Connect with us

BizNews

Security response planning on the rise, but containing attacks remains an issue – IBM

While organizations surveyed have slowly improved in their ability to plan for, detect and respond to cyberattacks over the past five years, their ability to contain an attack has declined by 13% during this same period.

Published

on

IBM announced the results of a global report examining businesses’ effectiveness in preparing for and responding to cyberattacks. While organizations surveyed have slowly improved in their ability to plan for, detect and respond to cyberattacks over the past five years, their ability to contain an attack has declined by 13% during this same period.

The global survey conducted by Ponemon Institute and sponsored by IBM Security found that respondents’ security response efforts were hindered by the use of too many security tools, as well as a lack of specific playbooks for common attack types.

While security response planning is slowly improving, the vast majority of organizations surveyed (74%) are still reporting that their plans are either ad-hoc, applied inconsistently, or that they have no plans at all. This lack of planning can impact the cost of security incidents, as companies that have incident response teams and extensively test their incident response plans spend an average of $1.2 million less on data breaches than those who have both of these cost-saving factors in place.

The key findings of those surveyed from the fifth annual Cyber Resilient Organization Report include:

  • Slowly Improving: More surveyed organizations have adopted formal, enterprise-wide security response plans over the past 5 years of the study; growing from 18% of respondents in 2015, to 26% in this year’s report (a 44% improvement).
  • Playbooks Needed: Even amongst those with a formal security response plan, only one third (representing 17% of total respondents) had also developed specific playbooks for common attack types — and plans for emerging attack methods like ransomware lagged even further behind.
  • Complexity Hinders Response: The amount of security tools that an organization was using had a negative impact across multiple categories of the threat lifecycle amongst those surveyed. Organizations using 50+ security tools ranked themselves 8% lower in their ability to detect, and 7% lower in their ability to respond to an attack, than those respondents with less tools.
  • Better Planning, Less Disruption: Companies with formal security response plans applied across the business were less likely to experience significant disruption as the result of a cyberattack. Over the past two years, only 39% of these companies experienced a disruptive security incident, compared to 62% of those with less formal or consistent plans.

“While more organizations are taking incident response planning seriously, preparing for cyberattacks isn’t a one and done activity,” said Wendi Whitmore, Vice President of IBM X-Force Threat Intelligence. “Organizations must also focus on testing, practicing and reassessing their response plans regularly. Leveraging interoperable technologies and automation can also help overcome complexity challenges and speed the time it takes to contain an incident.”

Updating Playbooks for Emerging Threats
The survey found that even amongst organizations with a formal cybersecurity incident response plan (CSIRP), only 33% had playbooks in place for specific types of attacks. Since different breeds of attack require unique response techniques, having pre-defined playbooks provides organizations with consistent and repeatable action plans for the most common attacks they are likely to face.   

Amongst the minority of responding organizations who do have attack-specific playbooks, the most common playbooks are for DDoS attacks (64%) and malware (57%). While these methods have historically been top issues for the enterprise, additional attack methods such as ransomware are on the rise. While ransomware attacks have spiked nearly 70% in recent years, only 45% of those in the survey using playbooks had designated plans for ransomware attacks.

Additionally, more than half (52%) of those with security response plans said they have never reviewed or have no set time period for reviewing or testing those plans. With business operations changing rapidly due to an increasingly remote workforce, and new attack techniques constantly being introduced, this data suggests that surveyed businesses may be relying on outdated response plans which don’t reflect the current threat and business landscape.

More Tools Led to Worse Response Capabilities
The report also found that complexity is negatively impacting incident response capabilities. Those surveyed estimated their organization was using more than 45 different security tools on average, and that each incident they responded to required coordination across around 19 tools on average. However, the study also found that an over-abundance of tools may actually hinder organizations ability to handle attacks. In the survey, those using more than 50 tools ranked themselves 8% lower in their ability to detect an attack (5.83/10 vs. 6.66/10), and around 7% lower when it comes to responding to an attack (5.95/10 vs. 6.72/10).

These findings suggest that adopting more tools didn’t necessarily improve security response efforts — in fact, it may have done the opposite. The use of open, interoperable platforms as well as automation technologies can help reduce the complexity of responding across disconnected tools. Amongst high-performing organizations in the report, 63% said the use of interoperable tools helped them improve their response to cyberattacks.

While security response planning is slowly improving, the vast majority of organizations surveyed (74%) are still reporting that their plans are either ad-hoc, applied inconsistently, or that they have no plans at all.

Better Planning Pays Off
This year’s report suggests that surveyed organizations who invested in formal planning were more successful in responding to incidents. Amongst respondents with a CSIRP applied consistently across the business, only 39% experienced an incident that resulted in a significant disruption to the organization within the past two years  compared to 62% of those who didn’t have a formal plan in place.

Looking at specific reasons that these organizations cited for their ability to respond to attacks, security workforce skills were found to be a top factor. 61% of those surveyed attributed hiring skilled employees as a top reason for becoming more resilient; amongst those who said their resiliency did not improve, 41% cited the lack of skilled employees as the top reason.

Technology was another differentiator that helped organizations in the report become more cyber resilient, especially when it comes to tools that helped them resolve complexity. Looking at organizations with higher levels of cyber resilience, the top two factors cited for improving their level of cyber resilience were visibility into applications and data (57% selecting) and automation tools (55% selecting). Overall, the data suggests that surveyed organizations that were more mature in their response preparedness relied more heavily on technology innovations to become more resilient.

BizNews

Long-serving CEOs may weaken innovation, study finds

Companies led by long-serving chief executives may become less innovative over time unless challenged by strong independent boards.

Published

on

A new study from the University of East London has found that companies led by long-serving chief executives may become less innovative over time unless challenged by strong independent boards.

The research examined 215 FTSE 350 companies over an 11-year period between 2010 and 2021. It explored how CEO tenure and independent directors influence a company’s “R&D knowledge stock”, which is the research, expertise and technological capability built through investment in innovation.

The study published in the journal Corporate Governance found that CEOs who remain in office for many years often become more cautious and less willing to back risky research and development projects. These companies were more likely to reduce investment in innovation and long-term technological growth.

Firms with higher numbers of independent directors were more likely to continue building innovation capacity with experienced CEOs and independent directors forming an effective partnership, to combine deep company knowledge with outside challenge.

However, both experienced CEOs and independent directors become more cautious and less willing to back risky research and development projects when the company fails to meet performance aspirations, suggesting that independent directors do not have stable risk preferences.

The findings suggest that innovation is shaped not only by technology and finance, but also by leadership culture and corporate governance structures.

Author Dr Igbekele Sunday Osinubi, of the Royal Docks School of Business and Law, said: “Long-serving CEOs can bring valuable experience and stability, but there is also a risk that leaders become too cautious or too attached to existing ways of thinking. Our findings show that independent directors play an important role in encouraging companies to continue investing in innovation, especially during difficult periods when firms may otherwise retreat from long-term research and development.”

He added: “This matters beyond individual companies. Innovation drives productivity, competitiveness and economic growth. The study highlights how governance structures can influence whether firms continue building the knowledge and technologies that shape future industries.”

The paper argues that regulators and policymakers should consider governance reforms and incentives that encourage long-term innovation strategies, particularly in firms led by long-serving executives. The findings may also influence how boards think about CEO succession planning, oversight and the balance between short-term financial pressures and long-term investment.

Osinubi’s research, “Long CEO tenure, independent directors and R&D knowledge stock: the moderating effect of performance shortfalls”, was published in the Corporate Governance: The International Journal of Business in Society

Continue Reading

BizNews

Profit alone is a poor measure of success, study shows companies can look efficient while harming the planet

Firms that appear highly efficient at generating revenue can perform far worse when their environmental footprint are included in the calculation.  

Published

on

Companies celebrated for strong financial performance may actually be inefficient once their environmental impact is taken into account, according to new research from the University of Surrey. 

The study, published in the European Journal of Operational Research, shows that firms that appear highly efficient at generating revenue can perform far worse when their environmental footprint are included in the calculation.  

To tackle this problem, researchers developed a new way to measure “sustainable corporate efficiency”, combining traditional financial metrics with environmental data such as energy consumption, carbon emissions and revenues generated from environmentally friendly products and services.  

Dr Menelaos Tasiou, co-author of the study and Senior Lecturer in Finance at the University of Surrey, said: “Businesses have long been judged on how efficiently they turn resources into profit. But if those profits come with large environmental costs, the picture changes completely. What we show is that true efficiency means generating revenue while also reducing the environmental damage caused by production. In other words, profitability alone can mask how wasteful a business really is when environmental costs are considered.  

The research analysed more than 2,800 publicly listed companies across 61 countries between 2010 and 2022, creating one of the largest global datasets measuring how sustainable companies are, when both financial performance and environmental impact are assessed together.  

The team combined company financial records, in alignment with the green economy (defined as a low carbon, resource efficient and socially inclusive economy), with environmental disclosures such as energy use and greenhouse gas emissions. They then applied a machine learning technique known as Convexified Efficiency Analysis Trees (CEAT) to estimate how efficiently companies convert resources into revenue while minimising pollution.  

