Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
Security Enterprise ServicesLogical SecuritySecurity & Business Resilience

Poor incident detection can cost your organization a fortune

By Michael Paye
cybersecurity risks
September 24, 2020

The United Nations Conference on Trade and Development estimates that the spread of COVID-19 will depress global economic growth in 2020 to below 2.5%, the recession threshold. Indeed, organizations are already seeing weak demand and decreased revenue and profits, and are responding by taking cost-containment measures and canceling planned investments. These changes will almost certainly affect physical security technology and cybersecurity projects; indeed the latest numbers from Gartner and Forrester expect a decline in global global IT spending cybersecurity budgets. 

While prompt detection of security incidents has always been critical, it is even more vital during an economic downturn. According to the 2019 Ponemon Cost of Data Breach Study, the longer it takes a company to detect a breach, the more it will cost. Organizations that spend more than 200 days on incident detection have a 37% higher cost of a breach compared to those who detected security incidents sooner. Those steeper costs are harder to absorb now and could even put a company out of business.

How long does incident detection currently take?

A malicious user can download a lot of sensitive data very quickly, and some modern attacks and malware can strike with blazing speed. Clearly, fast detection of incidents is critical to preventing data loss, data encryption and other damage. A SANS report confirms that businesses need to detect incidents in minutes or, at least, a few hours to minimize data security risks.

The Netwrix 2020 Data Risk and Security Report finds that organizations find it difficult to detect security incidents promptly at all six stages of the data lifecycle. The most problematic stage is data storage. It takes organizations days (43%) or weeks (23%) to discover sensitive data outside of secure locations, such as in cloud storage or enterprise applications like Microsoft Teams. The archive stage of the data lifecycle is nearly as bad; companies need days (38%) or weeks (28%) to detect breaches there. 

How can you spot incidents faster?

To promptly detect threats, organizations need to have deep awareness into where their data resides, how sensitive that data is and who has access to it. They also need to be able to quickly spot and investigate suspicious activity, so they can take action to mitigate threats. I suggest that you implement the following measures to speed up incident detection and ensure timely and effective response:

  • Understand which data requires attention. You need to know exactly which data is more valuable and is therefore a more likely target of threat actors. Data classification will help you understand which information is sensitive and where it is located so that you can take appropriate steps to protect it. Ideally, an automated solution will regularly check whether all critical data resides only in secure locations and take steps to remediate any overexposure before the data can be exfiltrated or encrypted. 
  • Closely monitor user activity around data. The longer hackers can lurk undiscovered in your IT environment, the more time they have to creep around, identify your most critical files and steal them. A user behavior analysis and monitoring tool is critical to quickly spotting both overt and subtle indicators of attacks, such as activity outside of business hours, unusual data access patterns and failed logon attempts. A solution that can proactively alert you about abnormal spikes in user activity will enable you to respond to threats even faster. 
  • Have an actionable incident response plan. Finally, it is essential to have a detailed incident response plan and regularly test it to make sure it works as intended. Ideally, this plan will include procedures for handling and reporting incidents, as well as guidelines for communicating with outside parties. Having a solid plan will help you take action more quickly in the event of a security incident so you can minimize the damage you suffer. If you want to revise your existing plan or create a new one, use best-practice standards like NIST SP 800-61 r.2 and ISO/IEC 27035 as a starting point. 

No matter how much the economic situation changes, prompt detection and response to cyber threats must remain a core priority for your organization. The ability to spot and address incidents in their early stages will help you avoid data breaches and their unpleasant consequences, including business downtime, lost revenue, costly security investigations and fines from regulatory bodies. As a result, you can save your budget for mission-critical tasks that will bring your organization value in the long run. 

KEYWORDS: cyber security risk mitigation

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mikepayeprofile
Paye is the chief technology officer at Netwrix. He is a thought leader in the cyber security space and now provides direction and expertise to build innovative cross-industry business solutions to help organizations with data security, regulatory compliance and information governance. Paye received his degree in computer science from Southampton University, U.K. His technical background is predominately focused on the Microsoft stack, specifically SQL Server and SharePoint, as well as cloud technologies. Prior to Netwrix, Paye led the research and development team at Concept Searching.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Security Leadership and Management
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • SEC0919-Assurance-Feat-slide1_900px

    Unprepared for CCPA? It Could Cost Your Organization

    See More
  • “Garbage In” Can Cost You Your Job

    See More
  • Ransomware on a laptop

    Ransomware has hit epidemic levels — does your organization have a cyberattack response plan?

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • threat and detection.jpg

    Surveillance and Threat Detection

  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

See More Products

Events

View AllSubmit An Event
  • January 14, 2026

    Is Your Organization Prepared to Navigate Interconnected Threats in 2026?

    ON DEMAND: The 2026 threat environment will be louder, faster, and more interconnected. In this webinar, we will provide real-world incident data and expert analysis from AlertMedia’s 2026 Threat Outlook Report.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing