results from a robust defensive posture or an incorrect threat landscape assessment.
660 decision-makers from around the area who serve in positions ranging from CEO to CISO to risk management contributed to the poll. Even though more than half of organisations have now experienced a cyber attack with a regional attack rate that is five per cent higher than the global average, more than 69 per cent of respondents said they are confident in their organisation's risk management program. Only 11 per cent of respondents indicated they were very confident in their cyber resilience, while another 58 per cent said they were somewhat confident, which slightly tempers this optimism.
When combined with the 31 per cent of respondents who stated they were not confident in their cyber resilience, the 48 per cent of respondents who claimed their programmes might use improvement would leave only 17 per cent of the respondents who were confident with their programmes' current state. There are indications from the poll, though, that a significantly larger number may be dealing with problems they are not aware of.
One is that regional cyber risk assessments perform significantly worse than the global average. Only 50 per cent of respondents in Asia indicate actively evaluating their risk, compared to 63 per cent of respondents globally. Additionally, there is a propensity for these reviews to be more reactive than preventive; roughly twice as many firms in Asia claim to conduct evaluations after a cyberattack or incident has already occurred.
In terms of actively enhancing system, network, and device security, Asia is likewise falling behind. On the surface, 74 per cent of respondents improved in this area the previous year.
Other risk management areas where the region falls short include enhancing data protection capabilities, carrying out penetration tests, and incorporating cybersecurity into business continuity plans. It is, however, also performing better than the global average in several areas, including redefining organisational cybersecurity roles and responsibilities, conducting vendor and supply chain risk assessments, performing business interruption valuations, adopting DevSecOps, and conducting post-mortem reviews following a cyber attack.
Organisations in Asia generally lag in putting into place critical cyber security risk controls, such as email filtering, endpoint detection and response, cybersecurity and phishing awareness training, secure and encrypted backup maintenance, and web security measures.
Internal corporate consensus is approximately on par with the average for the world. Therefore, that is not the problem. Lack of talent and lack of data are the main differences. The main issue businesses seem to encounter is finding qualified experts to conduct reviews. This includes assessing financial vulnerability, whose rate is less than half that of the world as a whole. Businesses almost everywhere are experiencing a shortage of cybersecurity experts, but a recent ISC2 survey found that Asia is now filling roughly two-thirds of these open positions.
More in News