Over a third of organisations are yet to develop a cyber-attack response plan

Lack of preparation by businesses alarming due to multi-faceted threat landscape.

  • Friday, 10th June 2016 Posted 8 years ago in by Phil Alsop
F5 Networks has published the findings of a survey into current concerns in the security community, conducted at the Infosecurity Europe 2016 show in London. 
 
The survey reveals that businesses are running the risk of being exposed by cyber-attacks, with over a third (36 %) of respondents claiming their organisation currently has no response plan in place. In an environment where cyber-attacks are increasingly common place, it is alarming more businesses are not prepared. As revealed by a recent Government report on Information Security Breaches, the average cost of a severe online security breaches for big business now starts at ?1.46 million – up from ?600,000 in 2014 – a cost which businesses can ill afford.
 
The F5 survey also highlights the broad nature of the threats security pros are facing. Asked what their top three security concerns were, network attacks (19%), malware (18%) and application data breaches (17%) were all highlighted, with DDoS attacks (16%), cloud-related data breaches (14%) and web fraud attacks (13%) closely behind.
 
DDoS remains prevalent 
DDoS attacks remain common, with 35% believing their business has either definitely or very likely suffered an attack.
 
When asked what their primary solution was for a DDoS attacks, respondents listed firewalls (33%), hybrid mitigation (17%) and Web Application Firewalls (WAF) (14%) as the top three.  According to the survey, WAF is an integral part of a company’s general security infrastructure - some 74% of businesses either use a WAF or plan to in the future.
 
In terms of types of DDoS attack, respondents listed ‘blended DDoS’ attacks (26%) as the biggest threat followed by ‘application level’ (25%) and ‘volumetric-based’ (19%). Extortion-driven attacks (15%) were scored bottom – surprising considering the increasing number of cyber-ransom style attacks reported in the media. 
 
On-premise v. cloud
The 2016 survey also revealed that hybrid DDoS mitigation (17%) was a more popular solution than an on-premise DDoS mitigation approach (15%). A question specifically about WAF found that 31 % opted for on-premise and 19% for cloud-based solutions.