Cybersecurity Assessment

Cybersecurity assessment low among APAC organisations

Share

Singapore – Mumbai, India: Cybersecurity assessment plays a crucial role in organisations today in ensuring security, addressing vulnerabilities, mitigating risks in IT environment and overall strengthening their security posture.

Despite knowing and understanding the consequences of cyberattacks and security threats, are organisations actually performing cybersecurity assessment? Probably, the answer lies in the increasing number of cyberattacks every year on organisations across the world and their overall security posture.

Performing cybersecurity assessement

According to a new study findings, only a quarter of organisations in APAC perform regular cybersecurity assessments. Certainly, it’s a very count because today a growing number of organisations across industries and segments in APAC are actively adopting new technologies and investing massively in transforming their businesses digitally.

Perhaps this digital transformation trend among APAC organisations don’t actually align with the survey findings on cybersecurity assessment. It revealed that a significant number of organisations are not even engaging in regular penetration testing or vulnerability assessments.

In APAC, only 26.7% of respondents perform these critical evaluations on a monthly basis, while the majority (42.7%), conduct assessments every few months, found the study titled, Securing OT with Purpose-built Solutions conducted by Kaspersky in collaboration with VDC Research.

The study findings are based on the survey of more than 250 decision-makers from key industries such as energy, utilities, manufacturing and transportation. The research aimed to unveil vital trends and challenges faced in fortifying industrial environments against cyber threats.

Fequency of cybersecurity assessment

Shockingly, 20% of APAC organisations perform cybersecurity assessment only once or twice a year, and 10.7% organisations address vulnerabilities solely as when required, as per the study findings.

The frequency of cybersecurity assessment conducted by APAC organisations is also approximately 6% lower than the global average. However, the frequency varies across industries and segments, while industries are highly regulated compared to others.

This inconsistent approach can leave organisations vulnerable as they navigate an increasingly complex threat landscape. However, with IT becoming the enabler for businesses and software applications powering them – any vulnerabilities will lead to dire consequences.

Vulnerabilities

Vulnerabilities in software via bugs, insecure codes and malware attacks could not only exploit and compromise IT systems but even can shutdown business operations. Eventually causing huge financial losses and tarnishing the organisational reputation in the market.

On the software vulnerability front, it Is necessary for organisations to carry out regular software updates and patch management to mitigate risks. However, the findings revealed that many industrial organisations encounter significant challenges in this area, often struggling to allocate the necessary time to pause operations for critical updates.

Many organisations in APAC patch their OT (operational technology) systems only every few months or even longer, significantly heightening their risk exposure. Specifically, 21.3% of organisation apply patches monthly, while 52% do so every few months, and 16% update only once or twice a year, the research stated.

In a hypercompetitive business environment, consistency and continuity are key cornerstones for organisational performance, according to Kaspersky’s APAC MD DAdrian Hia.

“The need for a robust security system then becomes crucial to guard against potential cyber breaches that could result in significant operational disruptions, such as unplanned downtime, equipment damages, and scrap and loss of work-in-progress inventory,” said Hia.

“There is a need for companies to bolster the resiliency of their cybersecurity systems – not only to protect their operations, but also to strengthen their competitive edge in a digitally driven economy,” concluded Hia.