深度-THALES-2021年数据威胁报告(英文)-2021.6-28页_4mb
报告摘要
2021 Data Threat Report Summary
Core Content Overview
The 2021 Thales Data Threat Report provides an in-depth analysis of data security challenges in the context of accelerated cloud transformation and the shift to remote work due to the COVID-19 pandemic. It is based on a survey of over 2,600 security professionals and executive leaders across 10 countries. The report highlights the evolving threat landscape, the inadequacy of current security infrastructure, and the need for improved data protection strategies.
Key Findings
- Only 20% of respondents indicated their security infrastructure was very prepared for pandemic-induced disruptions.
- 82% of respondents expressed concern about the security risks of a remote workforce, with 44% lacking confidence in their access security systems.
- 56% of organizations globally reported experiencing a data breach, and 41% in the last 12 months.
- Malware is the most reported source of increased cyberattack activity (54%), followed by ransomware (48%) and phishing/whaling (41%).
- 47% of respondents are concerned about the long-term security risks posed by quantum computing.
- Zero Trust strategies are gaining momentum, with 30% of respondents having a formal strategy.
- Encryption is widely used for data protection, but only 17% of sensitive data in the cloud is encrypted.
- Multicloud strategies are common, with 53% using AWS and 41% using Microsoft Azure for IaaS.
- 46% of respondents use multi-factor authentication (MFA), but adoption is still low in the US federal sector.
- Data discovery remains a challenge, with 24% of respondents having full knowledge of where their data is stored.
Main Points
1. Impact of the Pandemic on Data Security
- The shift to remote work and cloud adoption has significantly disrupted traditional security models.
- 82% of respondents expressed concern about remote work security risks.
- 44% of respondents lack confidence in their access security systems to support remote work.
- 60% of respondents still use VPN as the primary remote access method, despite its limitations in securing diverse work patterns.
2. Cloud Security Challenges
- 31% of respondents have 41-50% of their data in external clouds, and 24% have more than 50%.
- Only 17% of sensitive data in the cloud is encrypted, despite the widespread use of encryption as a security measure.
- 45% of respondents have centrally defined cloud security policies, but technical standards and enforcement are often left to individual cloud teams.
- Multicloud environments increase complexity in managing encryption and keys, as each provider has its own consoles and APIs.
3. Data Protection Technologies
- Encryption and tokenization are the top choices for data protection, with 38% and 35% of respondents respectively.
- 46% of respondents avoided breach notifications due to encrypted or tokenized data.
- 57% of respondents use key management, but this is not always aligned with encryption deployment.
4. Security Strategies and Priorities
- Zero Trust is becoming a mainstream strategy, with 30% of respondents having a formal plan.
- Data loss prevention (DLP) is the top spending priority (39%), followed by encryption/key management (36%) and DevSecOps tools (35%).
- 45% of respondents believe that cloud environments are more complex to manage than on-premises networks.
5. Security Threat Perceptions
- Third-party vendor networks are the most frequently identified as the top target for cyberattacks (38%).
- Web applications and cloud-based storage follow closely at 37%.
- Cloud databases and cloud-hosted applications are also high-risk targets.
- End-user devices and IoT devices are perceived as lower risk, though recent vulnerabilities in IoT suggest otherwise.
6. Quantum Computing and Future Threats
- 47% of global respondents are very concerned about quantum computing's potential to break current encryption.
- Australian respondents show the highest concern (58%), followed by Hong Kong (55%), South Korea (53%), Singapore (52%), New Zealand (49%), and UAE (51%).
- US federal government respondents are also highly concerned (48%), indicating a growing awareness of quantum threats.
- Organizations should consider post-quantum cryptographic techniques and crypto agility to prepare for future risks.
7. Security Posture and Awareness
- Despite awareness of risks, many organizations have not implemented sufficient security measures.
- 47% of respondents believe that security threats have increased in volume, severity, and scope.
- Senior management is less aware of the threat landscape than practitioners and managers, with only 40% of senior management reporting an increase in cyberattacks.
Critical Insights
- The lack of MFA adoption in the US federal sector is a significant concern.
- Data discovery and visibility are critical challenges in cloud environments.
- Encryption is not being implemented comprehensively, and key management is often overlooked.
- The rise of multicloud strategies increases the complexity of managing data security.
- Zero Trust adoption is growing but still limited, and organizations need to align it with broader security practices.
- Quantum computing poses a long-term risk that is increasingly being recognized by security professionals.
Conclusion
The 2021 Data Threat Report underscores the urgent need for organizations to modernize their security infrastructure, adopt more robust data protection measures, and align their security strategies with the evolving threat landscape. With the continued rise of remote work and cloud adoption, there is a clear call for better encryption, key management, and Zero Trust implementation to secure data effectively in the future.
试读结束,高清完整版pdf/doc/ppt,请点下载