Firms failing to implement watertight cyber security incident response plans
Without a fully tested plan, organisations may find a breach costs $1million more than those whose plans are tried and tested...
More than three quarters of businesses don't have a consistent cyber security incident response plan and half of businesses that do have one in place haven't tested them, according to research by Ponemon Institute.
Those who have thoroughly tested their plans are able to contain an attack within 30 days, which should offer some motivation to those not properly preparing for an incident. Indeed, on average, businesses that have a robust cybersecurity incident plan save over $1 million on the total cost of a data breach, according to the research, which was commissioned by IBM.
"Failing to plan is a plan to fail when it comes to responding to a cybersecurity incident," Ted Julian, vice president of product management and co-founder of IBM Resilient.
"These plans need to be stress tested regularly and need full support from the board to invest in the necessary people, processes and technologies to sustain such a program. When proper planning is paired with investments in automation, we see companies able to save millions of dollars during a breach."
In addition, IBM said that not properly preparing for an incident could also lead to a business falling foul of the GDPR guidelines. Nearly half of businesses questioned in the research said they were not fully compliant with the GDPR.
One of the biggest barriers to being fully compliant and having a watertight strategy is that businesses still don't have the staffing they need for cyber security to be as secure as it could be.
IBM has suggested that cyber security incident management automation will become a more popular topic in future. Although businesses are already using automation for identity management and authentication, incident response platforms and security information and event management (SIEM) tools are still gaining popularity.