Many organisations have turned to strengthening conventional network security “point solution” approaches to protect against threats. In 2012, organisations allocated about 24 percent of their overall IT security budget toward network security, and 42 percent of firms indicated that they expected to increase budget for network security for 2013. The majority of this network security investment is allocated to wireless security and intrusion prevention systems (IPS). In fact, 27 percent of organisations are planning to invest in the notoriously difficult-to-implement network access control in the coming year. However, investment strategies that put significant focus on these types of conventional technologies will do little to prevent or minimise the impact of targeted attacks.
“If organisations want to protect intellectual property and shareholder value, they must adopt advanced threat detection and response solutions that identify malicious activity quickly and enable earlier mitigation of targeted attacks,” said Sharda Tickoo, PMM, Trend Micro India.
The lack of focus on security technologies that truly combat targeted attacks is matched by the false sense of security organisations have in their ability to deal with these attacks. A large majority (77 percent) of IT security decision makers are confident in their organisation’s ability to thwart targeted threats today. In fact, these decision-makers claim to be almost as adept at defending against targeted attacks as they are at detecting commodity attacks. Additional Forrester survey data reveals that in the past year, 55 percent of organisations surveyed claim to have had no compromises or breaches. In reality, many of these organisations have been compromised but simply don’t have the technology available to detect the malicious activity. As a result, enterprises overestimate their abilities.
Targeted Attacks Require Advanced Threat Detection And Response
For this Technology Adoption Profile, Trend Micro commissioned Forrester Consulting to create a custom survey that explored key needs for network security and security operations in enterprises in the current market. Confidence — rightly or wrongly placed — in current security capabilities isn’t enough for targeted threats, and mature security organisations will recognise this fact. Targeted threat detection and response isn’t a single point solution product or technology but rather a combination of technologies and competencies that integrate into a company’s security strategy.