Accenture Third Annual State of Cyber Resilience Report
Total Page:16
File Type:pdf, Size:1020Kb
THIRD ANNUAL STATE OF CYBER RESILIENCE INNOVATE FOR CYBER RESILIENCE LESSONS FROM LEADERS TO MASTER CYBERSECURITY EXECUTION CONTENTS ABOUT THE AUTHORS ...................................3 WHY LEADERS ARE MORE SUSTAIN WHAT THEY HAVE CYBER RESILIENT ........................................ 16 Maintain existing investments ................38 SECURE INNOVATION ....................................4 Stop more attacks ....................................18 Perform better at the basics ...................39 AT A GLANCE .................................................5 Find breaches faster ...............................20 Fix breaches faster .................................. 22 MASTERING CYBERSECURITY THE STATE OF CYBER RESILIENCE ................. 7 EXECUTION ................................................. 40 Reduce breach impact ............................ 24 WHERE ARE WE NOW? ABOUT THE RESEARCH ............................... 41 WHAT MAKES LEADERS SUCCESSFUL ........ 27 Investment in innovation grows ............... 8 Our methodology ...................................43 The basics seem better .............................9 INVEST FOR OPERATIONAL SPEED Demographics .........................................45 Progress masks hidden threats ............... 10 Prioritize moving fast .............................. 28 Reporting structure.................................46 Unsustainable cost increases ..................12 Choose turbo-charging technologies ....30 Budget authorization .............................. 47 Security investments are failing ..............14 DRIVE VALUE FROM NEW INVESTMENTS Scale more .............................................. 32 Train more ...............................................34 Collaborate more ....................................36 Copyright © 2020 Accenture. All rights reserved. 2 ABOUT THE AUTHORS KELLY BISSELL RYAN M. LASALLE PAOLO DAL CIN GLOBAL LEAD – MANAGING DIRECTOR – MANAGING DIRECTOR – ACCENTURE SECURITY ACCENTURE SECURITY ACCENTURE SECURITY [email protected] [email protected] [email protected] Kelly leads the Accenture Security business Ryan leads the North America practice for Paolo leads the Europe and Latin America globally. With more than 25 years of security Accenture Security. He is responsible for nurturing practice for Accenture Security. He has 20 years industry experience, Kelly specializes in breach the talented teams that bring transformative of experience leading complex projects for incident response, identity management, privacy solutions to better defend and protect our clients. Accenture clients. He is an expert in security and data protection, secure software development, Over the course of nearly two decades, He has strategy, business resilience, cyber defense and and cyber risk management. His role as the worked with Accenture clients in the commercial, offense, cloud protection, security analytics, threat Accenture Security lead spans strategic consulting, non-profit and public sectors helping them identify intelligence, application security, data protection proactive risk management and digital identity and implement emerging technology solutions and managed security services. He has authored to cyber defense, response and remediation to meet their business needs. Ryan is a Ponemon several articles on security and is a frequent services, and managed security services—across Institute Fellow and is active with the Greater speaker at security events. Paolo taught information all industries. Kelly is also affiliated to OASIS, a Washington Board of Trade. and communication technology (ICT) security at non-profit consortium that drives the development, the Universities of Udine, Modena and Milan. convergence, and adoption of open standards for Twitter: https://twitter.com/Labsguy the global information society. Twitter: https://twitter.com/Paolo_DalCin Twitter: https://twitter.com/ckellybissell Copyright © 2020 Accenture. All rights reserved. 3 SECURE INNOVATION At first glance, the basics of cybersecurity are distinct groups: the first an elite group—17 What is one key to secure innovation? Leaders improving and cyber resilience is on the rise. Our percent—that achieve significantly higher levels show us that they scale, train and collaborate latest research shows that most organizations are of performance compared to the rest. These more. So, while non-leaders measure their getting better at preventing direct cyberattacks. organizations set the bar for innovation and success by focusing on the destination— But in the shape-shifting world of cybersecurity, achieve high-performing cyber resilience. The improved cyber resilience—the leaders focus attackers have already moved on to indirect second is the group forming the vast majority of on how to get there using warp speed to detect, targets, such as vendors and other third parties our sample—74 percent—who are average mobilize and remediate. in the supply chain. It is a situation that creates performers, but far from being laggards in cyber new battlegrounds even before they have resilience. This second group has lessons to learn In the Accenture Third Annual State of Cyber mastered the fight in their own back yard. At the from our leaders while leaders, too, have further Resilience report we take a deep dive into what same time, cybersecurity cost increases are room for improvement. sets leaders apart. Based on our research among reaching unsustainable levels and, despite the 4,644 executives and backed by our knowledge hefty price tags, security investments often fail Being innovative in security is different to any and deep industry expertise, our findings aim to to deliver. As a result, many organizations face other aspect of the business. Caution is help organizations innovate securely and build a tipping point. necessary. After all, a fail fast approach is not an cyber resilience to help grow with confidence. option for security where attack vulnerabilities There is good news for organizations wondering could be catastrophic. Growing investments in In this cybersecurity report, we show how if they will ever move beyond simply gaining innovation illustrate organizations’ commitment organizations are coping with cybersecurity ground on the cyber attacker. Our analysis to prevention and damage limitation. And it is demands since our last analysis and explore reveals there is a group of standout organizations here that leaders excel. By focusing on the what our large sample of non-leaders can do that appear to have cracked the cybersecurity technologies that provide the greatest benefit to master cybersecurity execution and drive code for innovation. Detailed modeling of and sustaining what they have, they are finding innovation success. cybersecurity performance has identified two themselves moving fast and first in the race to cyber resilience. Copyright © 2020 Accenture. All rights reserved. 4 AT A GLANCE State of Cyber Resilience A group of leading organizations are doing things differently Innovation investment is growing 4x 4x 3x 2x better at stopping better at finding better at fixing better at reducing Cybersecurity attacks breaches faster breaches faster breach impact basics are better BUT... HOW DO THEY DO IT? There are hidden threats Invest for Drive value Sustain Costs are unsustainable operational from new what they speed investments have Investments are failing Copyright © 2020 Accenture. All rights reserved. 5 The cyber-resilient business brings What is together the capabilities of cybersecurity, business continuity and enterprise cyber resilience. It applies fluid security strategies to respond quickly to threats, resilience? so it can minimize the damage and continue to operate under attack. As a result, the cyber-resilient business can introduce innovative offerings and business models securely, strengthen customer trust, and grow with confidence. Copyright © 2020 Accenture. All rights reserved. 6 THE STATE OF CYBER RESILIENCE Investment The basics Progress Unsustainable Security in innovation seem better masks hidden cost increases investments grows (p.8) (p.9) threats (p.10) (p.12) are failing (p.14) The number of Direct attacks are Indirect attacks Sixty-nine percent Failures lead to leaders spending down 11 percent over against weak links in say staying ahead gaps in protection, more than 20 percent the last year and the supply chain now of attackers is a lower detection of IT budgets on security breaches are account for 40 percent constant battle rates, longer business advanced technology down by 27 percent. of security breaches. and the cost is impact and more investments has unsustainable. customer data loss. doubled in the last three years. Copyright © 2020 Accenture. All rights reserved. 7 WHERE ARE WE NOW? Investment in innovation grows Increasingly, the online world has grown complex The good news is that most organizations, on Figure 1. Percentage of leaders spending more and threatening. Many organizations are finding average, spend 10.9 percent of their IT budgets than 20 percent of their IT budgets on advanced it hard to reconcile the level of their on cybersecurity programs. Leaders spend technology investments cybersecurity innovation investments with the slightly more at 11.2 percent which is insufficient cyber resilience outcomes for their business. to account for their dramatically higher levels of Even worse, choosing the wrong strategy to performance. And their investments in advanced invest in cybersecurity technologies can cost the