SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Story image
APAC businesses unsure if cybersecurity defences are up to scratch
Tue, 24th Aug 2021
FYI, this story is more than a year old

Businesses are now exposed to more and increasingly sophisticated cyber attacks, yet over half (57%) of Asia-Pacific businesses are unsure if their cybersecurity defenses are strong enough to combat hackers' new strategies, according to the 2021 EY Global Information Security Survey.

Even so, the cyber spend of Asia-Pacific businesses remains low at just 0.05% of their annual revenue, on par with the global average of 0.04%.

The low allocation of budget to counter cybersecurity risk is surprising, given that almost three in four (73%) Asia-Pacific companies warn of an increase in the number of disruptive attacks, such as ransomware, over the last 12 months (compared to 47% in last year's GISS).

Almost half of the respondents (48%) are more concerned than they have ever been about their company's ability to manage cyber threats, higher than their counterparts in the Americas (41%).

Cybersecurity investment out of sync with need

About two-fifths (41%) of businesses in Asia-Pacific expect to suffer a major breach that could have been avoided through better investment, higher than in the Americas (29%).

“Businesses are planning a new wave of technology investments to thrive in the post-COVID-19 era,' says Richard Watson, EY Asia-Pacific cyber leader says.

"If cybersecurity is left out of investment discussions, the threat will continue to grow in the years to come," he says.

"They should consider sharing the cost of cybersecurity across the business to support transformation.

Increased cyber risk in pandemic-era transformation

The majority of cyber leaders in the region say they have never been as concerned as they are now about their ability to manage the cyber threat, slightly higher than the global average of 43%. More than half (56%) say their organisations have sidestepped cyber processes to facilitate new requirements around remote or flexible working.

Kris Lovejoy, EY global consulting cybersecurity leader, says the speed of change that businesses have had to adopt to this past year came with a heavy price.

"The need to rapidly transform to survive meant that security was often overlooked. The risks of simply moving on, especially as businesses look to maintain some of these working practices in the post-COVID-19 era, without addressing these cyber gaps, are very real and increasingly urgent," Lovejoy says.

"Recent ransomware events only serve to underscore how critical immediate action is.

Building relationships with the C-suite can turn crisis into an opportunity

The essential relationships between cybersecurity leaders in Asia-Pacific and other functions in the business lack positivity and strength, according to the survey.

Almost 80% of respondents in the region say cybersecurity teams are not always consulted or briefed in a timely manner until after the planning stage has finished, slightly higher than the global average of 76%. Meanwhile, 71% of Asia-Pacific cybersecurity leaders would describe their relationships with business owners as being neutral or negative, while just over four in ten (44%) say their dealings with the marketing and HR functions are poor.

Only 20% of organisations in the region include cybersecurity in the planning phase of any digital transformation program. Respondents believe that the lines of business recognise cybersecurity's traditional strengths, such as in controlling risk, but they do not always perceive the function as a strategic partner.

“CISOs must make difficult decisions, realigning cybersecurity requirements to better meet changing business needs after the COVID-19 pandemic," says Watson.

"Mapping cybersecurity strategy and their organisation's risk profile against business and IT goals will ensure alignment and cement strategic relationships between CISOs, CEOs and the rest of the C-suite," he says.

“At a time of greater distrust and with the cyber function being under more scrutiny than ever, CISOs have an opportunity to better demonstrate the strategic importance of their role and raise their profiles within the business, especially in the aftermath of the pandemic.