Unlike older approaches, the method models the reality that production creates both desirable outputs, such as revenue, and undesirable ones, such as emissions. This allows companies to be compared on how well they balance profit with environmental performance.  

The results found a moderate link between financial efficiency and environmental efficiency, meaning many firms that are strong financially are not necessarily good at managing their environmental impact.  

The study also found large differences across industries and countries. Firms operating in sectors with high emissions, such as manufacturing and energy, often lagged behind leaders that were better at reducing carbon intensity while maintaining revenue.  

Dr Tasiou continued: “Measuring efficiency in this broader way can help investors, regulators and policymakers identify companies that are genuinely prepared for a low carbon economy. Stronger management capability plays a key role. Firms with more capable management teams were more likely to balance profitability with environmental responsibility, suggesting that leadership decisions can strongly influence sustainable performance.  

“As governments push towards net zero and investors scrutinise environmental performance more closely, companies that fail to integrate sustainability into their operations risk falling behind.” 

Continue Reading

BizNews

Reminder to marketing people: Missing information can misinform

You don’t need bad actors for people to get the wrong idea. Incomplete information can be enough.

Published

on

To get people to pay attention, you have to make it engaging. But what makes content engaging often comes at the cost of detail – shaping what people learn and what they think they’ve learned. The result: People can come away with the wrong idea, even when what they read isn’t factually wrong.

That tension sits at the core of research from Marta Serra-Garcia, a behavioral economist at the University of California San Diego’s Rady School of Management. The study, published in the American Economic Review, examines how incentives in the online attention economy shape the way scientific information is communicated – and what readers ultimately take away from it.

A trade-off in the attention economy

You don’t need bad actors for people to get the wrong idea. Incomplete information can be enough.

Crucially, the research finds that attention-grabbing summaries are not more likely to be factually inaccurate. Instead, they tend to include less information – especially key details about how studies were conducted.

“This is not a simple story that clickbait is bad,” said Serra-Garcia, associate professor of economics and strategy and Phyllis and Daniel Epstein Chancellor’s Endowed Faculty Fellow at UC San Diego’s Rady School. “You need to get people’s attention in order for them to learn something, and it’s good to encourage curiosity. Yet there’s a trade-off: Material designed to engage can also unintentionally contribute to the kinds of misunderstandings that can fuel misinformation.”

The finding comes from a large, multi-stage experimental study in which freelance writers produced nearly 600 summaries of actual scientific research, and more than 3,700 participants were then tested on what they learned from them.

Why “in mice” matters

In one study used in the experiment, a compound in broccoli reduced cancer cell growth – in mice. Leave out those last two words, and the finding can sound far more directly relevant to human health than it actually is.

“Why can’t we say ‘in mice’?” Serra-Garcia said. “It’s not very hard to add. It’s two words. But once you say ‘in mice,’ maybe fewer people will click.”

Study results were consistent. Summaries written to attract attention were shorter, easier to read and more engaging – but included less detailed information, especially about sample sizes and methods.

Given the option to seek out more information, most readers did not. That mirrors real-world behavior: Studies of social media use suggest most content is shared without users ever clicking through to read more.

Among those who relied on summaries alone in Serra-Garcia’s study, knowledge dropped by about 6-7 percentage points. Readers were also more likely to draw incorrect conclusions – such as assuming findings applied to humans or reflected firm medical guidance.

Inside the experiments

To isolate these effects, Serra-Garcia conducted a multi-stage experimental study. In the first stage, 149 freelance writers produced nearly 600 summaries of the same set of studies – covering topics such as cancer, sleep, vaccines and climate – under different instructions: to inform readers accurately, or to attract attention by encouraging clicks or shares. 

In the second stage, more than 3,700 participants read those summaries under different conditions, including whether they could click through for more information.

The results held across experiments: Attention-driven summaries increased engagement and prompted some readers to learn more – but left many others with less complete understanding.

AI and the attention economy

The same pattern emerged when a human wasn’t doing the writing. In additional tests, when a large language model was prompted to attract attention, it also produced less detailed summaries – suggesting the effect is driven less by who creates the content than by the objective it’s optimized for.

For Serra-Garcia, the findings point to an ongoing challenge for researchers, journalists and institutions alike.

“How do you make science engaging and important to readers,” she said, “without missing the essentials that convey the full picture?” 

The research was funded in part by National Science Foundation grant no. 2343858. 

Read the full study: “The Attention – Information Trade-off.” 

Continue Reading
Advertisement
Advertisement

Like us on Facebook

Trending