Back to Insights Risk Management

Rise in Cybersecurity Threats Among Businesses

According to a recent survey conducted by the Wall Street Journal, cybersecurity threats to businesses have increased over the past year. This comprehensive survey, which gathered insights from approximately 300 compliance professionals, reveals that 90% of companies experienced an increase in cybersecurity risks, with nearly half reporting a significant rise. These figures highlight the growing challenges businesses face in protecting their digital assets.

Key Findings:
1. Rise in Cyber Threats: Nearly all mid-sized companies—those with revenues ranging from $50 million to $1 billion—reported an increase in cyber threats.
2. Sector Insights: The survey primarily included professionals from the U.S. (over 75%) and Canada (approximately 4%). It covered various industries, with representation from Financial Services (36%), Professional and Business Services (13%), and Technology (9%).

Primary Concerns: Regulatory Scrutiny and Digitization
Alongside cyber threats, 78% of respondents cited regulatory scrutiny and enforcement as a major concern, while 71% pointed to the digitization of business processes.

Notable Recent Incidents:
Several high-profile cyberattacks highlighted corporate vulnerabilities:
* In September, MGM Resorts International was forced to shut down parts of its computer systems due to a cyberattack that disrupted hotel and casino operations.
* In February, Change Healthcare, a unit of UnitedHealth Group, was hit by a ransomware attack that disabled critical segments of the U.S. healthcare system.

Regulatory Changes:
Regulatory bodies have tightened requirements for rapid reporting of cybersecurity breaches:
* As of December, the SEC requires companies to report cyberattacks within four business days if they have a material impact on company operations.
* The Cybersecurity and Infrastructure Security Agency (CISA) has proposed rules requiring critical infrastructure companies to report major cyberattacks within 72 hours and ransomware payments within 24 hours.

Expertise and Staffing Challenges:
Nearly half of the survey participants admitted to having only a basic or low level of understanding regarding cybersecurity compliance. Only 8% considered themselves experts. Staffing remains a significant challenge, with 35% of respondents citing a manpower shortage in their cyber-compliance programs. Additionally, 31% pointed to the need to keep pace with changing cybersecurity regulations, and 23% noted a lack of required skills among their teams.

Geopolitical Risks:
The survey also delved into how geopolitical tensions affect business risks:
* 64% of respondents reported an increase in risks due to geopolitical factors, with 43% citing the Russia-Ukraine war, particularly among large companies.
* Supply chain risks have risen, with 47% of respondents noting increased concerns.
* U.S.-China tensions, as well as the war in Gaza, are also significantly impacting compliance professionals.

Artificial Intelligence in Compliance:
Artificial Intelligence (AI) is an emerging tool in compliance, although its utilization is not yet widespread:
* Over a third of respondents currently use AI in business compliance, while 46% plan to adopt it in the future.
* Smaller companies are leading the way, with 41% already using AI-based tools, compared to more than half of large companies currently considering adoption.
* Among those using AI, 45% used it to identify control deficiencies, while 44% used AI for cybersecurity. One-third of respondents claimed to use AI for managing regulatory changes.

In summary, despite numerous challenges, 90% of respondents believe their cybersecurity compliance programs are at least somewhat effective. However, the evolving landscape of cyber threats and regulatory requirements demands continuous improvement and adaptation.
See also: “Cyber Threats Rise Along With Scrutiny of How Companies Handle Hacks” – WSJ

Insights from Senior Cyber Experts at IPV Security:

Strengthening Multi-Factor Authentication (MFA)
* Mandate the use of MFA for all employees, especially when accessing sensitive systems and data. MFA adds an extra layer of security beyond passwords, such as a phone-based code or biometric identification (fingerprint, facial recognition).

Periodic Security Training
* Regular employee training on the latest phishing techniques, cyber threats, and how to identify them.
* Use simulated phishing attacks to test and reinforce training.
* Compliance training to ensure the team understands regulatory requirements and the importance of adhering to cybersecurity policies.

Strengthening Incident Response Plans
* Detailed Procedures: Develop and document comprehensive incident response plans. These should include steps for identification, containment, and recovery from cyber incidents.
* System Backups: Maintain backups and practice restoration procedures.
* Tabletop Exercises: Conduct periodic drills to ensure all team members are familiar with their roles during an incident.

Developing a Robust Vendor Management Program
* Conduct periodic assessments of the cybersecurity posture of third-party vendors and partners. Ensure they adhere to your security standards.
* Include cybersecurity requirements in vendor contracts to ensure alignment with your security policies.

Improving Regulatory Compliance
* Stay updated on evolving cybersecurity regulations and ensure compliance programs are current. Timely reporting of cyber incidents to regulatory bodies must be conducted as required by law.

Building a Skilled Cyber Team
* Training and Certifications: Invest in training and certifications for your cyber staff to keep their skills up to date.
* Collaboration with External Experts: Partner with external cybersecurity firms to access specialized expertise and conduct thorough security audits.

Implementing these recommendations will allow your organization to significantly improve its cybersecurity posture and better protect digital assets in a hostile cyber environment. A commitment to continuous improvement and adaptation of cybersecurity strategies is essential for addressing the complexities of modern cyber threats and regulatory demands.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation