Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Over Half Of UK Businesses Create IT Security Blind Spots Due To Incorrect Metrics
News & Analysis

Over Half Of UK Businesses Create IT Security Blind Spots Due To Incorrect Metrics

ISBuzz TeamBy ISBuzz TeamApril 9, 20145 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Blind_Spot
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to research[1] revealed by Tenable Network Security, Inc., the leader in real-time vulnerability and threat management, 54 percent of companies in the UK are using incorrect metrics when trying to determine their IT security status, providing a false picture of the organisation’s vulnerabilities and risk, driving the wrong behavior.

The results, collected through a survey of IT decision makers at companies with more than 500 employees by market research firm Vanson Bourne on behalf of Tenable Network Security, also indicate that there is a communication gap between the IT department and the boardroom—despite the fact that frequency of reporting between the two is increasing. In addition, the survey uncovers a potential to increase efficiency in IT security actions by reducing the current extensive reporting times.

Measurement: big security, little meaning

Top on the list of tracked key performance indicators (KPIs) in the UK with 57 percent is “quantity of security breaches detected.” This KPI is a strong trailing indicator of detective and preventative controls, but does not necessarily enable proactive prevention of further incidents. However, KPIs that do demonstrate proactive prevention are only tracked by a minority of companies, with 41 percent listing “checking if their systems have the latest version of patches or antivirus patterns” and 30 percent “monitoring if they are equipped with the latest software versions”–these are both indicators that are critical for determining IT security status. .

Because of zero-day exploits, minimising the time to roll out new patches or antivirus patterns is critical–yet the former KPI is only being measured by 32 percent and the latter by 19 percent. Encouragingly, 48 percent of respondents in the UK say that they want to be able to track more KPIs, but claim that lack of manpower and an automated approach is holding them back.

“Transparency around security is key for IT managers who are constantly playing catch-up to the ever-evolving threat landscape,” said Gavin Millard, Technical Director for Tenable Network Security in Europe, Middle East and Africa.  “Despite this, 54 percent of IT decision makers are tracking the number of malware detected–which is often viewed as a false flag metric. Measuring the amount of malware detected gives little insight into the efficiency and effectiveness of the control; it merely indicates that it is functioning on some of the systems, some of the time. Strategic decisions based on the wrong data are not only ineffective but can also give a false sense of security.”

Bridging the gap to the boardroom

Over half (52 percent) of IT managers report the company’s security status to their board once per quarter or more frequently. Forty-nine percent confirm that IT security is a high priority for their CEO, with 7 percent saying it is a top priority. Further, 50 percent of IT respondents share half or more of all KPIs tracked with their board, with 26 percent sharing all of them.

“It is not surprising to see security becoming a top priority for CEOs due to the increasing awareness of the cost to businesses of data breaches and compliance issues,” Millard continued. “Therefore, it is encouraging to see how frequently IT is reporting to the boardroom, as some years ago this would have been once a year maximum. However, IT still has a long way to go to secure understanding and buy-in from the board, primarily through better means of communication. The findings showed that although a huge amount of information is being shared there is a danger of drowning management in irrelevant data – this is again reflected in the results which found that only 17 percent reported the data as “highly valuable” by their board. When delivering metrics, they have to be succinct, based on irrefutable fact and demonstrate value to the business.”

Freeing up time for vital tasks

Creating transparency in IT security is a huge task – 39 percent of UK companies have IT security solutions from three or more vendors in place and 53 percent compile all their reports manually, of which 54 percent need to report every quarter or more. In line with these findings 40 percent confirmed that it takes up to two or three days to compile a management-ready report. In view of this, 54 percent consider more resources for monitoring solutions to add additional value to protect their organisation from threats.

“Looking at these results specifically, it becomes painfully clear that IT staff are spending a large portion of their time on reporting,” explained Millard. “This is time that is being taken away from more strategic tasks designed to improve overall IT security of the business. The drain to resources is then compounded by the increasing workload driven by the rise of mobile and cloud—34 percent of survey respondents confirmed they had to add 20 percent or more devices or services to their monitoring efforts within the last twelve months.”

“As long as security blind spots within an organisation exist, businesses will not be able to rest easy from the threat of attack. Gaining clarity on the effectiveness of the investments currently made within security and making risk-based, data-driven decisions on what other controls are necessary put businesses on a more secure footing.”

[1] The survey was conducted by Vanson Bourne on behalf of Tenable and interviewed 200 IT decision makers in the UK working in companies with more than 500 employees across March 2014.

About Tenable

Tenable Network Security is relied upon by more than 20,000 organisations, including the entire U.S. Department of Defence and many of the world’s largest companies and governments, to stay ahead of emerging vulnerabilities, threats and compliance-related risks. Its solutions continue to set the standard to identify vulnerabilities, prevent attacks and comply with a multitude of regulatory requirements. For more information, please visit www.tenable.com.


[1] The survey was conducted by Vanson Bourne on behalf of Tenable and interviewed 200 IT decision makers in the UK working in companies with more than 500 employees across March 2014.

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 404

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}