Two thirds of respondents to a global survey by the Business Continuity Institute reported that they had experienced at least one cyber incident during the previous twelve months, and 15% reported they had experienced at least ten incidents during the same period.
Faster response times are needed
The report found that there was a wide range of response times for cyber incidents. Almost a third of organizations (31%) stated that they responded within one hour. However, one fifth (19%) take a worrying four hours or more in responding to a cyber event, and almost half (44%) take more than two hours to respond. This has clear implications for the time taken to return to business as usual, and the ultimate cost of the incident to the organization.
Even if organizations wish to respond immediately to a cyber attack, the nature of the attack may render them unable to do so. The research found that phishing and social engineering was the top cause of cyber disruption, with over 60% of companies reporting being hit by such an incident over the past 12 months, and 37% hit by spear phishing.
It also found that 45% of companies were hit by a malware attack and 24% by denial of service. All these forms of attack will, in different ways, render an organization’s own network either contaminated or inoperable. Their website may have been taken down and they may well have to switch off their internet connection until they can secure themselves from further attack.
Incidents cost more each year
The research, a study of 369 business continuity and resilience professionals from across the world, also revealed that the costs of these incidents varied greatly, with 73% reporting total costs over the year of less than €50,000, but 6% reporting annual costs of more than €500,000.
“Cyber attacks tend to target the weakest links of an organisation, and this calls for a greater awareness of cybercrime. As the cyber threat evolves, it is crucial to stay on top of it, building long-term initiatives and regularly updating recovery plans,” said David James-Brown FBCI, Chairman of the BCI.
Rickie Sehgal, Chairman of Crises Control, said: “Rapid communication with employees, customers and suppliers is vital for any company in terms of responding effectively to a major business disruption event such as a cyber attack. When your business is at risk, even a one hour delay in responding to an incident can be too long. Taking more than two hours to respond, as almost half of companies do, is just unacceptable.”