Hornetsecurity unveils: 25% of organizations not ready for cyber-attacks

June 4, 2024
1 min read

TLDR:

  • 26% of organizations do not provide IT security training to end-users.
  • 39% of organizations reported that their training does not adequately cover recent or AI-powered cyber threats.

In a new survey conducted by cybersecurity provider Hornetsecurity, it was revealed that a significant gap exists in IT security training, with a quarter of organizations failing to provide any form of training to their end-users. This lack of training is concerning, especially as one in four respondents had experienced a cybersecurity breach within the last year. The survey also highlighted that many training initiatives are seen as ineffective, with nearly four in ten organizations reporting that their training does not cover the latest cyber threats adequately.

The survey emphasized the importance of engaging and effective training for employees, as they are the frontline of every company’s cybersecurity strategy. Despite the perception that training is moderately effective in combating cyber threats, there is a clear disconnect between the perceived effectiveness of training and its actual relevance to modern cyber threats, especially AI-driven attacks.

Post-incident adaptations and reporting gaps were also identified in the survey, with many organizations implementing additional controls post-incident, but facing challenges in getting end-users to report identified threats. The need for updated training content that addresses the latest and most sophisticated cyber threats was reiterated by decision-makers in IT.

The survey highlighted the growing reliance on cyber insurance as a financial safeguard against cyber incidents, with over half of organizations now using it. However, organizations also recognize the importance of IT security training in preventing cybersecurity incidents and enabling end-users to spot security threats across various media sources.

In conclusion, the survey underscores the critical need for organizations to provide regular, engaging, and adaptive training that addresses the latest cyber threats to ensure a strong security culture and proactive defense against cyber-attacks.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and