{"id":36305,"date":"2019-12-13T15:18:24","date_gmt":"2019-12-13T15:18:24","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/12\/13\/servicenow-research-shows-that-security-breaches-increased-in-2019\/"},"modified":"2019-12-13T15:19:12","modified_gmt":"2019-12-13T15:19:12","slug":"servicenow-research-shows-that-security-breaches-increased-in-2019","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/12\/13\/servicenow-research-shows-that-security-breaches-increased-in-2019\/","title":{"rendered":"ServiceNow research shows that security breaches increased in 2019"},"content":{"rendered":"\n<p>ServiceNow, a leading digital workflow company\nmaking work, work better for people, has released its second sponsored study on\ncybersecurity vulnerability and patch management,\nconducted with the Ponemon Institute. <\/p>\n\n\n\n<p>The study, <em>Costs and Consequences of Gaps in Vulnerability Response<\/em>, found that despite a 24% average increase in annual spending on prevention, detection and remediation in 2019 compared with 2018, patching is delayed an average of 12 days due to data silos and poor organisational co-ordination. Looking specifically at the most critical vulnerabilities, the average timeline to patch is 16 days. <\/p>\n\n\n\n<p>At the same time, the risk is increasing. According to the findings, there was a 17% increase in cyberattacks over the past year, and 60% of breaches were linked to a vulnerability where a patch was available, but not applied. The study surveyed almost 3,000 security professionals to understand how organisations are responding to vulnerabilities. In this report, ServiceNow presents the consolidated findings and comparisons to its 2018 study, <em>Today\u2019s State of Vulnerability Response: Patch Work Requires Attention<\/em>. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/12\/ServiceNow-infographic-622x1024.jpg\" alt=\"\" class=\"wp-image-36310\" \/><\/figure>\n\n\n\n<p><strong>The survey results reinforce a need for organisations\nto prioritise more effective and efficient security vulnerability management: <\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>34% increase in weekly costs spent\non patching compared to 2018<\/li><li>30% more downtime vs. 2018,\ndue to delays in patching vulnerabilities<\/li><li>69% of respondents plan to\nhire an average of five staff members dedicated to patching in the next year,\nat an average cost of US$650,000 annually for each organisation<\/li><li>88% of respondents said they\nmust engage with other departments across their organisations, which results in\ncoordination issues that delay patching by an average of 12 days<\/li><\/ul>\n\n\n\n<p><strong>The findings also indicate a persistent\ncybercriminal environment, underscoring the need to act quickly:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>17%\nincrease in the volume of cyberattacks in the last 12 months compared to the\nsame timeframe in 2018<\/li><li>Nearly\n27% increase in cyberattack severity compared to 2018<\/li><\/ul>\n\n\n\n<p><strong>The report points to other factors beyond staffing that contribute to delays in vulnerability patching:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>76% of respondents noted the\nlack of a common view of applications and assets across security and IT teams<\/li><li>74% of respondents said they\ncannot take critical applications and systems offline to patch them quickly<\/li><li>72% of respondents said it is\ndifficult to prioritize what needs to be patched<\/li><\/ul>\n\n\n\n<p>According to the findings, automation delivers\na significant payoff in terms of being able to respond quickly and effectively\nto vulnerabilities. Four in five (80%) of respondents who employ automation\ntechniques say they respond to vulnerabilities in a shorter timeframe through\nautomation. <\/p>\n\n\n\n<p>\u201cThis study shows the vulnerability gap that has been a\ngrowing pain point for CIOs and CISOs,\u201d said Sean Convery, General Manager,\nServiceNow Security and Risk. <\/p>\n\n\n\n<p>\u201cCompanies saw a 30% increase in downtime due to patching\nof vulnerabilities, which hurts customers, employees and brands. Many organisations\nhave the motivation to address this challenge but struggle to effectively\nleverage their resources for more impactful vulnerability management. Teams\nthat invest in automation and maturing their IT and security team interactions\nwill strengthen the security posture across their organisations.\u201d<\/p>\n\n\n\n<p><strong>ServiceNow Security Operations<\/strong><\/p>\n\n\n\n<p>Vulnerability Response is part of ServiceNow Security\nOperations, a security orchestration, automation and response engine built on\nthe Now Platform. Designed to help security teams respond faster and more\nefficiently to incidents and vulnerabilities, Security Operations uses\nintelligent workflows, automation and a deep connection with IT to streamline\nsecurity response.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ServiceNow, a leading digital workflow company making work, work better for people, has released its second sponsored study on cybersecurity vulnerability and patch management, conducted with the Ponemon Institute. The study, Costs and Consequences of Gaps in Vulnerability Response, found that despite a 24% average increase in annual spending on prevention, detection and remediation in [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":36311,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,171,6617,93],"tags":[775,183,564,12647,3835,14073,7939,14074,14075],"class_list":["post-36305","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-infographics","category-research","category-top-stories","tag-automation","tag-cyberattacks","tag-cybersecurity","tag-now-platform","tag-ponemon-institute","tag-sean-convery","tag-servicenow","tag-servicenow-security-operations","tag-vulnerability-response"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=36305"}],"version-history":[{"count":4,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36305\/revisions"}],"predecessor-version":[{"id":36313,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/36305\/revisions\/36313"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/36311"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=36305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=36305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=36305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}