New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

How fast can organizations respond to a cybersecurity crisis?

New York Tech Editorial Team by New York Tech Editorial Team
March 16, 2022
in Cybersecurity
0
Most CIOs and CISOs underestimate the risk of an OT breach
Share on FacebookShare on Twitter

Immersive Labs launched an analysis of human cyber capabilities. The report analyzed cyber knowledge, skills and judgment from over half a million exercises and simulations run by more than 2,100 organizations in the last 18 months. These were broken down to understand the workforce cyber capabilities of cybersecurity, application security and crisis response teams.

human cyber capabilities

Key findings

Analysis of 35,000 cybersecurity team members inside 400 large organizations reveals it takes over three months (96 days) on average to develop the knowledge, skills and judgment to defend against breaking threats, except with Log4j. Infrastructure and transport are the two slowest sectors, taking an average of more than four months (137 days) to ensure skills development after a threat emerges.

A long lag in human capabilities contrasts significantly with the widely accepted need for swift technical remediation. Government cybersecurity bodies, for example, suggest patching as quickly as 48 hours after a vulnerability emerges. Log4j was an exception to this rule, with cybersecurity teams developing human capabilities within just two days.

Cybersecurity teams prioritize knowledge, skills and judgment development against high-profile threat groups. The top five groups of interest, in order, are UNC2452 (Solarwinds), Iranian Threat Groups, Fin 7, Hafnium and Darkside. Capability development is significantly more rapid with such groups. The knowledge, skills and judgment to defend against SolarWinds, for example, was built nearly eight times quicker than average.

The frequency of organizations conducting cyber crisis exercises varies significantly across sectors. Analyzing over 6400 crisis response decisions shows that technology and financial services companies prepare the most for cyber-attacks, running nine and seven exercises per year respectively. Critical national infrastructure organizations prepare the least, with just one exercise per year.

Ransomware causes great uncertainty for crisis response teams. Seven out of the top 10 least confidently answered crisis scenarios across the entire platform were focused on this threat. When asked, 83% of all organizations chose not to pay the ransom; however, 18% of Government crisis response teams did, despite often being against official guidance.

Application security teams develop human cyber capabilities faster than cybersecurity teams. Analysis of 43,000 hands-on application security exercises shows that 78% are completed faster than expected, as opposed to just 11% for cybersecurity labs. The average application security exercise is completed 2.5 minutes under the predicted complete time – but cybersecurity labs take 17 minutes longer than expected.

The cybersecurity talent of tomorrow struggles to engage with application security. Pointing towards a potential future problem for the industry, of the 176,000 exercises completed by university students and other groups aiming for a career in cybersecurity, application security skills have the lowest engagement rate – a quarter of that of offensive cybersecurity skills. In fact, only 0.5% of all the labs completed focused on application security. With insecure software being the cause of some of the largest breaches of 2021, this highlights a burgeoning future problem for the industry.

Rebecca McKeown, Director of Human Science at Immersive Labs and ex-military psychologist, said, “The data on the time gap between threats breaking and people having the ability to defend against them shows a need for faster time to human cyber capability for large organizations. Without this, people will potentially be making decisions founded in unhelpful biases.”

“Cybersecurity presents a unique skills development challenge for humans. Responding to a hybrid real-world and digital battlespace which is always changing means continuous skills development is crucial to preventing skills decay and building cognitive agility.”

“The insights produced by this report underscore the need for large organizations to have visibility of the cyber capabilities of their workforce, ” said James Hadley, CEO of Immersive Labs. “Without measuring the ability of technical and non-technical teams to mitigate risk, a critical part of resilience is missing. Gaps in cyber knowledge, skills and judgment can have the same impact as technical vulnerabilities.”

Credit: Source link

Previous Post

Why raising capital remains one of the biggest challenges for women-led MSMEs

Next Post

London-based startup procures $8.2 million to make supply chain management hassle-free and real-time

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post

London-based startup procures $8.2 million to make supply chain management hassle-free and real-time

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025
Magnus Almqvist, new CEO of Exberry

Exberry Appoints Magnus Almqvist as CEO to Drive Next Phase of Strategic Growth

March 5, 2025
Expert Family Law Firms in New York: Your Essential Guide to Legal Help

Expert Family Law Firms in New York: Your Essential Guide to Legal Help

March 3, 2025

Recommended

Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media