Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Are Enterprises Really Too Far Behind on Cybersecurity?

By Tom Misson
May 27, 2015

The Information and cybersecurity field can be a sea of numbers, so it’s not surprising to see – almost on an everyday basis – articles published that spits out numbers like a lottery ticket machine. One recent article on SecurityMagazine.com caught the eye of SecureState.

The article under the microscope was posted May 19, and revealed the findings of a new Ponemon Institute survey. The focal point – to shed light on the lag time it takes both the retail and financial industries to identify advanced threats once those threats are inside their networks. The article points out the “dwell” time for Financial is 98 days, while Retail takes 197 days. These glaring numbers had this author wondering, what are the response times for the other industries, and if it might be a bit unfair to target financial and retail.

So I did some digging. The 2015 Trends Report, along with The 2014 Threat Report – both published by the cybersecurity firm Mandiant – shows a positive trend as an industry whole, with a 16 percent increase in the success rate of data breach discovery, over the past three years:  2014 (205 days), 2013 (229 days), 2012 (243 days). Thus, judging by these numbers, financial and retail are actually ahead of the curve.

Another point the article claims is organizations need to invest more in security staff and tools.

Sounds logical enough, so I looked into that as well.  I dug into the 2015 Global State of Information Security Survey, authored by Pricewaterhouse Coopers, which estimates organizations are spending roughly four percent of their IT budgets on security. A low number, yes, and actually reversing a three year trend of increasing security budgets. However, in North America, security budgets remain on the rise, while financial loses from 2013-2014 declined. This could be a direct correlation.

So then, the argument of Capex (Capital spending) versus Opex (Operational spending) comes into play. Do these businesses spend a chunk of money on a piece of equipment they believe will better protect their systems, or earmark it for employees and further training?  A perfect example of this is Home Depot. The do-it-yourself retailer hired its first ever CISO just months ago, after falling victim to a breach in 2014. More and more organizations are realizing putting someone specifically in charge of their security is the better path to protection. It ultimately comes down to the Principle of Three Forces – Time, Resource and Change.

Here’s one other morsel of food-for-thought. The better all industries get at discovering data breaches, the faster they place themselves in the cross-hairs of the media. It is a definite Catch-22 for any organization to admit they’ve been breached, knowing they’ll become a victim of the media meat grinder.

KEYWORDS: data breach data loss prevention security budget

Share This Story

Tom Misson is a Public Relations Specialist at SecureState, a global management consulting firm specializing in information security, headquartered in Cleveland, Ohio. Misson spent 22 years as a journalist before taking the step to public relations. He is an Ohio native, who obtained a communications degree from The University of Toledo.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

Cybersecurity predictions of 2026

5 Cybersecurity Predictions for 2026

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing