sb-nz logo
Story image

Fear of cyber risk is stunting growth in NZ businesses

23 Jul 2018

New Zealand businesses need to revamp their cybersecurity efforts if they’re to have any hope of making the most of digital transformation, a new report by Microsoft and Frost & Sullivan says.

The report found that 36% of the New Zealand organisations surveyed had experienced a cybersecurity incident; however 16% were not sure because they did not conduct a data breach assessment or digital forensics.

Furthermore, 43% of New Zealand respondents say they have put off digital transformation because they are worried about cyber risks.

“As companies embrace the opportunities presented by cloud and mobile computing to connect with customers and optimise operations, they take on new risks,” comments Microsoft New Zealand national technology officer, Russell Craig.

“With traditional IT boundaries disappearing the adversaries now have many new targets to attack. Companies face the risk of significant financial loss, damage to customer satisfaction and market reputation—as has been made all too clear by recent high-profile breaches.”

Unsure what to do about it, many organisations are taking the wrong approach to dealing with security. Many see security as an afterthought, while others use an ‘unnecessarily complex’ range of cybersecurity solutions.

The report also found that before a digital transformation project, only 19% will consider cybersecurity. The report says this mindset limits an organisation’s ability to conceptualise and deliver a ‘secure-by-design’ project, which could lead to products going to market that have inadequate security measures.

If a business uses a large number of security solutions, it doesn’t necessarily mean they are any safer. Organisations with between 26-50 security solutions encountered a similar percentage of security incidents as those organisations with fewer than 10 solutions.

The report suggests that it’s best to reduce complexity and the number of security tools organisations use.

Artificial intelligence continues to be a hot topic in cybersecurity, with 65% of respondents either adopting or looking to adopt an AI approach towards cybersecurity protection.

“Utilising AI-enabled security tools can significantly reduce risk,” says Craig.

“Ever more advanced tools scan incoming mail for threats and filter these out before they even reach our inboxes. Of course, it’s impossible to entirely prevent malicious hacking, human error or other sources of cyber risk, but the effectiveness of these tools continually improves, thanks to the vast scale of cyber threat data that can be gathered via the public cloud and translated into insights using data analytics.”

The report provides three recommendations:

Continue to invest in strengthening your security fundamentals: Over 90% of cyber incidents can be averted by maintaining the most basic best practices. Maintain strong passwords, use multi-factor authentication and keep device operating systems, software and anti-malware protection up-to-date;

• Assessment, review and continuous compliance: Assessments and reviews should be conducted regularly to test for potential gaps. Keep tabs on not just compliance to industry regulations but also how the organisation is progressing against security best practices; and

• Leverage AI and automation to increase capabilities and capacity: With security capabilities in short supply, organisations need to look to automation and AI to improve the capabilities and capacity of their security operations.

The statistics are taken from the Understanding the Cybersecurity Threat Landscape in Asia Pacific: Securing the Modern Enterprise in a Digital World report.

Story image
Huawei introduces all-flash OceanStor Dorado arrays
All-flash offers stability and high-performance storage with extremely low levels of latency – and it can offer reliability in the event of a disaster.More
Story image
Cloud breaches set to increase in velocity and scale - Accurics
“While the adoption of cloud native infrastructure such as containers, serverless, and servicemesh is fuelling innovation, misconfigurations are becoming commonplace and creating serious risk exposure for organisations."More
Story image
Reports suggest spike in vaccine-related phishing campaigns
According to new research from Check Point, the primary attack delivery method is email, constituting 82% of all attack vectors for malicious files in the last month.More
Story image
CompTIA's new threat intelligence resource officially launches
The new resource is designed to help technology solution providers, managed services providers (MSPs) and other organisations searching for critical cybersecurity threat intelligence. More
Story image
Network intelligence is stopping a wave of DDoS misdiagnosis
Security teams already know the value of a layered defence; it’s time to add more layers, writes ThousandEyes principal solutions analyst Mike Hicks.More
Story image
Cyber criminals turn to Gmail and AOL to advance attacks
“Securing oneself against this threat requires organisations to take protection matters into their own hands - this requires them to invest in sophisticated email security that leverages artificial intelligence to identify unusual senders and requests."More