Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Survey: SIEM, Database Security Top of Mind for IT Professionals

Security Information and Event Management (SIEM) solutions have been put under the microscope and are often criticized by some in the industry as being outdated and “reactive” security solutions that don’t always help organizations defend against cyber attacks, but rather help respond after a damaging attack. While SIEM solutions may be taking some heat, they still play an important role in an organization’s overall security strategy, and new research from McAfee shows that SIEM is still top of mind for security executives.

Security Information and Event Management (SIEM) solutions have been put under the microscope and are often criticized by some in the industry as being outdated and “reactive” security solutions that don’t always help organizations defend against cyber attacks, but rather help respond after a damaging attack. While SIEM solutions may be taking some heat, they still play an important role in an organization’s overall security strategy, and new research from McAfee shows that SIEM is still top of mind for security executives.

In its annual study that looks to see how IT decision-makers view and address risk and compliance management, McAfee’s Risk and Compliance Outlook: 2012 found that Database Security and SIEM were among the top priorities due to the rise in advanced persistent threats and increased compliance requirements.

According to the report, database security appears to be an ongoing concern for organizations due to growing compliance requirements and high profile data breaches that have hit just about every industry.

When asked about sensitive database breaches, over one quarter of the 438 respondents had either had a breach or didn’t have the visibility to detect a breach, making SIEM a top concern. The results revealed that most organizations rely on legacy systems that do not meet their current needs, with approximately 40% of respondents saying they plan to implement or update a SIEM solution. While 80% of respondents cited visibility as very important, security teams remained challenged in this area. Discovering threats was listed as the top challenge to managing enterprise risk.

Other key findings include:

•  96% of organizations indicated they would spend the same or more on risk and compliance solutions as part of their 2012 security budgets.

• Approximately half of respondents spend 6 to 10 hours per month on risk management activities that assess and correlate the impact of threats on their organizations.

• Respondents said ‘Compliance’ was the driver for almost 30% of IT projects.

Advertisement. Scroll to continue reading.

• On average, one-third of all organizations prioritized the upgrade/implementation of unique risk and compliance products to address vulnerability assessment, patch management, remediation, governance, risk management, and compliance.

• Nearly 40% organizations claim to be moving towards hosted SaaS and virtualized deployment models in 2012.

• Patch Management frequency is a challenge – almost half of the organizations patch on a monthly basis with one-third doing it on a weekly basis. Just like last year’s analysis, not all companies are able to pinpoint threats or vulnerabilities, as a result, 43% indicate that they over-protect and patch everything they can.

“Managing risk through security and compliance continues to be a leading concern for organizations the world over,” said Jill Kyte, vice president of security management at McAfee. “Meeting the requirements of increasingly demanding regulations while reducing exposure to the new classes of sophisticated threats and having an accurate understanding of risk and compliance at any point in time – can be challenging. To address this issue, organizations are looking to ‘best-of-breed’ solutions to manage all aspects of their risk and compliance needs and reduce the amount of time spent managing multiple solutions.”

The study was conducted by Evaluserve for McAfee, and includes responses from 438 IT decision makers, consultants and security analysts from companies with more than 250 worldwide employees who are involved in evaluation, selection, day-to-day management and maintenance of security products. Surveys were conducted in Australia, Brazil, Canada, France, Germany, New Zealand, Singapore, United Kingdom and United States.

The full report is available here.

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Compliance

Web scraping is a sensitive issue. Should a third party be allowed to visit a website and use automated tools to gather and store...

Cloud Security

Proofpoint removes a formidable competitor from the crowded email security market and adds technology to address risk from misdirected emails.

Application Security

Microsoft on Tuesday pushed a major Windows update to address a security feature bypass already exploited in global ransomware attacks.The operating system update, released...