Businesses Overestimate Their Defense Against Cyber Threats

A recent Cohesity report reveals that many organizations are struggling with business continuity as the frequency of malicious threats continues to escalate. The study indicates that businesses often overestimate their cyber resilience, finding themselves unable to meet their recovery objectives when faced with ransomware or other cyberattacks.

The survey, which included over 3,100 IT and security professionals across eight countries, highlights a significant disparity between companies’ self-reported resilience and their actual performance under attack. Despite having policies against paying ransoms, nearly 70% of IT and security leaders admitted their organizations paid ransoms in the past year. Additionally, around 80% of respondents stated that their companies had a no-ransom policy.

The findings also reveal that almost half of the companies need more than six days to restore essential business functions following an attack. This contrasts sharply with the 98% of respondents who reported having a target recovery time of just one day for such incidents.

The report underscores a troubling gap between companies’ perceived and actual capabilities when facing cyber threats. This issue has gained heightened relevance following significant incidents like the February ransomware attack on Change Healthcare and the July IT outage that affected 8.5 million Microsoft Windows devices due to a problematic CrowdStrike software update.

Conducted by Censuswide between June 27 and July 18, the survey illustrates that while 80% of respondents expressed confidence in their resilience strategies, this confidence appears to be based more on aspirational goals rather than practical, demonstrated performance.

More Articles & Posts