The latest International Cyber Benchmarks Index™, for May 2018, is 15.2, maintaining the upward trend.
Impact of cyber attacks
The vast majority of participants agreed that a Web Application Firewall (WAF) is an essential component of their security infrastructure. This increases the survey average by three points.
Meltdown-Spectre vulnerability: actions taken to minimize risks and whether attacks will become the ‘norm’
Vast majority of companies (98%) have taken steps to minimize the risk from Meltdown-Spectre vulnerability and nine of ten agree these types of attack will become the ‘norm’.
Cyber threats ranked in order of level of concern
During March-April 2018, System Compromise was the greatest concern followed closely by Ransomware and DDoS.
How threat of attack by various vectors has changed
During March-April 2018, DDoS was most likely to be perceived as an increasing threat to organisations, followed by Ransomware and Social engineering - email.
How organisations’ ability to respond to threats has changed
During March-April 2018, organisations have focused most on increasing their ability to respond to Ransomware, DDoS and Targeted hacking.
How the risk of attack from various actors has changed
During March-April 2018, organisations have perceived the most likely increase in threats to be from Criminals and Unknown actors.
How threat landscape has changed
During March-April 2018, organisations have continued to perceive the threat landscape to be increasing most from the World at large and least from within their own Company.
Whether respondents have ever been on the receiving end of a DDoS
42% of enterprises surveyed in May 2018 have *ever been on the receiving end of a DDoS, in line with previous reporting periods.
* Note that the sample composition changes from wave to wave which explains why the trend for this question can be down as well as up.
Whether survey respondents outsource DDoS mitigation
48% of enterprises surveyed in May 2018 outsource their DDoS mitigation, as many as in any previous reporting period, and maintaining the average at 42%.
Length of time taken to initiate DDoS mitigation
In May 2018, enterprises were most likely to take between 60 seconds and 5 minutes to initiate DDoS mitigation, in line with previous reporting periods.