A string of new reports has raised the level of concerns about cyber preparedness. A recent Ponemon Institute survey of IT and security professionals said 75 percent of U.S. organizations are not prepared to respond to cyberattacks. One has to wonder why this is the case given all the press about cyberattacks, breaches and legal actions that result from these incidents.
Perhaps the answer rests in another recent study: KPMG found 87 percent of CEOs in the U.S. said their operations were ready to address major cyber incidents. Now that is a major disconnect, but why? Most seem to side with the Ponemon report, citing a Symantec figure that said 317 million new strains of malware were released last year. That’s 10 new strains of malware per second (on average). Can any organization be prepared for that?
Given the ever-increasing frequency, severity and costs of cyberattacks, this must not be tolerated. What is the real state of cyber preparedness? Our government is taking some action. Officials are currently discussing and considering sanctions against China for stealing U.S. trade secrets. Sanction discussions are likely to include freezing accounts and blocking other transactions but will they take place when Chinese President Xi Jinping comes to the United States to meet with President Obama. There are those that believe these discussions will be elevated and replaced with talks about the growing concerns over cyber warfare and cyber arms control.
That addresses only part of this growing issue. An increasing number of individuals believe mandatory preparedness regulations are necessary given what appears to be a sad state of preparedness — or at very least a huge perception gap between executives and cybersecurity professionals on whether organizations are ready. It must be a sad state of affairs when government regulation seems to be the answer to this issue. But if this risk is not properly addressed now, regulations are almost assuredly what we will get.
RELATED: Learn more about securing defense and federal networks at C4ISR & Networks and Federal Times’ CyberCon 2015, held Nov. 18 at the Ritz Carlton in Pentagon City, Virginia.




