Businesses are not doing enough to combat online threats and risks despite an increased awareness of the need to take cyber security seriously, according to research by ICAEW based on the experiences of auditors from the six largest accounting firms
The institute’s report, Audit Insights: Cyber Security, says there is a growing gap between business and cyber attacker capabilities, with economic growth and new business activity continuously creating new cyber risks which have to be addressed.
The complex nature of supply chains, increased exploitation of digital channels and the disparate nature of data storage across servers, cloud storage and mobile devices, are all areas for concern of they provide access points for attackers to exploit.
Richard Anning, head of ICAEW’s IT faculty, said: ‘Businesses are more aware of cyber risks than before and are working to mitigate threats, yet they are still falling further behind the cyber attackers. Businesses must now match their good intentions with action.’
The ICAEW recommends that organisations identify business-critical data and associated risks, even when there is no regulatory requirement to do so, and says they should challenge the IT function to explain its security strategy and risk mitigation plans.
The research is supprted by EY’s annual Global Information Security survey, Get Ahead of Cybercrime, which shows that although most organisations (67%) report growing levels of online risk, over a third (37%) lack the real-time insight on cyber risks necessary to combat these threats.
Over half (53%) say that a lack of skilled resources is one of the main obstacles challenging their information security program, while only 5% of responding companies have a threat intelligence team with dedicated analysts.
‘Careless or unaware employees’ is the number one vulnerability companies face, cited by 38% as their first priority, followed by ‘outdated information security controls or architecture’ (35%) and ‘cloud computing use’ (17%).
The top three threats are identified as ‘stealing financial information’, 'disrupting or defacing the organisation’ and ‘stealing intellectual property or data.’
Mark Brown, executive director of cyber security and resilience at EY, said: ‘Organisations must undertake a journey from a reactive to a proactive posture, transforming themselves from easy targets for cybercriminals into more formidable adversaries.
'Organisations are not taking the basic steps, such as setting up a security operations centre or putting in place an incident response plan, and this continues to be a major cause for concern.’
This view is echoed by the ICAEW report, which recommends companies should design cyber security into all strategy and operations, considering it a business risk rather than a technical issue. They should pay more attention to the monitoring, detection and response to threats, and work with industry bodies and supply chain partners to share information on threats and attacks.
Anning said: ‘It is no longer about simply being compliant with data protection regulations. Businesses must demonstrate that they are ready to deal with cyber attacks by having a plan of action in place.
'This is particularly important for businesses hoping to enter a major supply chain or considering IPO, a merger or acquisition. It could also provide a competitive advantage against others in the market.’