Connect with us

Hi, what are you looking for?

HEADLINES

PH companies fail to address nearly half of cyber threat alerts received

Companies in Philippines do not address nearly half of the legitimate cyber threat alerts they receive, according to the Cisco 2018 Asia Pacific Security Capabilities Benchmark Study. 

Among those surveyed, 42 percent say they receive more than 5000 alerts each day. While companies in Philippines rank the lowest in Southeast Asia among those receiving more than 5,000 alerts per day, the real challenge lies in what comes after the alert is received, and how many are actually investigated.

The study shows that on average just 50 percent of the alerts received are investigated by companies in Philippines. Of those investigated, on average, only 30 percent turn out to be legitimate, of which only 51 percent are acted upon and corrected. This suggests that more work is needed to help companies and security professionals in Philippines to tackle the rapidly evolving cyber threat landscape.

The results of the study highlight the scale of the challenge faced by the companies, with 79 percent of respondents saying their organization has suffered a breach in the past year. 

Advertisement. Scroll to continue reading.

Cyberattacks are also having a significant financial impact. Among those who suffered an attack in the past twelve months, 35 percent say it cost them US$500,000 or more, while 25 percent say the cost was US$1 million or more. This includes costs from lost revenue, loss of customers, and out of pocket expenses etc.

“In the Philippines, digital transformation has been a favourite theme for consumers, businesses, and the government. While we have seen many benefits from digital innovation and adoption, it is important to ensure that we have the right infrastructure, processes, and technologies in place that continue to enable and empower digital growth. The ability to tackle the cybersecurity threat is critical on that front,” says Karrie Ilagan, Managing Director for Philippines at Cisco.  

“All stakeholders need to work together in a coordinated manner to achieve this. Businesses need to raise awareness about the issue, have proper processes in place and deploy the right technologies to help identify, block or address any attacks. We need strict regulations that deter malicious actors from taking the risk of launching such attacks. Finally, we need to develop local cybersecurity talent so we have the manpower to support the country’s digital drive in a sustainable manner,” she adds.

Cyberattacks are starting to evolve from just targeting IT infrastructure to attacking operational infrastructure, intensifying the challenge for companies. According to the survey, 19 percent of respondents say they have already seen cyberattacks on their operational infrastructure, 35 percent said they expect similar attacks to take place on them within the next one year.

Given the growing scale of cyber threats, respondents say they expect scrutiny of their security policies to increase over the next one year from all stakeholders, especially their customers who are keen to ensure their data is protected. Among those surveyed, 76 percent say they expect increased scrutiny from customers. Privacy concerns are also delaying sales for the companies, with 66 percent of respondents saying such concerns are adding time to the sales cycle. 

Advertisement. Scroll to continue reading.

“When it comes to cyber security, it is no longer a case of a company needing to protect just its own IT infrastructure. Today, business partners, customers, and employees expect a company to keep their data secure. With stringent regulations like the European Union’s General Data Protection Regulation (GDPR) coming into force, the pressure on companies to have the right policies, technology and resources in place will only increase. Those who lag behind run the risk of not only facing high financial penalties, but also losing the trust of customers,” says Stephen Dane, Managing Director of Security for Asia-Pacific, Japan and China at Cisco.

The use of multiple vendors and products is making the challenge more complex. The study shows that 39 percent of surveyed organizations work with more than 10 security vendors, while 41 percent use more than 10 security products or solutions. This creates complexity and increases vulnerability, as having different security products, can lengthen the time to identify and contain a breach. The study highlights that companies are already facing this issue, with 97 percent of respondents saying they find it challenging to orchestrate multiple vendor alerts. 

To put this in context, it is estimated that an almost instant detection of a cyber security breach within a large enterprise costs the business US$433,000. If detection is delayed by more than a week, this figure triples to an average US$1,204,000.

Key recommendations: Based on the findings of the survey, the study has made a series of recommendations that will provide companies with more actionable visibility into the threat landscape, reduce their exposure and improve their security posture. The report states that companies should consider: 

  • Adopting next-generation end point process monitoring tools
  • Accessing timely, accurate threat intelligence data and processes that allow for data to be incorporated into security monitoring and eventing
  • Implementing first line–of-defence tools that can scale, like cloud security platforms
  • Employing network segmentation to help reduce outbreak exposures 
  • Reviewing and practicing security response procedures regularly

Advertisement. Scroll to continue reading.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

The PLDT wireless unit is also calling on customers to report these messages to Smart’s HULISCAM portal for further action.

HEADLINES

Here are some tips from Sophos for staying secure online during the cybersecurity awareness month.

HEADLINES

While only 21% of hackers believed that AI technologies enhance the value of hacking in 2023, 71% reported it to have value in 2024....

HEADLINES

Kaspersky has enhanced its Kaspersky Industrial CyberSecurity (KICS), a native XDR Platform for industrial enterprises, and streamlined Managed Detection and Response (MDR) for Industrial...

MOTORING

HATASU, your go-to brand for safe, sustainable, and value-for-money mobility solutions, is gearing up to make this season fang-tastic for everyone—young and old alike!

HEADLINES

When asked about how satisfied they were with their job, 85% of respondents shared a neutral or positive answer, which equals to an overall...

HEADLINES

Located in the Kaspersky office, the new facility will provide the company’s stakeholders with services ranging from an overview of Kaspersky’s practices, to a...

HEADLINES

Smart and Maya emphasize that they never send SMS with links requesting login credentials, personal information, or account verification. If you receive such a...

Advertisement