Independent Study Reveals Incident Response Perception Gap Among EU Companies

By   ISBuzz Team
Writer , Information Security Buzz | Jun 04, 2015 09:00 pm PST

86 percent of businesses feel they’re prepared for a breach – yet nearly 40 percent have no response plan

A new study by Pierre Audoin Consultants (PAC) uncovers a notable gap in Incident Response(IR) preparedness among EU companies. The majority of respondents – 86 percent – feel they’re prepared to face a cyber attack, yet nearly 40 percent have no IR plan in place. Additionally, only 30 percent of those with IR plans test and update them regularly (more than once a month).

The study was co-sponsored by Resilient Systems, the leading Incident Response Platform (IRP) provider for security professionals, along with FireEye, HP and Telefonica. The study questioned 200 respondents at CISOs/CIO/VP IT level from companies with more than 1000 employees in the UK, France and Germany.

“As the cyber threat landscape becomes more challenging, businesses need enhanced response plans to ensure they’re able to survive and thrive in the face of these threats,” said Bruce Schneier, Chief Technology Officer at Resilient Systems. “For decades, companies have focused on preventing and detecting attacks, but they haven’t focused enough on Incident Response. This is critical to good security.”

The survey also identified an increase of cybersecurity spending for Incident Response. According to the survey, businesses spend 77 percent of their security budgets on prevention and detection technology. However, spend is moving towards Incident Response capabilities – growing from 23 percent today to 39 percent in two years.

“Organisations are realising that cyber breaches are inevitable – but focusing on improving response can ensure breaches are survivable,” said Duncan Brown, Research Director at PAC and lead author of the study. “We’re encouraged to see that organisations are investing more in the tools, processes, and people needed for effective and fast Incident Response.”

Additional key findings include:

  • 67 percent experienced a breach in the last year. 100 percent have experienced a breach at some point in the past
  • 22 percent of organisations have no technology in place to assist with incident response
  • Organisations require between one and six months to recover from a breach
  • The average direct costs of a data breach (not including internal staffing and loss of business and reputation) is €75000
  • 77 percent are either ‘very’ or ‘somewhat’ concerned at the prospect of mandatory breach notification

About Resilient Systems

Resilient SystemsResilient Systems (formerly Co3 Systems) is the leading Incident Response Platform (IRP) provider, empowering organisations to thrive in the face of cyberattacks and business crises. Our collaborative platform arms Incident Response teams with workflows, intelligence, and deep-data analytics to react faster, coordinate better, and respond smarter. Headquartered in Massachusetts, USA, Resilient Systems’ customers are some of the world’s most trusted organisations. Visit us at

About Pierre Audoin Consultants (PAC)

Pierre Audoin Consultants (PAC)From strategy to execution, PAC delivers focused and objective responses to the growth challenges of Information and Communication Technology (ICT) players.

PAC helps ICT vendors to optimize their strategies by providing quantitative and qualitative market analysis as well as operational and strategic consulting. We advise CIOs and financial investors in evaluating ICT vendors and solutions and support their investment decisions. Public institutions and organizations also rely on our key analyses to develop and shape their ICT policies.

Founded in 1976 and headquartered in Paris, PAC is part of the CXP Group, the leading European research and advisory firm in the field of software & IT services.  For more information, please visit  PAC’s top analyst views : Visit HERE

Notify of
0 Expert Comments
Inline Feedbacks
View all comments

Recent Posts

Would love your thoughts, please comment.x