The latest International Cyber Benchmarks Index™, for January 2020, is 29.8, maintaining the upward trend.
Use of tools that generate security alerts and percentage of false positive alerts
Two-fifths (39%) of organizations have 7 or more tools in place that generate security alerts and over two-fifths (43%) experience false positive alerts in more than 20% of cases (26% on average).
Cyber threats ranked in order of level of concern
During November-December 2019, DDoS was the greatest concern followed by System compromise and then Ransomware.
How threat of attack by various vectors has changed
During November-December 2019, Social engineering - email was most likely to be perceived as an increasing threat to organisations, followed by DDoS and Ransomware.
How organisations’ ability to respond to threats has changed
During November-December 2019, organisations have focused most on increasing their ability to respond to Targeted hacking, Ransomware and Vendor or customer impersonation.
How the risk of attack from various actors has changed
During November-December 2019, organisations have perceived the most likely increase in threats to be from Criminals and Unknown actors.
How threat landscape has changed
During November-December 2019, organisations have continued to perceive the threat landscape to be increasing most from the World at large and least from within their own company.
Whether respondents have ever been on the receiving end of a DDoS
62% of enterprises surveyed in January 2020 indicated that they have been on the receiving end of a DDoS attack at some time, a higher proportion than in previous reporting periods*.
* Note that the sample composition changes from wave to wave which explains why the trend for this question can be down as well as up.
Whether survey respondents outsource DDoS mitigation
52% of enterprises surveyed in January 2020 outsource their DDoS mitigation, in line with the previous reporting period.
Length of time taken to initiate DDoS mitigation
In January 2020, enterprises were most likely to take between 60 seconds and 5 minutes to initiate DDoS mitigation, in line with previous reporting periods.