{"id":37063,"date":"2020-01-29T11:33:53","date_gmt":"2020-01-29T11:33:53","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2020\/01\/29\/almost-half-of-respondents-to-latest-infosecurity-europe-poll-wouldnt-know-if-their-organisation-had-suffered-a-cyber-breach\/"},"modified":"2020-02-03T09:31:17","modified_gmt":"2020-02-03T09:31:17","slug":"almost-half-of-respondents-to-latest-infosecurity-europe-poll-wouldnt-know-if-their-organisation-had-suffered-a-cyber-breach","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2020\/01\/29\/almost-half-of-respondents-to-latest-infosecurity-europe-poll-wouldnt-know-if-their-organisation-had-suffered-a-cyber-breach\/","title":{"rendered":"Almost half of respondents to poll &#8216;wouldn\u2019t know&#8217; if their organisation had suffered a cyber breach"},"content":{"rendered":"\n<p>Almost half of respondents to the latest Twitter poll run by Infosecurity Europe, Europe\u2019s number one information security event, admit they would be completely unaware if a cyber breach occurred in their organisation. The poll was designed to explore incident response, an area that has come under recent scrutiny following Travelex\u2019s response to its New Year\u2019s Eve cyberattack, which left many of its systems down and impacted travel currency sales. <\/p>\n\n\n\n<p>In answer to the question: &#8216;If a cyber breach occurred, how quickly could you discover it?&#8217;, 31.5% of respondents said they would discover it immediately, 14.3% within 30 days and 6.6% within 200 days. However, a shocking 47.6% conceded they simply would not know. <\/p>\n\n\n\n<p>According to Maxine Holt, Research Director at Ovum, this reflects a widespread issue. \u201cDiscovering a breach well after the event is usual. Uncovering breaches is not easy, but proactive threat hunting is an approach being increasingly used by organisations. Regularly scanning environments to look for anomalies and unexpected activity is useful, but it can be difficult to deal with the number of resulting alerts. Ultimately, effective cyberhygiene involves having layers of security to prevent, detect and respond to incidents and breaches.\u201d<\/p>\n\n\n\n<p>Good incident response demands good risk insight. The poll examined this by asking, &#8216;What understanding do you have of your information assets?&#8217;. A worrying 44.7% revealed they had &#8216;very little&#8217; understanding, with 30.7% stating they had &#8216;some&#8217; \u2013 and only 24.7% said their grasp was &#8216;comprehensive&#8217;.<\/p>\n\n\n\n<p>Bev Allen, Head of Information Security Assurance, CISO, Quilter, said: \u201cMany companies don\u2019t know what or where all their information assets are. They may think they do, but if they\u2019re wrong this leaves them vulnerable to breaches. Consistent knowledge of your assets takes effort; you need tools and systems to record what you have, you need people to follow appropriate processes and you need to search to find out what you don\u2019t know about and where it is. This search must be done regularly.\u201d<\/p>\n\n\n\n<p>Steve Trippier, CISO of Anglian Water, believes the \u2018knowledge gap\u2019 is due to a lack of awareness of the need for effective asset management. \u201cIt often falls behind other processes in terms of priorities as its value can be less immediately obvious. As more companies introduce automated vulnerability discovery and management, the need for effective asset management will become very obvious, especially as cyber teams highlight vulnerabilities on assets that the organisation forgot it even had.\u201d<\/p>\n\n\n\n<p>The poll also uncovered potential evidence of skewed priorities around post-breach actions. Travelex released a series of statements after its December attack, but received criticism from customers for a lack of information about when service would return to normal and whether sensitive customer data had been accessed, as the gang behind the attack claimed.<\/p>\n\n\n\n<p>In response to the question, &#8216;What is the key priority when dealing with the fall out of a major cyberattack?&#8217;, getting back to business topped the list for 42.4% of respondents, followed by customer communications and PR (23.6%), engaging law enforcement (19.4%) and ensuring compliance (14.6%). This indicates that more time and energy might need to be refocused on the communication side of incident response. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Almost half of respondents to the latest Twitter poll run by Infosecurity Europe, Europe\u2019s number one information security event, admit they would be completely unaware if a cyber breach occurred in their organisation. The poll was designed to explore incident response, an area that has come under recent scrutiny following Travelex\u2019s response to its New [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":37072,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,13,6617,93,24],"tags":[14290,14291],"class_list":["post-37063","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-main-story-newsletter","category-research","category-top-stories","category-used","tag-anglian-water","tag-quilter"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/37063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=37063"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/37063\/revisions"}],"predecessor-version":[{"id":37085,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/37063\/revisions\/37085"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/37072"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=37063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=37063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=37063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}