Despite Optimism, Companies Must Improve Security Strategies as Incidents Continue to Rise

Press release from the issuing company

Monday, September 24th, 2012

The rise in global security incidents, diminished budgets and degrading security programs have left organizations to deal with security risks that are neither well-understood nor consistently addressed. Executives around the world feel confident that they're winning the high-stakes game of information security despite the growing number of obstacles, according to The Global State of Information Security® Survey 2013 released today by PwC US in conjunction with CIO and CSO magazines.

"Security models of the past decade are no longer effective. Today's rapidly evolving threat landscape represents a danger that shows no signs of diminishing, and businesses can no longer afford to play a game of chance," said Mark Lobel, a principal in PwC's Advisory practice. "Companies that want to be information security leaders should prepare to play a new game – one that requires advanced skills and strategy to win against emerging threats."

According to the tenth annual survey, the general mood among global executives is largely optimistic. The majority of respondents said they are very or somewhat confident their organizations have instilled effective information security behaviors into their culture (68 percent), and are very or somewhat confident their information security activities are effective (more than 70 percent). Yet, while nearly half of respondents (42 percent) view their organization as a "front-runner" in information security strategy and execution, the survey finds that only 8 percent actually qualify as true information security leaders.  According to PwC, "leaders" are defined as companies that have a chief information security officer (or CISO equivalent) who reports to the organization's top executives, have an overall information security strategy in place, have measured and reviewed the effectiveness of their security in the last year, and understand exactly what types of security events have occurred.

"Clearly, many executives have unfounded confidence in their security capabilities," said Bob Bragdon, publisher of CSO. "In order to strengthen security practices, organizations must embrace a new way of thinking in which information security is both a means to protect data as well as an opportunity to create value to the organization. Security strategies and security spending must be well-aligned with business goals."

Despite an increase in the number of respondents reporting 50 or more incidents (13 percent), fewer than half (45 percent) expect an increase in their budgets in the next 12 months – down from 51 percent and 52 percent in 2011 and 2010, respectively. While multiple factors shape security budgets, the primary determinant is the economic environment, with information security concerns far down the list. Also, senior executives are frequently seen as understanding the problem, with half of respondents – including 86% of the security "leaders" – pointing to top-level leadership as the greatest obstacle to improving information security effectiveness.

The survey shows that a winning security practice is often hindered by decreased deployment of basic information security and privacy tools. Among the categories taking a hit are malicious code detection tools for spyware and adware, down to 71 percent after topping out at 84 percent in 2008, and intrusion detection tools, once in use by nearly two-thirds of respondents and now used by just over half.

In today's world of "big data," the survey also finds that most organizations are keeping looser tabs on their data today than in years past. While more than 80 percent say protecting customer and employee data is important, far fewer understand what that data entails and where it is stored. Fewer than 35 percent of respondents said they have an accurate inventory of employee and customer personal data, and only 31 percent reported they had an accurate accounting of locations and jurisdictions of stored data.

The decreased deployment of security and privacy tools is like playing a championship game with amateur sports equipment," continued PwC's Lobel.  "Intruders are exploiting business ecosystems, leaving reputational, financial and competitive damage in their wake. Today's information security leaders must acknowledge that playing the game at a higher level is required to achieve effective security. The very survival of the business demands that they understand, prepare for, and quickly respond to security threats."

Addressing Security Threats in Social, Mobile and the Cloud
As mobile devices, social media, and the cloud become commonplace inside the enterprise and out, technology adoption is moving faster than security. PwC has found that 88 percent of consumers use a personal mobile device for both personal and work purposes, yet only 45 percent of companies have a security strategy to address personal devices in the workplace and 37 percent have malware protection for mobile devices.

Despite an increase in the number of respondents reporting safeguards in place for mobile, social media, cloud computing, and policies covering the use of employee-owned devices, only 44 percent report having a mobile security strategy and less than 40 percent have strategies for the cloud and social media. These numbers lag the adoption rates of the technologies themselves.

Asia Leads in Practices and Performance, while North America Leads in Mobile and Social
The survey finds that years of investment pay off as Asia leads the world in security practices and performance. Among all regions, Asia has the fewest respondents who expect a decrease in security budgets this year. Roughly 60 percent of Asia respondents expect to see an increase over the next 12 months. That's down from 74 percent in 2011, but still among the highest of any region. As for keeping up with new challenges, Asiarates highly for mobile security initiatives and cloud security strategy.

Despite Asia's lead in practices and performance, North America ties Asia for the lead in cloud security strategy and leads in mobile and social media security. Responses from North American firms also indicate that they are the least likely to outsource security functions. Further responses indicate North American organizations are the best at staying on plan when it comes to IT projects.

To learn more about the survey, including industry specific highlights and further regional information, please visit:  www.pwc.com/giss2013.