HomeCybersecurityRetail industry sees most cyber incidents in APAC due to lack of...

Retail industry sees most cyber incidents in APAC due to lack of cybersecurity budget

According to a recent study by Kaspersky, globally, critical infrastructure, oil & gas, and energy organizations suffered the biggest number of cyber incidents due to improper budget allocation (25%). In Asia Pacific, however, the retail industry experienced the greatest number of successful cyberattacks in the past 24 months.

The latest survey also revealed that 19% of companies in the region have experienced cyber incidents due to insufficient cybersecurity investment in the last two years. When it comes to companies’ finances, nearly one in five (16%) admit they do not have the budget for adequate cybersecurity measures.

Kaspersky conducted a study to discover the opinions of IT Security professionals working for SMEs and enterprises worldwide regarding the human impact on cybersecurity in a company. The research – aimed at gathering information on various groups of people who influence cybersecurity – considered both internal staff, and external contractors. It also analyzed the impact decision-makers have on cybersecurity in terms of budget allocation. A total of 234 respondents from APAC were surveyed.

Insufficient distribution of budget for cybersecurity led 19% of Asian companies to endure cyber incidents in the last two years.

The situation is different for every industry. For example, retail organizations suffered the greatest number of cyber breaches because of the lack of budget (37%), followed by telecommunication companies (33%) and critical infrastructure, energy, oil, and gas sectors (23%).

“E-commerce is expected to be a 2.05 trillion USD market in Asia Pacific towards the end of 2023. Retail being the industry that suffered most cyber incidents here makes sense as cybercriminals follow the money trail. These companies are part of the greater digitalization movement in the region and hold treasure troves of data, specifically financial ones,” comments Adrian Hia, Managing Director for Asia Pacific at Kaspersky.

“Our recent study proves that threat actors know which company to target. They know the data they want and where to get them. I encourage all industries in APAC, especially those that handle critical information, to allot better cybersecurity budget to ensure the safety of their businesses, and most importantly, of their customer’s sensitive data,” he added.

Meanwhile, some industries showed a smaller number of cyber incidents. The manufacturing industry suffered 11% of cyber incidents due to budget constraints, while transport & logistics saw 9% of them.

When asked about the budget for cybersecurity measures, a majority (83%) of respondents from APAC said they are equipped to keep up with or even stay ahead of new threats. However, 16% of companies are not doing so well – 15% report that they don’t have sufficient funds to protect the company’s infrastructure properly.

At the same time, there are still companies without cost allocations for cybersecurity at all – 2% claimed they don’t have a dedicated budget for cyber protection needs.

The most successful industry in APAC in terms of proper monetary distribution for cybersecurity is financial services – 100% of respondents working in this sphere claim their organizations are set to keep up with and stay ahead of all new threats.

Would you say the budget for cybersecurity measures in your company ….?

Kaspersky Study - fyi9

Many respondents’ companies are eager to take steps to strengthen their cybersecurity in the next 1-1.5 years. One of the most popular areas of investment is threat detection software (46%), and training, where half (50%) of companies plan to allocate budgets for educational programs for cybersecurity professionals and 46% for training general staff.

Other popular measures organizations plan to take soon are introducing endpoint protection software (42%), hiring additional IT professionals (37%), and adopting SaaS cloud solutions (45%).

“Today, companies must align cybersecurity investment with a business strategy and consider cybersecurity one of their business goals. Of course, investments must justify themselves and be effective, so the information security department also faces the task of increasing the ROI of investments in information security and defending investments to senior management or the board of directors. Also, in addition to reducing MTTD and MTTR, information security is tasked with reducing the cost of a security incident. These challenges can be met using various modern approaches and technologies. For example, we are investing in developing our SASE portfolio as well as XDR and MDR with integrated AI, Machine Learning, automated detection and response, automated threat investigation, out-of-the-box integrations, and much more. To ensure process transparency and prove the value of our solutions, we also provide C-level dashboards and reports for CISOs, which include information on how many incidents we prevented, how quickly incidents were investigated, and the effectiveness of deployed cybersecurity solutions. We also highlight customer-specific risks, and show them trends particular to the industry to help them shape their cybersecurity by targeting their defenses around current dangers, and justify investments in the necessary technology.” comments Ivan Vassunov, VP, of Corporate Products at Kaspersky.

To get the most out of your budget, Kaspersky recommends:

  • Implementing cybersecurity products with Advanced Anomaly Control such as Kaspersky Endpoint Detection and Response Optimum. This helps prevent potentially dangerous ‘out of the norm’ activities initiated by a user or an attacker who has already taken control of the system.
  • Using easily-manageable solutions. Kaspersky Endpoint Security Cloud is designed for smaller enterprises or companies that don’t currently have the budget for a wide stack of cybersecurity products. The all-in-one hosted SaaS console allows just a single administrator to manage a broad range of cybersecurity tasks from one place, with a simple and easy-to-master workflow.
  • Investing in training for everyone in your company – from general staff to decision makers. Kaspersky Automated Security Awareness Platform training teaches employees safe internet behavior and includes simulated phishing attack exercises. At the same time, Kaspersky Cybersecurity for IT Online training helps build up simple yet effective IT security best practices and simple incident response scenarios for generalist IT admins, while Kaspersky Expert Training equips your security team with the latest knowledge and skills in threat management and mitigation to defend your organization against even the most sophisticated attacks. And last but not least, to advance decision-makers understanding of the importance of cybersecurity and how best to distribute budgets to stay ahead of threats, engage them with Kaspersky Interactive Protection Simulation for enhanced C-level professional education.
  • Considering experts’ help. For example, the Kaspersky Assessments family of professional services identifies security gaps in your system’s configuration, and the Security Architecture Design helps create an IT security infrastructure that’s a perfect fit for a particular company. Every step of implementation is grounded in real security needs, giving decision-makers convincing arguments to allocate budgets.

Also read – Amazfit Balance Smartwatch Unveiled, Redefining Wellness in India

Join our WhatsApp News Channel for quick updates – FYI9 News WhatsApp Channel

Must Read