Half of all large multinational corporations think they should have a separate cyber security budget to tackle the growing threat from highly organised criminal attacks, according to research from KPMG and BT
The report, Taking the Offensive – Working together to disrupt digital crime, finds that, while 94% of IT decision makers are aware that criminal entrepreneurs are blackmailing and bribing employees to gain access to organisations, roughly half (47%) say they do not have a strategy in place to prevent it.
Only a fifth of IT decision makers in large multinational corporations are confident that their organisation is fully prepared against the threat of cyber-criminals. The vast majority of companies feel constrained by regulation, available resources and a dependence on third parties when responding to attacks.
The research found that 97% of respondents experienced a cyber-attack, with half of them reporting an increase in the last two years.
Paul Taylor, UK head of cyber security, KPMG said: ‘It’s time to think differently about cyber risk – ditching the talk of hackers – and recognising that our businesses are being targeted by ruthless criminal entrepreneurs with business plans and extensive resources – intent on fraud, extortion or theft of hard won intellectual property.’
The report indicates that a quarter (26%) of respondents have already appointed a chief digital risk officers (CDRO). While 60% of decision makers reporting that their organisation’s cyber security is currently financed by the central IT budget, half of them (50%) think it should come from a separate security budget. One major challenge identified by the research is the funding and scale of R&D spending that the criminals can bring to bear on breaching the defences of target companies.