Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

9/26/2018
02:30 PM
Ger Daly
Ger Daly
Commentary
Connect Directly
Twitter
RSS
E-Mail vvv
50%
50%

A 'Cyber Resilience' Report Card for the Public Sector

Government agencies are making great strides in defending themselves against cyberattacks, according to new research from Accenture. But technology alone won't solve the problem.

Cyberattacks against governments agencies are increasing in frequency, sophistication, and severity, demanding heightened vigilance. New research from Accenture finds that public service organizations experience on average 31 successful security breaches each year, often resulting in significant damage or the loss of high-value assets. And it only takes one successful cyberattack to create widespread damage, as demonstrated by the recent WannaCry and Petya malware attacks. Thankfully, government organizations are demonstrating success in defending themselves against attacks.

Our survey of 4,600 security practitioners (including 400 from government agencies) across 15 countries finds that government agencies today are preventing the majority (87%) of focused cyberattacks and that most understand the benefits of digital technologies for organizational and data security. Most respondents (83%) agree that new technologies such as artificial intelligence and machine learning are essential to achieving a sustainable level of cyber resilience, and two-thirds (62%) plan to continue investing in these technologies.

While building capacity for wise security investments is a priority for public service organizations, technology alone will not be sufficient to defend against cyberattacks. Government agencies must look beyond their four walls for help, while also taking steps to identify and address internal threats.

Security Teams Are Finding Breaches Faster; Collaboration Is Critical
Government agencies are detecting security breaches faster than ever before. More than half (52%) of survey respondents say it takes them one week or less to detect a security breach. However, despite faster detection times, security teams are finding less than two-thirds (63%) of all breaches. To improve detection rates, teams must develop strategic and tactical threat intelligence tailored to their organizations, which will allow them to identify security risks and constantly monitor for anomalous activity at the most likely points of attack.

When asked how they learn about attacks that their internal security teams are unable to detect, government respondents indicate that most attacks are identified with the assistance of law enforcement, white-hat hackers, peers, or competitors. These findings underscore the importance of cross-sector collaboration.

Agencies Are Addressing Cybersecurity from the Inside Out
While cyberattacks by external actors continue to pose a serious threat, organizations should not ignore the enemy within. According to survey respondents, two-thirds (72%) of the most damaging security breaches are the result of actions undertaken by internal actors such as employees. Many of these breaches result in sensitive information being published online accidentally or shared with unauthorized third-parties. A previous survey of health employees in North America reports that nearly one in five employees (18%) say they would be willing to sell confidential data to unauthorized parties.

Organizations must take a proactive approach to technology deployments, while reinforcing security behaviors and enhancing existing security protocols to help employees cope with increasingly sophisticated cyberattacks. For example, strengthening email controls and passwords as well as utilizing stronger spam filters can prevent malicious correspondence from reaching employees and reduce the likelihood that they fall victim to phishing scams.

Organizations can build a strong security foundation by identifying high-value assets and hardening the security around them, and by ensuring high levels of security are deployed across the entire organization — not just around core corporate functions. Organizations must also pressure test their system's resilience by behaving like an attacker so they can better understand their vulnerabilities.

Cybersecurity Investments Continue to Grow, but in a New Direction
The heightened state of cyber awareness within government is also helping to fuel investments. A majority (87%) of public sector respondents say their organization plans to increase security-related spending over the next three years. When asked which capabilities are needed, nearly half (44%) cite either cyber-threat analytics or security monitoring (46%).

However, organizational spending patterns are shifting. The study identifies a growing focus on technologies that protect employee privacy (33%) and enhance customer security (32%). Spending in these areas will likely increase as new legislation emerges across the world to protect citizen data, adding further requirements on government organizations' security practices.

Ideally, all cybersecurity investments should be overseen by a designated chief information security officer (CISO), a senior-level executive responsible for developing and implementing an information security program, which includes all procedures and policies designed to protect an organization's communications, systems, and assets from internal and external threats. Government organizations must take immediate steps to develop the next generation of public service CISOs, who are capable of balancing security requirements with their organization's operational risk appetite.

Related Content:

 

Black Hat Europe returns to London Dec. 3-6, 2018, with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions, and service providers in the Business Hall. Click for information on the conference and to register.

Ger Daly is Accenture's managing director for defense and public safety. Mr. Daly leads Accenture's defense, policing, customs and borders work with government clients globally. His defense industry experience spans large-scale enterprise resource programs (ERP), supply chain ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3035
PUBLISHED: 2021-04-20
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.
CVE-2021-3036
PUBLISHED: 2021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where secrets in PAN-OS XML API requests are logged in cleartext to the web server logs when the API is used incorrectly. This vulnerability applies only to PAN-OS appliances that are configured to us...
CVE-2021-3037
PUBLISHED: 2021-04-20
An information exposure through log file vulnerability exists in Palo Alto Networks PAN-OS software where the connection details for a scheduled configuration export are logged in system logs. Logged information includes the cleartext username, password, and IP address used to export the PAN-OS conf...
CVE-2021-3038
PUBLISHED: 2021-04-20
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect app on Windows systems allows a limited Windows user to send specifically-crafted input to the GlobalProtect app that results in a Windows blue screen of death (BSOD) error. This issue impacts: GlobalProtect app 5.1 versions...
CVE-2021-3506
PUBLISHED: 2021-04-19
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The hi...