77 percent of executives ‘confident’ in basic security controls

Twenty-seven percent of IT professionals ‘not confident’ in the secure configuration of network devices.

Tripwire, Inc. has announced the results of an extensive survey conducted by Atomik Research on the state of foundational security controls. The survey respondents included 404 IT professionals and 302 executives from retail, energy and financial services organizations in the U.S. and U.K.


Respondents were asked about the level of confidence they have in their application of foundational security controls, including hardware and software inventory, vulnerability management, patch management and system hardening. These controls are required by the most widely recognized global security standards and organizations, including:
• The PCI Data Security Standard (PCI DSS)
• North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP)
• National Institute of Standards and Technology (NIST)
• The Sarbanes-Oxley Act (SOX)
• The Health Insurance Portability and Accountability Act (HIPAA)
• Control Objectives for Information and Related Technology (COBIT)
• ?International Organization for Standardization (ISO)

According to a report by the United States Computer Emergency Readiness Team (US-CERT), 96 percent of successful data breaches could be avoided if simple or intermediate security controls were put in place. Tripwire’s survey found that 77 percent of all respondents felt “confident” in their implementation of these basic security controls. However, despite the ongoing increase in targeted cyberattacks, 27 percent of IT professionals remain “not confident” in the secure configuration of common devices connected to their network.


Key survey findings included:
• Over 100 million records have been comprised in retail data breaches in the last 12 months as a result of malware on point of sale devices, but 77 percent of retail IT professionals are “confident” that all of the devices on their network are running only authorized software.
• Despite an ICS-CERT warning regarding an ongoing, sophisticated malware campaign targeting ICS systems, 89 percent of executives from the energy industry are “very confident” or “fairly confident” in their vulnerability management program.
• Only 10 percent of security professionals are “very confident” in their patch management program.
• Only 47 percent of IT professionals are “confident” in the secure configuration of routers, firewalls and modems connected to their network.
 

Atos has won a new contract with Utmost Life and Pensions, a UK-based Life & Pensions provider, to...
EthosEnergy has successfully enhanced its data management and business continuity with the Nasuni...
Technology explores simplifying and securing hybrid multicloud connectivity at scale to deliver...
With Cubbit DS3, healthcare company ASL CN1 Cuneo protects its data with exceptional resilience...
‘Intelligent partner’ for SecOps and NetOps will allow teams to query network activity, drill...
53% of Tech Companies Integrate Cloud Solutions With AI, According to Survey of IT Decision-Makers
New state-of-the-art data centre features Vultr’s first AMD GPU supercompute cluster.
Only a quarter (25%) think their approach to the cloud is carefully considered and successful.