Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - 77 Percent of Executives ‘Confident’ in Basic Security Controls
News & Analysis

77 Percent of Executives ‘Confident’ in Basic Security Controls

ISBuzz TeamBy ISBuzz TeamNovember 13, 2014Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
security controls
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Tripwire, Inc., a leading global provider of advanced threat, security and compliance solutions, has announced the results of an extensive survey conducted by Atomik Research on the state of foundational security controls. The survey respondents included 404 IT professionals and 302 executives from retail, energy, and financial services organizations in the United States and U.K.

Featured Download: Social media access at work. Do your employees know the rules?

Respondents were asked about the level of confidence they have in their application of foundational security controls, including hardware and software inventory, vulnerability management, patch management and system hardening. These controls are required by the most widely recognized global security standards and organizations, including:

·         The PCI Data Security Standard (PCI DSS)
·         North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP)
·         National Institute of Standards and Technology (NIST)
·         The Sarbanes-Oxley Act (SOX)
·         The Health Insurance Portability and Accountability Act (HIPAA)
·         Control Objectives for Information and Related Technology (COBIT)
·         International Organization for Standardization (ISO)

According to a report by the United States Computer Emergency Readiness Team (US-CERT), 96 percent of successful data breaches could be avoided if simple or intermediate security controls were put in place. Tripwire’s survey found that 77 percent of all respondents felt “confident” in their implementation of these basic security controls. However, despite the ongoing increase in targeted cyberattacks, 27 percent of IT professionals remain “not confident” in the secure configuration of common devices connected to their network.

Key survey findings included:

– Over 100 million records have been comprised in retail data breaches in the last 12 months as a result of malware on point-of-sale devices, but 77 percent of retail IT professionals are “confident” that all of the devices on their network are running only authorized software.
– Despite an ICS-CERT warning regarding an ongoing, sophisticated malware campaign targeting ICS systems, 89 percent of executives from the energy industry are “very confident” or “fairly confident” in their vulnerability management program.
– Only 10 percent of security professionals are “very confident” in their patch management program.
– Only 47 percent of IT professionals are “confident” in the secure configuration of routers, firewalls and modems connected to their network.

Comments:

“It’s not surprising that IT and security professionals have confidence in foundational security controls. The Controls are instrumental in defending against common cyberattacks and lay the foundation for effective defense against more sophisticated intrusions. But to be effective, they must be implemented consistently across the entire enterprise.”

Jane Holl Lute, president and CEO of the Council on CyberSecurity

“With the list of high-profile security breaches across all sectors of industry continuing to grow, 2014 is on target to be the worst year yet for data breaches. All indications show that the amount of data stolen is set to outstrip 2013, which itself was recognized across the security industry as being a very bad year. Against this backdrop of failure, it is inconceivable that over three quarters of IT professionals are confident that their existing security facilities will keep them safe. A fair proportion of these organizations already have suffered security problems this year, and given that the average time taken to detect a security breach continues to be measured in months, there is a good chance they just haven’t as yet identified the problem.”

Andrew Kellett, Principal Analyst, Security and Infrastructure Solutions, Ovum

“I don’t think it’s surprising that so many IT and security professionals are confident in their implementation of foundational security controls, even with the rapid increase in number of reported data breaches. The context that most IT teams operate within is that of general corporate objectives around regulatory compliance, making sure they are meeting industry standards, and trying to get stuff done while competing for organizational resources.”

Chris Conacher, Manager of Engineering, Tripwire

“This survey clearly shows the disconnect between the executive branch and the IT branch and the false sense of security within a typical organzation. This, in my opinion, false level of confidence may stem from several factors, including the false belief that if no breach has been discovered, ‘we must be secure.’”

Amar Singh, Chair ISACA UK SAG, Founder of the Cyber Management Alliance and Give01Day.com 

A report detailing the survey’s results can be read in full here.

About Tripwire

tripwireTripwire delivers advanced threat, security and compliance solutions used by over 9,000 organizations, including over 50% of the Fortune 500. Tripwire enables enterprises, service providers and government agencies around the world to detect, prevent and respond to cybersecurity threats.

Tripwire discovers every asset on an organization’s network and delivers high-fidelity visibility and deep intelligence about these endpoints. When combined with business-context, this valuable information enables immediate detection of breach activity and identifies other changes that can impact security risk.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}