Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

A new survey of managers and executives revealed that organizations are all talk and no walk when it comes to risk-based security management, as most have not implemented a formal program to manage risk.

According to research by Tripwire and the Ponemon Institute, security spending within organizations is not aligned with perceived risk. Organizations are making excellent progress with deploying preventive controls, but are not implementing detective controls, the survey found. In fact, for organizations in the United States, 80 to 90 percent said they have partially or fully deployed preventative controls, but only 50 percent have deployed the majority of detective controls, according to Tripwire. As a result, the organizations are unable to identify, implement, and continuously monitor their programs effectively.

The State of Risk Based Security Management (RBSM) study found that many organizations are relying on cost reductions to gauge the success of RBSM programs. Such a metric can “encourage the wrong behavior and actually increase the risk,” Tripwire said.

“We believe risk-based security management will transform organisations’ approach to protecting critical information assets and technologies from one that is reactive to proactive,” said Larry Ponemon of the Ponemon Institute.

Although organizations claim to be strongly committed to RBSM, they aren’t taking action, the survey found. Over 72 percent of UK organizations claimed a “significant” or “very significant” commitment, but more than half of the surveyed organizations didn’t have formal strategies or procedures in place to manage risk. The numbers are similar for US organizations, with 77 percent expressing a strong commitment, but only 52 percent adopting a formal approach. Only 46 percent have actually deployed any RBSM activities, according to the survey.

This gap creates potential risks for businesses moving forward, Tripwire said.

“Savvy security executives will leverage risk as a means to drive business-relevant discussions, and use objective measures to show security effectiveness. It is imperative to break the cycle of ‘habitual security spending’ to better align security resource allocations within their businesses,” said Dwayne Melancon, CTO for Tripwire.

Advertisement. Scroll to continue reading.

The survey collected information from 2,145 individuals from organizations of different sizes and types in the United Kingdom, Germany, Netherlands and the United States. The respondents were asked how they viewed risk-based security management  within their organizations, how they addressed the risks, and how they measured the effectiveness of the measures deployed.

Greatest IT Security Risks

Perceptions of RBSM differed in the US, UK, Germany and the Netherlands, the survey found. In the US, 71 percent of organizations said they were concerned about malicious insiders, compared to 49 percent in UK, 32 percent in Germany, and only 16 percent in the Netherlands.

Tripwire actually released U.S. results earlier in June during the Gartner Security & Risk Management Summit. About 30 percent of organizations in the US had no RBSM strategy, and about 23 percent had an informal or ad-hoc strategy, Tripwire said.

“It is evident from this data that CISO’s must to move beyond ‘lip service’ when it comes to Risk-Based Security Management,” said Melancon.

The full report is availble here.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...