Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Cybersecurity News

Cybercrime Incidents, Associated Financial Costs Surge While Organizations Still Unprepared: Survey

May 29, 2014

Acccording to the 2014 U.S. State of Cybercrime Survey, most U.S. organizations' cybersecurity capabilities do not rival the persistence and technological skills of their cyber adversaries.

According to the report, only 38 percent of companies have a methodology to prioritize security investments based on risk and impact to business strategy.  "Cyber criminals evolve their tactics very rapidly, and the repercussions of cybercrime are overwhelming for any single organization to combat alone. It's imperative that private and public organizations collaborate to combat cybercrime and gain intelligence about security threats and how to respond to them. A united response will prove to be an indispensable tool in advancing the state of cybersecurity," said David Burg, PwC's Global and U.S. Advisory Cybersecurity Leader.

The U.S. Director of National Intelligence has ranked cybercrime as the top national security threat, higher than that of terrorism, espionage and weapons of mass destruction. U.S. business leaders in particular are increasingly worried about cybercrime—much more than their global counterparts. PwC's Annual Global CEO Survey 2014 found 69% of U.S. respondents reported they were worried about the impact of cyber threats to their growth prospects, compared with 49% of global CEOs.

The Cybercrime survey finds that the average number of security incidents detected over the past year was 135 per organization. Fourteen percent of respondents reported that monetary losses attributed to cybercrime have increased. The actual costs, however, remain largely unknown as more than two-thirds (67 percent) of those who detected a security incident were not able to estimate the financial costs. Among those that could, the average annual monetary loss was projected to be $415,000.

Eight Major Cybersecurity Deficiencies
The survey revealed the following key cybersecurity deficiencies:

  • Most organizations do not take a strategic approach to cybersecurity spending
  • Organizations do not assess security capabilities of third-party providers
  • Supply chain risks are not understood or adequately assessed
  • Security for mobile devices is inadequate and has elevated risks 
  • Cyber risks are not sufficiently assessed
  • Organizations do not collaborate to share intelligence on threats and responses
  • Insider threats are not sufficiently addressed
  • Employee training and awareness is very effective at deterring and responding to incidents, yet it is lacking at most organizations

To combat these deficiencies, PwC  recommends that organizations can: invest in people and processes, in addition to technologies; hold third parties to the same or higher standards; assess risks associated with supply chain partners; ensure that mobile security practices keep pace with adoption and use of mobile devices; perform cyber risk assessments regularly; take advantage of information sharing internally and externally to gain intelligence on fast-evolving cyber risks; develop threat-specific policies; and, enhance training and create workforce messaging to boost cybersecurity awareness across the organization.

"Despite substantial investments in cybersecurity technologies, cyber criminals continue to find ways to circumvent these technologies in order to obtain sensitive information that they can monetize," said Ed Lowery, Special Agent in Charge, Criminal Investigative Division, U.S. Secret Service. "The increasing sophistication of cyber criminals and their ability to circumvent security technologies indicates the need for a radically different approach to cybersecurity: A balanced approach that, in addition to using effective cybersecurity technologies, develops the people, processes, and effective partnerships in order to strategically counter cybersecurity threats."

This year, three in four (77 percent) respondents to the survey reported a security event in the past 12 months, and more than a third (34 percent) said the number of security incidents increased over the previous year. Additionally, 59 percent of respondents reported that they were more concerned about cybersecurity threats this year than they were the year before.

"There is a correlation between company size and how they confront important elements of cybersecurity," said Bob Bragdon, vice president and publisher, CSO. "For larger companies, insiders remain the greatest risk for cybersecurity, while outsiders pose more of a risk for smaller companies. Large companies with over a thousand employees have entire IT security departments, focused solely on these issues, compared to smaller businesses. Regardless of size, developing threat-specific policies that include detection, monitoring, analytics and investigation for responding to insider threats is critical. However, experience breeds caution – the companies that have experienced a security event have developed more mature practices and become more cautious than those who have not."

In particular, many recent incidents with payment-card heists have proved threat actors are increasingly attempting to infiltrate systems via third parties, yet only 44 percent of companies have a process for evaluating third parties before the launch of business operations. 

"Third-party and supply chain partners should be held to the same, if not higher, cybersecurity standard that companies set for themselves," said Randy Trzeciak, technical manager of the Insider Threat Center at CERT. "In particular, compliance should be mandated in contracts. Carefully assessing risks associated with partners and determining incident response plans are also essential elements."

"The severity of cyber threats will continue to intensify as threat actors evolve and sharpen their skills and techniques. If history—and responses to this survey—are a guide, more organizations will fall victim to more costly cybercrime in the coming year," commented Burg. "Organizations that take a strategic approach to cybersecurity spending can build a more effective cybersecurity practice, one that advances the ability to detect and quickly respond to incidents that are inevitable."

For the full survey report, please visit: http://www.pwc.com/us/en/increasing-it-effectiveness/publications/2014-us-state-of-cybercrime.jhtml

KEYWORDS: cyber security cybercrime data breach supply chain security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Photograph of apartment complex patios

Enhancing Residential Building Security

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

American flag lit with people

Protecting America’s Critical Infrastructure: A Shared Responsibility in an Era of Escalating Cyber Threats

Events

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Rendered heart monitors

    Cybersecurity Stagnation in Healthcare: The Hidden Financial Costs

    See More
  • Report Shows Organizations Still Challenged by PCI Security Compliance Requirements

    See More
  • Many Global Organizations Still Lacking in Confidence to Fight Cyber Threats

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

  • contemporary.jpg

    Contemporary Security Management, 4th Edition

  • A Leaders Guide Book Cover_Nicholson_29Sept2023.jpg

    A Leader’s Guide to Evaluating an Executive Protection Program

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing