{"id":15349,"date":"2017-10-16T13:28:09","date_gmt":"2017-10-16T11:28:09","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=15349"},"modified":"2017-10-16T13:28:09","modified_gmt":"2017-10-16T11:28:09","slug":"new-global-survey-finds-most-companies-are-unprepared-for-dns-attacks","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2017\/10\/16\/new-global-survey-finds-most-companies-are-unprepared-for-dns-attacks\/","title":{"rendered":"New global survey finds companies are unprepared for DNS attacks"},"content":{"rendered":"<p>Infoblox has released results of a global survey finding that DNS security is often overlooked when it comes to cybersecurity strategy, with most companies inadequately prepared to defend against DNS attacks. Surveying over 1,000 security and IT professionals worldwide and conducted by Dimensional Research, the study  found that 86% of DNS solutions failed to first alert teams of an occurring DNS attack, and nearly one-third of professionals doubted their company could defend against the next DNS attack.<\/p>\n<p>The results come in advance of the one-year anniversary of the DDoS attack on DNS provider Dyn last October, which knocked dozens of major sites offline including Netflix, Airbnb, Amazon, CNN, New York Times, Twitter and more. The widespread impact of the attack shed light on a startling reality &#8211; that many companies have inadequate defences when it comes to DNS security. Despite this wake-up call, only 11% of companies have dedicated security teams managing DNS, showing DNS is still not as high of a priority as it should be.<\/p>\n<p>\u201cOur research reveals a gap in the market &#8211; while we found that DNS security is one of IT and security professionals\u2019 top three concerns, the vast majority of companies are ill-equipped to defend against DNS attacks,\u201d said David Gehringer, Principal at Dimensional Research. \u201cThis is exacerbated by the fact that companies are extremely reactionary when it comes to DNS security, only prioritising DNS defence once they have been attacked. Unless today\u2019s organisations begin moving to a proactive approach, DDoS attacks such as the one on DNS provider Dyn will become more pervasive.\u201d<\/p>\n<p>Other key findings from the <em>Most companies unprepared for DNS Attacks<\/em> report include:<\/p>\n<p>\u2022\tDNS attacks extremely effective: Three out of 10 companies have already been victims of DNS attacks. Of the companies that have been victims of DNS attacks, 93% experienced downtime. 40% were down for an hour or more, substantially impacting their business.<br \/>\n\u2022\tCompanies slow to notice DNS attacks: Despite 71% of companies claiming they have real time monitoring for DNS attacks, 86% of solutions failed to be the first in notifying teams that a DNS attack was occurring. Moreover, 20% of companies were first alerted to DNS attacks by customer complaints, meaning it had already impacted their business, reputation and customer satisfaction.<br \/>\n\u2022\tMost companies vulnerable to DNS attacks: Only 37% of companies were able to defend against all types of DNS attacks (hijacking, exploits, cache poisoning, protocol anomalies, reflection, NXDomain, amplification), meaning that the majority (63%) are essentially gambling that the next DNS attack is one they can repel.<br \/>\n\u2022\tReactive rather than proactive: Before an attack, 74% of companies focus on anti-virus monitoring as their top security focus; however, after an attack, DNS security moves to the number one position with 70% claiming it is the most important security focus. This demonstrates a reactionary approach and that DNS is not a priority until a company has been attacked and suffered a tangible business loss.<br \/>\n\u2022\tDNS has direct impact on the bottom line: 24% of companies lost $100,000 or more from their last DNS attack, significantly impacting their bottom line. 54% lost $50,000 or more. As the numbers show, once websites are rendered inaccessible, all digital business and revenue comes to a grinding halt, while internal resources are redirected to resolving the attack rather than driving the business. <\/p>\n<p>\u201cMost organisations regard DNS as simply plumbing rather than critical infrastructure that requires active defence,\u201d said Cricket Liu, Chief DNS Architect at Infoblox. \u201cUnfortunately, this survey confirms that, even on the anniversary of the enormous DDoS attack against Dyn \u2013 a dramatic object lesson in the effects of attacks on DNS infrastructure \u2013 most companies still neglect DNS security. Our approach to cybersecurity needs a fundamental shift: if we don\u2019t start giving DNS security the attention it deserves, DNS will remain one of our most vulnerable Internet systems, and we\u2019ll continue to see events like last year\u2019s attack.\u201d<\/p>\n<p><strong>Download report<\/strong><br \/>\nDownload the full report, <em>Most Companies Unprepared for DNS Attacks<\/em>, <a href=\"http:\/\/info.infoblox.com\/resources-whitepapers-dimensional-research-dns-survey-report\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p><strong>Methodology<\/strong><br \/>\nParticipants for the study included more than 1,000 security, IT operations and infrastructure professionals worldwide across all company sizes and verticals.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infoblox has released results of a global survey finding that DNS security is often overlooked when it comes to cybersecurity strategy, with most companies inadequately prepared to defend against DNS attacks. Surveying over 1,000 security and IT professionals worldwide and conducted by Dimensional Research, the study found that 86% of DNS solutions failed to first [&hellip;]<\/p>\n","protected":false},"author":23,"featured_media":15350,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,399,54],"tags":[388,1396,161,162,817],"class_list":["post-15349","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-more-news","category-research","tag-cybersecurity","tag-dns-security","tag-infoblox","tag-network","tag-research"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/15349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=15349"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/15349\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/15350"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=15349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=15349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=15349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}