Story image

Fear of cyber risk is stunting growth in NZ businesses

23 Jul 2018

New Zealand businesses need to revamp their cybersecurity efforts if they’re to have any hope of making the most of digital transformation, a new report by Microsoft and Frost & Sullivan says.

The report found that 36% of the New Zealand organisations surveyed had experienced a cybersecurity incident; however 16% were not sure because they did not conduct a data breach assessment or digital forensics.

Furthermore, 43% of New Zealand respondents say they have put off digital transformation because they are worried about cyber risks.

“As companies embrace the opportunities presented by cloud and mobile computing to connect with customers and optimise operations, they take on new risks,” comments Microsoft New Zealand national technology officer, Russell Craig.

“With traditional IT boundaries disappearing the adversaries now have many new targets to attack. Companies face the risk of significant financial loss, damage to customer satisfaction and market reputation—as has been made all too clear by recent high-profile breaches.”

Unsure what to do about it, many organisations are taking the wrong approach to dealing with security. Many see security as an afterthought, while others use an ‘unnecessarily complex’ range of cybersecurity solutions.

The report also found that before a digital transformation project, only 19% will consider cybersecurity. The report says this mindset limits an organisation’s ability to conceptualise and deliver a ‘secure-by-design’ project, which could lead to products going to market that have inadequate security measures.

If a business uses a large number of security solutions, it doesn’t necessarily mean they are any safer. Organisations with between 26-50 security solutions encountered a similar percentage of security incidents as those organisations with fewer than 10 solutions.

The report suggests that it’s best to reduce complexity and the number of security tools organisations use.

Artificial intelligence continues to be a hot topic in cybersecurity, with 65% of respondents either adopting or looking to adopt an AI approach towards cybersecurity protection.

“Utilising AI-enabled security tools can significantly reduce risk,” says Craig.

“Ever more advanced tools scan incoming mail for threats and filter these out before they even reach our inboxes. Of course, it’s impossible to entirely prevent malicious hacking, human error or other sources of cyber risk, but the effectiveness of these tools continually improves, thanks to the vast scale of cyber threat data that can be gathered via the public cloud and translated into insights using data analytics.”

The report provides three recommendations:

Continue to invest in strengthening your security fundamentals: Over 90% of cyber incidents can be averted by maintaining the most basic best practices. Maintain strong passwords, use multi-factor authentication and keep device operating systems, software and anti-malware protection up-to-date;

• Assessment, review and continuous compliance: Assessments and reviews should be conducted regularly to test for potential gaps. Keep tabs on not just compliance to industry regulations but also how the organisation is progressing against security best practices; and

• Leverage AI and automation to increase capabilities and capacity: With security capabilities in short supply, organisations need to look to automation and AI to improve the capabilities and capacity of their security operations.

The statistics are taken from the Understanding the Cybersecurity Threat Landscape in Asia Pacific: Securing the Modern Enterprise in a Digital World report.

New threat rears its head in new malware report
Check Point’s researchers view Speakup as a significant threat, as it can be used to download and spread any malware.
Oracle updates enterprise blockchain platform
Oracle’s enterprise blockchain has been updated to include more capabilities to enhance development, integration, and deployment of customers’ new blockchain applications.
Used device market held back by lack of data security regulations
Mobile device users are sceptical about trading in their old device because they are concerned that data on those devices may be accessed or compromised after they hand it over.
Gartner names ExtraHop leader in network performance monitoring
ExtraHop provides enterprise cyber analytics that deliver security and performance from the inside out.
Symantec acquires zero trust innovator Luminate Security
Luminate’s Secure Access Cloud is supposedly natively constructed for a cloud-oriented, perimeter-less world.
Palo Alto releases new, feature-rich firewall
Palo Alto is calling it the ‘fastest-ever next-generation firewall’ with integrated cloud-based DNS Security service to stop attacks.
The right to be forgotten online could soon be forgotten
Despite bolstering free speech and access to information, the internet can be a double-edged sword, because that access to information goes both ways.
Opinion: 4 Ransomware trends to watch in 2019
Recorded Future's Allan Liska looks at the past big ransomware attacks thus far to predict what's coming this year.