Site navigation

70% of UK Security Professionals Are Working Over Weekends

Graham Turner

,

cybersecurity burnout
Bitdefender’s 2024 Cybersecurity Assessment Report offers some key data and insights around elevated security challenges businesses are currently facing – largely being heralded via cloud and AI.

The report highlights the widespread adoption of cloud technologies and the significant concerns organisations have regarding their security.

The report is based on data parsed from a survey conducted by Censuswide, which included 1,200 IT professionals from diverse sectors in France, Germany, Italy, Singapore, the UK, and the US, working in organisations with over 1,000 employees.

Cloud security concerns

Cloud computing’s constant availability and global accessibility present significant security challenges.

The survey revealed that 44% of respondents identified data breaches or leaks as a top concern, 43% expressed worries about unauthorised access to cloud services, and 42% were troubled by misconfigured cloud storage.

Notably, nearly half (47%) of organisations rely on native security offerings from their cloud service providers, assuming they are sufficient. However, these native tools often fall short as threats evolve, necessitating more advanced solutions that can detect and correlate data across multiple sources.

Human error and configuration issues

Human error remains a significant risk factor, with 32% of respondents concerned about it.

Other related concerns include 39% worrying about Identity and Access Management (IAM) and 34% concerned about misconfigurations.

The report emphasises that tools like Cloud Security Posture Management (CSPM) and Cloud Infrastructure Entitlement Management (CIEM) are essential for detecting misconfigurations and monitoring data access privileges, respectively.

The role of AI in cybersecurity

AI’s integration into cybersecurity strategies is a double-edged sword, according to the report.

While it offers benefits for decision-making and problem-solving, it also enhances the capabilities of cybercriminals. AI-driven tactics are now being used to craft sophisticated phishing emails and generate malicious content that bypasses conventional security measures.

The survey found that 96% of professionals view AI-assisted social engineering attacks as a concern and 41% consider it a very significant threat.

Despite this, 94% of professionals are confident in their organisation’s ability to respond to security threats, although only 37% feel very confident that their tools and strategies are sufficient.

AI is also being used to orchestrate narrative attacks or misinformation campaigns.

Nearly all (97%) of IT/security professionals consider the manipulation or creation of deceptive content a significant threat, with 36% viewing it as very significant.

Deepfakes, which can make fraudulent claims appear authentic, are particularly concerning. Although 74% of respondents are confident in their ability to identify deepfakes, 21% are not confident, and 5% are unsure.

Staffing challenges

The cybersecurity industry faces a chronic shortage of skilled professionals, with an estimated shortfall of nearly 4 million. This shortage exacerbates workload and burnout among existing staff, with over 70% of security professionals working weekends and 64% considering new job opportunities within the next year.

To address these challenges, the report states that organisations urgently need solutions that alleviate the burden on their security teams to help avoid burnout.

Such measures enhance the work environmentand improve the overall efficacy of security operations, ensuring that critical threats are not overlooked.

How can organisations combat these threats?

According to Bitdefender, a defense-in-depth strategy is essential.

This starts with establishing a secure foundation for cloud environments using Cloud Security Posture Management (CSPM) tools. CSPM automates the identification and remediation of risks from misconfigured cloud resources, preventing potential breaches and creating a robust baseline for cloud security.


Recommended reading


As organisations increasingly adopt cloud technologies for efficiency and agility, they often outpace the implementation of adequate security measures. This leaves significant vulnerabilities: 44% of organisations worry about data breaches, 43% about unauthorised access, and 42% about misconfigured cloud storage.

Building on this foundation, organisations should integrate Extended Detection and Response (XDR) and Managed Detection and Response (MDR) to strengthen defenses. XDR provides holistic visibility and correlation across all data points, crucial for detecting abnormal behaviors and sophisticated threats like zero-day exploits and AI-specific attacks. Advanced analytics and machine learning enable XDR to predict and prevent incidents before they escalate.

MDR offers 24/7 monitoring and threat hunting, ensuring continuous oversight and expertise to navigate evolving threat landscapes. In the event of a security breach, MDR’s rapid incident response minimises downtime and restores operations swiftly.

Together, CSPM, XDR, and MDR form a multi-layered security strategy that allows organisations to proactively identify and mitigate threats, securing their infrastructure against the evolving nature of cyber threats.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data