Study: Most Critical Infrastructure Firms Have Been Breached

  /     /     /  
Publicated : 22/11/2024   Category : security


Study: Most Critical Infrastructure Firms Have Been Breached


A new Ponemon Institute study finds 70% of critical infrastructure companies have been hit by security breaches in the last year, but cyber security programs are still a low priority.



Uptime still trumps proactive cyber security measures in most critical infrastructure organizations worldwide, a new Ponemon Institute study shows.
Though 60% of global IT and IT security executives at critical infrastructure organizations say minimizing downtime is a top security objective, just 32% say improving their security posture is a priority. On top of that, 67% say they suffered at least one security breach in the past 12 months that resulted in confidential data loss or disruption to operations. Nearly one-fourth of those attacks were due to insiders or privileged IT users being negligent, the respondents said.
Security as a priority… that didnt make the top five list, says Larry Ponemon, chairman and founder of the Ponemon Institute. Availability and uptime are top priorities.
Preventing and quickly detecting advanced persistent threats (APTs) was a priority for 55% of companies, followed by preventing cyber attacks (44%), compliance (40%), securing the national critical infrastructure (35%), and then, with 32%, improving the organizations security posture.
The perspective of prioritizing availability over improving security is short-sighted, says Dave Frymier, CISO at Unisys, which commissioned the study. If you have a cyber security event, its probably going to affect the availability of your service.
Meanwhile, critical infrastructure firms remain conflicted about patching their software with security or other updates. Fifty-four percent say their organization cant upgrade legacy systems to more secure systems cost-effectively without sacrificing mission-critical security, the report says.
The full report, Critical Infrastructure: Security Preparedness and Maturity, is available
here
for download.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Study: Most Critical Infrastructure Firms Have Been Breached