Visibility is key, and lacking

1 May 2019 Editor's Choice, Information Security

Sophos recently announced the findings of its global survey, 7 Uncomfortable Truths of Endpoint Security (http://www.sophos.com/truths), which reveals that IT managers are more likely to catch cybercriminals in their organisation’s servers and networks than anywhere else.

In fact, IT managers discovered 37% of their most significant cyberattacks on their organisation’s servers and 37% on its networks. Only 17% were discovered on endpoints and 10% were found on mobile devices.

For South African IT managers, 42% of the most significant cyberattacks were discovered on their organisation’s servers, 33% on their networks, 20% on their endpoints and 5% on mobiles.

The survey polled more than 3100 IT decision makers from mid-sized businesses in 12 countries including the US, Canada, Mexico, Colombia, Brazil, UK, France, Germany, Australia, Japan, India, and 200 from South Africa. The 7 Uncomfortable Truths of Endpoint Security survey was conducted by Vanson Bourne, an independent specialist in market research, in December 2018 and January 2019. All respondents were from organisations with between 100 and 5000 employees.

“Servers store financial, employee, proprietary, and other sensitive data, and with stricter laws like GDPR or PoPI that require organisations to report data breaches, server security stakes are at an all-time high. It makes sense that IT managers are focused on protecting business-critical servers and stopping attackers from getting on the network in the first place and this leads to more cybercriminal detections in these two areas,” said Chester Wisniewski, principal research scientist, Sophos. “However, IT managers can’t ignore endpoints because most cyberattacks start there, yet a higher than expected amount of IT managers still can’t identify how threats are getting into the system and when.”

26% of South African IT managers who were victim to one or more cyberattacks last year can’t pinpoint how the attackers gained entry, and 18% don’t know how long the threat was in the environment before it was detected, according to the survey. To improve this lack of visibility, IT managers need endpoint detection and response (EDR) technology that exposes threat starting points and the digital footprints of attackers moving laterally through a network.

“If IT managers don’t know the origin or movement of an attack, then they can’t minimise risk and interrupt the attack chain to prevent further infiltration,” said Wisniewski. “EDR helps IT managers identify risk and put a process in place for organisations at both ends of the security maturity model. If IT is more focused on detection, EDR can more quickly find, block and remediate; if IT is still building up a security foundation, EDR is an integral piece that provides much needed threat intelligence.”

The global average time spent investigating potential security issues is about four days a month, or 48 days a year. However, the report states only 15% turn out to be actual infections. “As a result, organisations are spending 85% of the time investigating non-issues, equivalent to around 41 days each year. This has significant financial and productivity implications:

• Direct cost – the financial and resourcing impact of spending such significant amounts of time investigating non-issues

• Opportunity cost – the IT activities that staff are not getting to because they are investigating non-issues.”

On average, South African organisations that investigate one or more potential security incidents each month spend 36 days a year (three days a month) investigating them, according to the survey. It comes as no surprise that regional IT managers ranked identification of suspicious events (31%), alert management (22%) and ability to search on file attributes (12%) as the top three features they need from EDR solutions to reduce the time taken to identify and respond to security alerts.

“Most spray and pray cyberattacks can be stopped within seconds at the endpoints without causing alarm. Persistent attackers, including those executing targeted ransomware like SamSam, take the time they need to breach a system by finding poorly chosen, guessable passwords on remotely accessible systems (RDP, VNC, VPN, etc.), establish a foothold and quietly move around until the damage is done,” said Wisniewski. “If IT managers have defence-in-depth with EDR, they can also investigate an incident more quickly and use the resulting threat intelligence to help find the same infection across an estate. Once cybercriminals know certain types of attacks work, they typically replicate them within organisations. Uncovering and blocking attack patterns would help reduce the number of days IT managers spend investigating potential incidents.”

56% of respondents from South Africa said they were planning to implement an EDR solution within the next 12 months. Having EDR also helps address a skills gap. 75% of IT managers wish they had a stronger team in place.

The full report is available at www.securitysa.com/*sophos1, redirects to https://www.sophos.com/en-us/medialibrary/gated-assets/white-papers/sophos-seven-uncomfortable-truths-about-endpoint-security-wpna.pdf





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.