Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireSecurity Leadership and ManagementSecurity Education & TrainingCybersecurity News

Study Examines Why Security Professionals are Turning 'Gray Hat'

hacker
August 14, 2018

Almost one in 10 U.S. security professionals has admitted to having considered participating in Black Hat activity, according to the report, "White Hat, Black Hat and the Emergence of the Gray Hat: The True Costs of Cybercrime" conducted by Osterman Research. The study polled 900 senior IT decision-makers and IT security professionals in Australia, Germany, the U.S., U.K., and Singapore about the impact of cybercrime on their bottom line, and also looked at all sides of IT security costs from budget and remediation, to hiring, recruiting and retention.

The study also found that Black/Gray Hats aren't hard to find in today's SOCs. More than half of all U.S. security professionals surveyed (50.5 percent) know or have known someone that has participated in Black Hat activity. This was the highest rate of all countries surveyed. The global average was 41 percent.

"The current skills shortage combined with a steady stream of attacks against antiquated endpoint protection methods continues to drive up costs for today's businesses, with a seemingly larger hit to security departments of mid-market enterprises," said Marcin Kleczynski, Malwarebytes CEO. "On top of this, we are seeing more instances of the malicious insider causing damage to company productivity, revenue, IP and reputation. We need to up-level the need for proper security financing to the executive and board level. This also means updating endpoint security solutions and hiring and rewarding the best and brightest security professionals who manage endpoint protection, detection and remediation solutions."

According to the study, cybercrime incidents are escalating, security budgets are exploding and security remediation costs are skyrocketing:

  • U.S.-based businesses experienced a higher number of very serious security events such as ransomware and intentional insider breaches compared to other countries surveyed—an average of 1.8 incidents in 2017.
  • Based on security budget per employee responses, the average 2,500 employee company in the U.S. will spend more than $1.8 million dollars on security costs. That number is expected to increase to more than $2 million in 2018—nearly twice the average cost of all global responses (more than $1 million in 2018).
  • Remediating major security incidents is extremely expensive: the average global expenditure for remediating just a single event is approximately $290K for a 2,500-employee organization. In the U.S., the average cost escalates to $429K.
  • Phishing was the most common cause of major incidents globally (44 percent) with ransomware (26 percent) and spear phishing (20 percent) also in the top five. While the delivery tactics are familiar, the malware has grown increasingly complex and sophisticated.

In addition, midsize companies (500-999 employees) are getting squeezed with massive increases in security incidents and exploding security budgets, but have fewer employees and smaller budgets:

  • To protect against a high volume of malicious attacks, mid-sized companies' security budgets increased by 36 percent.
  • Mid-market businesses had the highest percentage of security budget increases from 2017 to 2018 (36.32 percent increase for midsize companies; 20.46 percent increase for large companies; 8.5 percent increase in budget for small companies) to counter the significantly higher levels of adware, accidental insider data breaches and intentional insider data breaches and even nation state attacks.
  • Mid-sized companies spent 19 percent of their security budget remediating compromises. Fewer staff on-hand in mid-sized companies' Security Operations Centers (SOCs) to handle the volume of attacks resulted in the highest percentage of security budget spent on remediating attacks (18.62 percent of budget spent on remediating compromises) compared with both large (11.3 percent) and smaller (13.97 percent) companies.
  • 49 percent of global mid-market professionals were most likely to suggest that it's easy to get into cybercrime without getting caught.
KEYWORDS: cyber security Grey Hat IT security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Glowing police siren

Security Isn’t a Commodity. Neither Is Off-Duty Law Enforcement

Two women consulting with a group in background

5 Skills That Will Serve You in Your Security Career

SEC 2026 Benchmark Banner

Events

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Business meeting

    Research finds Security Professionals are Skeptical About Cybersecurity Vendor Claims

    See More
  • SEC0921-Edu-Feat-slide1_900px.jpg

    Technology ownership and risk management: The critical step corporate security professionals are making

    See More
  • Thomas Kinsella podcast news header

    Why security professionals experience burnout

    See More

Related Products

See More Products
  • contemporary.jpg

    Contemporary Security Management, 4th Edition

  • into to sec.jpg

    Introduction to Security, 10th Edition

  • 9780128147948.jpg

    Effective Security Management, 7th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing