sb-au logo
Story image

CompTIA security study finds A/NZ firms should invest more in employee training

04 Mar 2019

IT professionals across Australia and New Zealand believe their organisation has ‘simply adequate’ security, according to a recent CompTIA survey.

Of the 35% of respondents who indicated their organisation had experienced a data breach in the last two years, 48% had suffered business disruption to customers, 45% suffered reputation damage, and 34% suffered negative financial impact.

The biggest cyber threat comes from employees and internally, according to 60% of respondents. Malicious attacks followed with 29%, and third-party partners came in at third with 8%.

IT professionals say that while their company’s security is satisfactory, many believe there is room for improvement.

“Employees may inadvertently jeopardise data, steal information for a competitor, or sell data or intelligence,” says CompTIA A/NZ Channel Community executive council member James Bergl. 

“This isn’t necessarily malicious behaviour on the part of these employees but simply an indication that they lack awareness. To counter this risk, organisations should control access to company data. This can significantly improve the chances of catching this behaviour before it causes devastating damage.” 

CompTIA recommends that employee training should happen often, should be short, and should be based on real-world scenarios.

“Effective cybersecurity training is best provided in small, digestible units followed up with thorough testing and reinforcement, and designed to support a culture of security by engaging employees at all levels.”

Bergl adds that Technology can help to mitigate the human risk element, but training and policy will also need to be updated to reduce security risk.

“Investing in cybersecurity professionals’ training reaps rewards for the organisation and is essential to stay abreast of current threats.” 

CompTIA cites statistics from Australia’s latest Notifiable Data Breaches Quarterly Statistics Report. It found that 57% of breaches were a result of malicious or criminal attacks.

“This shows that organisations must not focus all their attention on addressing human error at the expense of protecting themselves from external threats,” says Bergl.  “A comprehensive well-rounded security strategy will ensure the best outcome.” 

Story image
Security and operations collaboration key to success post COVID-19
“We are in an ultra-hybrid world with multi-everything, and in order to successfully navigate this landscape, ITOps, DevOps, and SecOps teams need to more closely align."More
Story image
Experiencing ransomware significantly impacts cybersecurity approach
"The survey findings illustrate clearly the impact of these near-impossible demands. Among other things, those hit by ransomware were found to have severely undermined confidence in their own cyber threat awareness."More
Story image
Why IT and HR must work together to help businesses weather the storm
Employers are striving to balance team productivity, security and employee engagement. If remote work is the new norm, it’s impossible to ignore the challenging nature of the situation, writes Gigamon manager for A/NZ George Tsoukas.More
Story image
IBM Security completes industry first with updates to Cloud Pak for Security solution
"With these updates, we will be the first in the industry to bring together external threat intelligence and threat management alongside data security and identity."More
Story image
Research: Younger cybersecurity pros more fearful of being replaced by AI
According to the findings, 53% of respondents under 45 years old either agreed or strongly agreed that AI and ML are a threat to their job security, despite 89% of this demographic believing that it would improve their jobs.More
Story image
UiPath and eSentire bring hyperautomation to Microsoft Security
UiPath and eSentire have announced a strategic partnership to deliver end-to-end security policy automation across multiple Microsoft Security services.More