Local organizations’ failure to prioritize cybersecurity is hindering their digital transformation journey, according to a Singapore study conducted by analyst firm Frost & Sullivan.
Commissioned by Forcepoint, the study finds that most Singapore organizations (78%) don’t think about cybersecurity before embarking on digital transformation projects. Less than half of the companies surveyed (47%) conducted regular breach assessments, and more than a third of firms in Singapore (37%) have encountered a data breach. The study reveals that cloud is a key component of digital transformation (75% of respondents have adopted cloud) but many organizations think cybersecurity is the responsibility of their cloud service provider.
“It’s clear from this study that many Singapore firms are on the back foot when it comes to enterprise cybersecurity in the borderless organization,” said Kenny Yeo, Industry Principal, APAC ICT, Frost & Sullivan. “Security leaders need to look beyond perimeter security, leverage automation, and adopt a human-centric security approach that focuses on understanding users’ behavior on the network and within applications to effectively curb attacks.”
Digital transformation hindered by cyber risks
The study reveals a big push for digital transformation among Singapore organizations, with 94% of respondents having embarked on a digital transformation journey, adopting emerging technologies including cloud computing, mobility, internet of things and artificial intelligence/machine learning. However, most organizations, or 65% of respondents, acknowledged that they are seriously hampered in the execution of their digital transformation projects due to rising cyberattacks.
One of the key reasons for this is Singapore business leaders’ less mature approach of not involving cyber security when designing digital transformation projects. Seventy-eight percent of the respondents did not consider cybersecurity until after their digital transformation projects had begun. Only 8% of Singapore organizations saw cybersecurity as a business enabler for their digital transformation needs. As much as 18% saw it primarily as a cost center. Also concerning is the fact that 70% of firms here don’t involve their C-level execs while preparing for potential cyber security breaches.
“Organizations today need to urgently to embrace ‘secure-by-design’ into their digital transformation projects,” said Alvin Rodrigues, senior director and security strategist at Forcepoint Asia Pacific. “They also need to better harness cybersecurity to drive business and get board-level executives more involved in risk management. There is a clear link between firms who involve their C-level execs and better breach preparedness.”
Organizations surveyed underestimate the impact of cyber security incidents on their operations − 56% assume less than an hour of service disruption, but, only 24% experienced such a short period of disruption. Likewise, 57% of organizations expect less than an hour of service disruption to customers, but, a significantly lower 37% experienced that period of disruption.
Serious misconceptions around security in the cloud
Cloud has become one of the key components which is leading digital transformation, with 75% of Singapore organizations adopting the technology. However, 50% of respondents perceive that their cloud service provider will take full responsibility for security. Normally, security and compliance are a shared responsibility between an organization and the cloud service provider. This serious misconception around responsibility of security in the cloud is resulting in a higher number of cyberattacks.
Enterprises not doing enough to protect themselves against cyber incidents
The findings show that not many organizations have taken measures to protect themselves against cyber incidents, with only 47% of them performing breach assessments at least once per quarter. This low readiness put 53% of Singapore companies at risk − either they have encountered a security incident before, or they didn’t do any checks to assess if they have been breached.
• 37% of Singapore organizations suffered at least one cybersecurity incident in the last 12 months.
• Institutions in the banking, financial services and insurance sector were the most diligent, with 62% of BFSI firms performing regular breach assessments (at least once a quarter), way more than the next highest industry (energy and utilities at 17%).
Top 5 security blind spots in digital transformation
The study reveals the impact digital transformation is having on each organization’s risk posture. As more digital technologies like cloud and mobility are built into businesses, it is opening each organization up to more threats. Data corruption, denial of service attacks, data exfiltration, general malware infection and insider threats emerged as the top security blind spots for Singapore organizations rolling out digital transformation. These five incident types have high levels of business impact and long recovery times.