{"id":15084,"date":"2015-07-24T15:21:30","date_gmt":"2015-07-24T15:21:30","guid":{"rendered":"http:\/\/kasperskydaily.com\/b2b\/?p=4272"},"modified":"2020-02-26T18:55:16","modified_gmt":"2020-02-26T16:55:16","slug":"is-it-time-to-re-think-enterprise-it-security","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.za\/blog\/is-it-time-to-re-think-enterprise-it-security\/15084\/","title":{"rendered":"Is it time to re-Think Enterprise IT Security?"},"content":{"rendered":"<p>Top-level IT security pros believe there\u2019s a significant, unaddressed gap between enterprise security priorities and the serious threats that keep them awake at night.<\/p>\n<p>According to the Black Hat USA 2015 attendee <a href=\"https:\/\/www.blackhat.com\/docs\/us-15\/2015-Black-Hat-Attendee-Survey.pdf\" target=\"_blank\" rel=\"noopener nofollow\">survey<\/a>, 73% of enterprise security professionals believe their organization will suffer a major data breach over the next 12 months.<\/p>\n<p>At a time when Gartner says enterprises have never spent more on security \u2013 <a href=\"http:\/\/www.gartner.com\/newsroom\/id\/2828722\" target=\"_blank\" rel=\"noopener nofollow\">more than $76 billion in 2015<\/a> \u2013 major breaches, from Target to Anthem and OPM, show no sign of abating.<\/p>\n<p><strong>Where are we going wrong?<\/strong><\/p>\n<p>According to the security pros at Black Hat, it\u2019s all about priorities. Only 27% of security professionals feel capable of addressing a breach \u2013 because they\u2019re too busy dealing with vulnerabilities introduced by internally developed and off-the-shelf software. While these threats are important to 35%, 57% view sophisticated targeted attacks as their biggest concern \u2013 an area that features in the top three spending categories of only 26% of businesses.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Is it time to re-Think Enterprise IT Security? #enterprisesec<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2F1BHC&amp;text=Is+it+time+to+re-Think+Enterprise+IT+Security%3F+%23enterprisesec\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>The second greatest concern \u2013 phishing and social engineering \u2013 receive only 22% of the security budget.<\/p>\n<p><strong>In a nutshell<\/strong><\/p>\n<p>The security tasks that consume the greatest amount of time and money in the enterprise aren\u2019t always the ones that are considered the greatest threats. There\u2019s a gap between budgets and the latest threats, and it\u2019s difficult to bridge the divide between spending and current concerns.<\/p>\n<p>It\u2019s not the only gap: Security professionals\u2019 perception of the threat posed by malicious insiders is lower than that of non-IT management. Only 44% of security staff believed that management rated targeted attacks as seriously as they do; that drops to 29% for social engineering. Key threats, it seems, are being overlooked as a gap grows between mainstream concerns and those of security professionals.<\/p>\n<p>When it comes to defense strategies, it\u2019s interesting to note that security professionals are worried about flaws in their own approach \u2013 one-fifth of them cite a \u201clack of security architecture and planning that goes beyond firefighting\u201d as their weakest link. There\u2019s a belief that single-purpose technologies or solutions are leaving way too many chinks in the armor.<\/p>\n<p><strong>Missed opportunities?<\/strong><\/p>\n<p>Despite the gap, it\u2019s interesting to see that 81% of security experts believe non-IT-management \u2018get\u2019 security and the need for it. The belief that they have the support of management is widespread.<\/p>\n<p>Maybe what\u2019s missing is a little more communication and a conversation that frames the threats more clearly. Kaspersky Lab\u2019s long track record in threat intelligence, making some of the highest profile, most relevant threat discoveries means it\u2019s uniquely placed to facilitate this conversation.<\/p>\n<p>Our understanding of the inner workings of some of the world\u2019s most sophisticated attacks \u2013 coupled with our ability to detect and monitor them \u2013 not only gives security professionals the kind of insight they need into the latest, most relevant threats, but provides the strategic insight needed to represent these security risks at board level, aligning them directly with business impacts.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>There\u2019s never been a better time for IT security professionals to make their mark on the business. #enterprisesec<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2F1BHC&amp;text=There%26%238217%3Bs+never+been+a+better+time+for+IT+security+professionals+to+make+their+mark+on+the+business.+%23enterprisesec\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>That should help differentiate between the mainstream and the critical in an environment where 91% of business users grossly underestimate threat volumes.<a title=\"\" href=\"#_ftn1\" name=\"_ftnref1\" target=\"_blank\" rel=\"noopener\"><sup>1<\/sup><\/a><\/p>\n<p><strong>Bend, don\u2019t break<\/strong><\/p>\n<p>This survey also highlights the need for a little more business understanding of how automating or streamlining time-consuming tasks like application vulnerability management could deliver a more effective overall security strategy aligned with the knowledge and understanding of the security experts.<\/p>\n<p>Kaspersky Lab\u2019s multi-layered platform combines industry-leading security technologies and threat intelligence capabilities with fully integrated systems management features such as vulnerability assessment and patch management. By enabling the automation of critical-yet-time-consuming security functions, Kaspersky Lab helps security professionals dedicate more of their time to addressing current and emerging issues \u2013 like the targeted threats that occupy so much of their minds, but so little of their working day.<\/p>\n<p><strong>Real world security, in real-time<\/strong><\/p>\n<p>It\u2019s obvious that security has got the board\u2019s attention. There\u2019s never been a better time for IT security professionals to make their mark on the business. Wouldn\u2019t it be nice if your security solution not only responded to the needs of the CISO, but aligned with the business too?<\/p>\n<p>Maybe all that\u2019s needed is a little re-thinking. And a lot more communication.<\/p>\n<p>Learn more about Kaspersky Systems Management <a href=\"https:\/\/www.kaspersky.com\/business-security\/systems-management\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">here.<\/a><\/p>\n<p style=\"font-size: smaller\"><a title=\"\" href=\"#_ftnref1\" name=\"_ftn1\" target=\"_blank\" rel=\"noopener\">1<\/a> Kaspersky Lab <em>Global IT Security Risk Survey 2014<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Top-level IT security pros believe there\u2019s a significant, unaddressed gap between enterprise security priorities and the serious threats that keep them awake at night. <\/p>\n","protected":false},"author":664,"featured_media":15622,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1999,3021],"tags":[2323,298,76,513,2324,81,2037],"class_list":{"0":"post-15084","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-black-hat-usa-2015","10":"tag-it-security","11":"tag-phishing","12":"tag-social-engineering","13":"tag-systems-management","14":"tag-targeted-attacks","15":"tag-vulnerability-assessment"},"hreflang":[{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/is-it-time-to-re-think-enterprise-it-security\/15084\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/is-it-time-to-re-think-enterprise-it-security\/15084\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/is-it-time-to-re-think-enterprise-it-security\/15084\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.za\/blog\/tag\/black-hat-usa-2015\/","name":"black hat usa 2015"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/15084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/users\/664"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/comments?post=15084"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/15084\/revisions"}],"predecessor-version":[{"id":26559,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/posts\/15084\/revisions\/26559"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/media\/15622"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/media?parent=15084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/categories?post=15084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.za\/blog\/wp-json\/wp\/v2\/tags?post=15084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}