Preparedness pays off

Commvault has released new critical insights from its 2024 Cyber Recovery Readiness Report. This global survey of 1,000 security and IT professionals across 11 countries, reveals interesting behaviour changes for organisations that have been breached versus those that have not.

  • Wednesday, 11th September 2024 Posted 3 months ago in by Phil Alsop

The Commvault survey, done in collaboration with GigaOm, shows that organisations that have endured cyber incidents in the past don’t want to get burned again. Consequently, they often reassess and invest in cyber resilience and recovery strategies in very meaningful ways. According to the survey:

Investments in cyber resilience increase: Organisations that have been breached spend nearly 30% more on cybersecurity measures than those that haven't.

More attention is given to understanding data risk profiles: Breached organisations are nearly 2.5 times more likely to prioritise understanding their data risk profiles, which highlight data types and relative levels of risk.

Cyber readiness testing is prioritised: Breached organisations conduct more testing to find gaps in their cyber preparedness plans. Twenty percent of organisations that haven’t been breached do not test their recovery plan at all, that number drops to just 2% for organisations that have been breached.

The impact of these added investments and focus on cyber resilience is significant. According to the survey, breached organisations that have invested in comprehensive cyber recovery plans recover 41% faster than their less-prepared counterparts. In terms of specific recovery times, breached organisations state that they are 32% more likely to recover within 48 hours compared to those that have not been breached – a much better outcome than the recovery times noted by other respondents, which could be three weeks or more. This reduced downtime can translate to significant savings, both in terms of direct financial losses and the preservation of customer trust and brand reputation.

"We’ve all heard the expression hindsight is 20/20, and that could not be more applicable when it comes to the findings of this survey," said Brian Brockway, Chief Technology Officer at Commvault. "Our survey shows that the most resilient organisations are those that continuously test and refine their recovery strategies, learning from each incident to strengthen their defences. It’s this proactive mindset, rather than reactive spending, that makes the difference."

Much like health insurance, where the cost of coverage often far outweighs the potential expenses of medical emergencies, cyber recovery readiness serves a similar purpose. The report underscores that the costs of being breached – ranging from operational disruption to regulatory fines – far exceed the expenses of proactive cyber resilience measures.

"The findings should be a call to action for all organisations, not just those that have been breached," said Chris Ray, Cybersecurity Analyst at GigaOm. "Cyber threats are constantly evolving, and so too must the strategies to counter them. It’s about adopting a holistic approach to cyber resilience that integrates people, processes, and technology, ensuring readiness at every level."

In addition to these findings, Commvault and GigaOm were able to pinpoint five key capabilities, also called resiliency markers, that when deployed together, helped companies recover faster from cyberattacks and experience fewer breaches compared to companies that did not follow the same path. These five resiliency markers emerged after data analysis teams combed through the same survey results across a range of topics including: how often companies were breached, what resilience technologies were (or were not) deployed, and how rapidly businesses were able to recover data and resume normal operations. 

Beacon, NY, Dec 20, 2024– DocuWare unveils its AI-powered Intelligent Document Processing (DocuWare IDP), bringing about unprecedented improvements...
85% of IT decision makers surveyed reported progress in their companies’ 2024 AI strategy, with 47% saying they have already achieved positive ROI.

MSPs will invest in more AI security forecasting

Posted 1 week ago by Phil Alsop
Predictive maintenance and forecasting for security and failures will be a growing area for MSPs with an interest in security, says Nicole Reineke,...

Machine identities next big target for cyberattacks

Posted 1 week ago by Phil Alsop
Venafi has published the findings of its latest research report: The Impact of Machine Identities on the State of Cloud Native Security in 2024....
Nearly 50% of organisations have experienced a security breach in the last two years.

IT professionals recognise lack of gender diversity

Posted 1 week ago by Phil Alsop
The majority (87 percent) of IT professionals agree that there is a lack of gender diversity in the sector, yet less than half (41 percent) of...

A moving landscape for MSPs

Posted 2 weeks ago by Phil Alsop
2025 predictions from Ranjan Singh, chief product officer at Kaseya.

Data breach epidemic takes its toll

Posted 2 weeks ago by Phil Alsop
New study by Splunk shows that a significant number of UK CISOs are stressed, tired, and aren’t getting adequate time to relax.