{"id":72110,"date":"2022-06-08T15:45:49","date_gmt":"2022-06-08T14:45:49","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2022\/06\/08\/cohesity-research-highlights-a-gap-that-puts-businesses-and-security-postures-at-risk\/"},"modified":"2023-05-25T10:27:57","modified_gmt":"2023-05-25T09:27:57","slug":"cohesity-research-highlights-a-gap-that-puts-businesses-and-security-postures-at-risk","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2022\/06\/08\/cohesity-research-highlights-a-gap-that-puts-businesses-and-security-postures-at-risk\/","title":{"rendered":"Cohesity research highlights a gap that puts businesses and security postures at risk"},"content":{"rendered":"\n<p><strong><em>Research from Cohesity reveals while most IT and security operations decision-makers believe they should share responsibility for data security, ineffective collaboration between the two teams is not addressing growing cyberthreats. <\/em><\/strong><\/p>\n\n\n\n<p>Research from <a href=\"https:\/\/www.cohesity.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cohesity<\/a> reveals while most IT and security operations decision-makers believe they should share responsibility for data security, ineffective collaboration between the two teams is not&nbsp; addressing growing cyberthreats.<\/p>\n\n\n\n<p>Research commissioned by Cohesity, a leader in next-gen data management, reveals that while most IT and security operations (SecOps) decision-makers believe they should jointly share the responsibility for their organization\u2019s data security strategy, many of these teams are not collaborating as effectively as possible to address growing cyberthreats.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"307\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat2-w.jpg\" alt=\"\" class=\"wp-image-72114\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat2-w.jpg 600w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat2-w-300x154.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n\n<p>The survey also shows that of those respondents who believe collaboration is weak between IT and security, nearly half of respondents believe their organization is more exposed to cyberthreats as a result &#8211; and the implications of that could have significant consequences for businesses.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"312\" src=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat4-w.jpg\" alt=\"\" class=\"wp-image-72113\" srcset=\"https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat4-w.jpg 600w, https:\/\/www.intelligentcio.com\/me\/wp-content\/uploads\/sites\/12\/2022\/06\/Glob_Sec_Surv_Stat4-w-300x156.jpg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n\n<p>The research is based on a survey conducted by Censuswide, of more than 2,000 IT decision-makers and SecOps professionals (split nearly 50\/50 between the two groups) from businesses in the United States, the United Kingdom and Australia &#8211; all of whom have a role in the decision-making process for IT or security.<\/p>\n\n\n\n<p>The survey was conducted as nearly three-quarters (74%) of respondents believe the threat of ransomware in their industry has increased over the last year, with nearly half of respondents (47%) saying their organization has been the victim of a ransomware attack in the last six months.<\/p>\n\n\n\n<p>The survey uncovered the following results globally:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Security should be a shared responsibility: <\/strong>More than four in five (81%) of respondents overall (86% of IT decision-makers and 76% of SecOps) somewhat or strongly agree that IT and SecOps should share the responsibility for their organization\u2019s data security strategy.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>But effective collaboration between IT and security teams is frequently not happening: <\/strong>Almost a third of SecOps respondents (31%) believe the collaboration is not strong with IT, with 9% of those respondents going so far as to call it \u2018weak.\u2019 Among IT decision-makers, more than a tenth of respondents (13%), believe collaboration with SecOps is not strong. In total, nearly a quarter (22%) of IT and SecOps respondents overall believe the collaboration between the two groups is not strong.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>In many cases, even though the threat of cyberattacks has increased, the level of collaboration between IT and SecOps has remained stagnant or has declined: <\/strong>40% of respondents, overall, said collaboration between the two groups has remained the same even in light of increased cyberattacks. And, 12% of all respondents said collaboration has actually decreased. While only 5% of IT decision makers said collaboration has decreased, nearly one in five (18%) of SecOps respondents believe that is the case, highlighting disparity between the two functions.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The on-going tech talent shortage is making matters worse:<\/strong> When asked if the talent shortage is impacting the collaboration between IT and security teams, 78% of respondents (77% of IT decision-makers and 78% of SecOps) said: \u2018Yes, it is having an impact.\u2019<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>As a result of this lack of collaboration between IT and SecOps, many respondents believe their organization is more exposed:<\/strong> Among the IT and SecOps respondents who believe the collaboration is weak between the two groups, 42% believe their organization is either more exposed (28%), or much more exposed (14%) to cyberthreats. <\/li>\n\n\n\n<li><strong>The consequences of that exposure could be devastating for businesses and for careers: <\/strong>When asked what would be their worst fear about a lack of collaboration between security and IT if an attack takes place, 42% of all respondents are concerned about a loss of data, 42% fear business disruption, 40% are worried customers will take their business elsewhere, 35% fear finger-pointing will take place and their team will be blamed should any mistakes occur, 32% are worried about paying ransomware, and 30% fear people from both teams (IT and SecOps) will be fired.<\/li>\n<\/ul>\n\n\n\n<p>\u201cThis research pinpoints there is often a lack of collaboration between IT and security teams that we\u2019re seeing across many organizations today,\u201d said Brian Spanswick, Chief Information Security Officer, Cohesity.<\/p>\n\n\n\n<p>\u201cFor too long, many security teams focused primarily on preventing cyberattacks, while IT teams have focused on data protection, including backup and recovery.<\/p>\n\n\n\n<p>\u201cA complete data security strategy must bring these two worlds together &#8211; but in many cases, they remain separate and this lack of collaboration creates significant business risks and can put companies at the mercy of bad actors.\u201d<\/p>\n\n\n\n<p>To further drive this point home, when respondents were asked how their company prioritized data backup and protection as part of their organization&#8217;s security posture or response to a cyberattack, 54% of IT decision-makers said it was a top priority and a crucial capability, while only 38% of SecOps respondents said the same.<\/p>\n\n\n\n<p>\u201cIf SecOps teams are not thinking about backup and recovery and lack next-gen data management capabilities as part of an overall security strategy, that\u2019s a problem,\u201d said Spanswick.<\/p>\n\n\n\n<p>\u201cIT and SecOps teams need to collaborate before an attack takes place &#8211; looking holistically across the NIST Cybersecurity Framework which includes five core capabilities: identify, protect, detect, respond, and recover. If they wait to collaborate until their data is hijacked, that\u2019s too late and the results could be catastrophic for businesses.\u201d<\/p>\n\n\n\n<p>Eighty-three percent of all respondents (84% of IT decision-makers and 81% of SecOps respondents) somewhat or strongly agree that if security and IT collaborated more closely, their organization would be better prepared to recover from cyberthreats including ransomware attacks. And, when respondents were asked what would give their organization greater confidence that they could recover business systems quickly in the event of a ransomware attack, 44% of all respondents (49% of IT decision-makers and 39% of SecOps respondents) said greater communication and collaboration between IT and security is key.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Research from Cohesity reveals while most IT and security operations decision-makers believe they should share responsibility for data security, ineffective collaboration between the two teams is not addressing growing cyberthreats. Research from Cohesity reveals while most IT and security operations decision-makers believe they should share responsibility for data security, ineffective collaboration between the two teams [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":72112,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5307,3624,5,6,12449,13,79],"tags":[12108,2158,1643,5205],"class_list":["post-72110","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-case-study-newsletter","category-enterprise-security","category-insights","category-north-america","category-top-stories","category-used","tag-cohesity","tag-cyberthreats","tag-data-security","tag-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/72110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=72110"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/72110\/revisions"}],"predecessor-version":[{"id":83502,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/72110\/revisions\/83502"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/72112"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=72110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=72110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=72110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}