【RADICL】2024网络安全成熟度报告_44页_569kb
报告摘要
DIB Cybersecurity Maturity Report Summary (2024 Edition)
Core Content
This report provides an in-depth analysis of the current state of cybersecurity among small and medium-sized businesses (SMBs) within the U.S. Defense Industrial Base (DIB) and Critical Infrastructure (CI) sectors. It highlights the challenges SMBs face in securing their data, the role of outsourced service providers, and the progress toward achieving CMMC compliance.
Key Findings
Cybersecurity Priorities and Capabilities
- 61% of SMBs consider cybersecurity a very high or high priority.
- 75% have three or more people dedicating time to security.
- 67% rate their security skill level as very high or high.
- 44% meet monthly to discuss cybersecurity with leadership.
Detection and Response Times
- 59% would take a week or more to detect a threat in their environment.
- 64% would take two days or longer to respond to ransomware or a breach.
- 39% would not be surprised to experience a ransomware attack.
- 59% had four or more endpoints compromised in the past year.
- 60% had four or more user accounts or emails compromised in the past year.
Financial Impact
- 46% say cybersecurity-related incidents have cost their company $100,001 or more.
- 12% report costs exceeding $500,001.
Top Challenges
- Implementing and maintaining compliance with regulations, including CMMC (58%).
- Protecting sensitive data from breaches and leaks (31%).
- Managing a limited budget and resources for comprehensive cybersecurity (31%).
- Keeping up with evolving cyber threat landscapes (25%).
- Educating and training employees on security best practices (24%).
- Managing third-party/vendor security risks (24%).
Security Function Management
- Top 3 areas managed in-house: Log Analysis (39%), Vulnerability Management (29%), Incident Response (29%).
- Top 3 areas managed by outsourced providers: Threat Monitoring (39%), Security Awareness Training (39%), Threat Investigation (36%).
- Top 3 areas managed by a combination: Threat Hunting (33%), Vulnerability Management (32%), Threat Monitoring (29%).
Security Program Effectiveness
- High effectiveness: Threat Hunting (37%), Incident Response (35%), Vulnerability Management (33%), Threat Monitoring (33%).
- Medium effectiveness: Threat Investigation (41%), Security Awareness Training (40%), Log Analysis (36%).
- Low effectiveness: Log Analysis (26%), Vulnerability Management (25%), Threat Monitoring (23%).
Outsourced Security Providers
- 71% use Managed Security Service Providers (MSSPs).
- 60% use Managed Detection and Response (MDR).
- 55% use Managed Service Providers (MSPs).
- 53% use Value-Added Resellers (VARs).
- 44% use cybersecurity consultants.
- 28% use compliance consultants.
Annual Outsourced Security Spending
- 77% spend $50,001 or more annually on outsourced security.
- 34% spend $50,001 to $100,000.
- 34% spend $100,001 to $250,000.
- 13% spend $20,001 to $50,000.
- 7% spend less than $20,000.
- 3% do not spend on outsourced security.
Reasons for Outsourcing
- Cost-effectiveness (51%).
- Scalability and flexibility (45%).
- Access to specialized expertise and technical skills (44%).
- Improved security posture with advanced tools and technologies (42%).
- Ability to focus internal resources on core business functions (34%).
- Support in complying with industry regulations and standards (31%).
- Enhanced incident response capabilities with round-the-clock monitoring (9%).
Summary
SMBs in the DIB and U.S. Critical Infrastructure sectors are increasingly aware of the importance of cybersecurity, with 61% considering it a very high or high priority. Despite this, many face significant challenges in detecting and responding to threats, with 59% taking a week or more to detect a threat and 64% requiring two days or longer to respond to a ransomware attack or data breach. The financial impact is also notable, with 46% reporting costs of $100,001 or more due to cybersecurity incidents.
The primary challenges include compliance with regulations (especially CMMC), protecting sensitive data, and limited budget and resources. SMBs are also struggling with outsourced service providers, citing issues like inadequate response time, limited support for compliance, and perceived high costs.
While many SMBs are using outsourced partners such as MSSPs, MDRs, and MSPs, there is no strong correlation between the amount of investment in cybersecurity and the effectiveness of their security programs. Instead, the quality of tools and expertise is emphasized as the key to better security outcomes.
SMBs are actively working toward CMMC compliance, with 81% having started the process, but only 13% are compliant with Level 1 and 11% with Level 2.
Overall, the report underscores the need for SMBs to invest in comprehensive cybersecurity solutions, specialized expertise, and effective partnerships to enhance their security posture and reduce vulnerabilities.
试读结束,高清完整版pdf/doc/ppt,请点下载