Lack of resources thwarting cyber security threat hunting

clock • 2 min read

Security teams lack the resources and time to proactively search for threats

Almost three-quarters (74 per cent) of organisations fail to employ ‘threat hunters' due to a lack of resources.

That's according to a new report from Computing and Carbon Black that gauges the opportunities and obstacles facing a more proactive approach to cyber security, known as threat hunting.

In addition to those who steer clear due to time constraints, a further 23.4 per cent do not use threat hunters due to a lack of time, signalling the strain cyber security teams are under.

The finding echoes reports this week concerning the Government Cyber Governance Health Check 2018's revelation that only 16 per cent of the boards of UK's FTSE 350 companies have a sound understanding of the potential impact that a cyber-attack could have on their organisation.

Computing's research into threat hunting reinforces these findings, highlighting a lack of board-level buy-in when it comes to a proactively seeking out security weaknesses and breaches. As the report explains:

"It's true that threat hunting offers business benefits, such as increased control and the ability to counter ever-more complex cyber attacks. But leadership buy-in is key to investment in threat hunting. This is partly about positioning ROI in the right way. It's also about budgets.

"According to our survey, a third of boards demand provable ROI on security operations. It's certainly a challenge, and it makes proactive protection that much harder.

"However, the cost of security breaches is rising. On top of the damage to reputation and operational disruptions, the EU General Data Protection Regulation (GDPR) stipulates that fines of up to four per cent of turnover can be applied to those firms that suffer a breach. This can end up costing tens of millions of pounds."

Given this stark reality, boards should be aware of the fact that ROI is clearly evident when the alternative is toying with the risk of huge fines and incalculable reputational damage.

To learn more, read the full report: Outsmarting the Smart: Entering the Age of Threat Hunting.

You may also like
Windows 11 security ineffective against attacks on old device drivers, say researchers

Threats and Risks

34 vulnerable drivers could grant an attacker full control of a hardware device

clock 07 November 2023 • 2 min read
Accidental exclusion exacerbating cyber's staffing problem

Careers and Skills

Many people who would excel in cybersecurity roles see no obvious way in, with those that do make it getting stuck in entry-level positions

clock 12 May 2023 • 4 min read
Former Head of Police National Cyber Crime Unit joins Cybersecurity Festival

Leadership

Charlie McMurdie spent 32 years in the Met and built the Police Central e-crime Unit

clock 29 March 2023 • 2 min read

More on Security

You need to lock down cyber-physical systems: Here's how and why

You need to lock down cyber-physical systems: Here's how and why

Cybersecurity should focus on OT as well as IT

Samara Lynn
clock 27 March 2024 • 3 min read
China Crisis: Government blames China for Electoral Commission cyberattack

China Crisis: Government blames China for Electoral Commission cyberattack

Also accuses Chinese state-affiliated actors of trying to hack MPs emails

Penny Horwood
clock 26 March 2024 • 5 min read
A cyber-focused attorney on why 'Data is the hot potato'

A cyber-focused attorney on why 'Data is the hot potato'

Shawn Tuma, partner and co-chair of the data privacy and cybersecurity practice group at Spencer Fane LLP, shares some tips on cybersecurity for companies to follow.

Samara Lynn
clock 26 March 2024 • 3 min read