In 2023, organisations exhibited a heightened reliance on their IT systems, reaching 68% that could survive less than a day without them. This marks a significant leap from the 46% recorded in 2017, underscoring a remarkable surge in technology dependence.
The latest Data Health Check from Databarracks delves into the growing significance of cyber insurance, examining how businesses shield themselves from the fallout of cyber breaches. With ransomware causing widespread financial havoc, there are serious implications for IT professionals in 2023.
Ransomware attacks surged compared to 2022, leaving only a quarter “extremely confident” in their response capabilities.
Over 50% faced cyber-attacks last year, and three organisations reported over 100 attacks. IT security budgets are on the rise, with almost half reporting increases.
Finally, managing supply chain security remains challenging, with just over half of organisations actively checking for vulnerabilities.
Despite the challenges posed by the cyber surge, the Data Health Check 2023 highlights positive shifts. More organisations are adopting cyber insurance, emphasising cybersecurity training, and proactively defending against threats. As cyber-attacks persist, robust security measures ensure a swift response, demonstrating organisational readiness for evolving digital challenges.
Databarracks managing director, James Watts, commented: “Organisations are finding themselves in an increasingly difficult position. On one hand, the risk of IT downtime is significantly increasing due to cyber causes. On the other hand, digital transformation efforts have led to a greater dependence on technology.
“Technology is so fundamental to the way organisations now function that the effect of IT downtime is amplified.
“So, what can businesses do to become more resilient? They should start by addressing the cyber threat and developing defences and response capability. The greater the potential impact of an outage, the more vital it is to react and respond as early as possible.
“Next, improve recovery methods to deliver the reduced Recovery Time Objective demanded by the organisation.
“We also recommend assessing what can be done to keep the business operational without IT. There are fewer manual tasks now that can keep organisations productive in the event of a systems failure or attack. As processes have been automated by technology, the old manual methods are often forgotten. These are never as fast or efficient, but they can keep the business operational at a minimum level.
“This is one reason why we would always recommend including manual workarounds in DR plans. As the incidence of cyber-attacks continues to rise, this is more important than ever.
“In Business Continuity, we talk about the Maximum Tolerable Period of Disruption. This is the period after which the viability of the organisation would be threatened. Each organisation will have a different MTPD and, as we have seen from our research, it is decreasing over time.
Recommended
- What’s the Most Overlooked Aspect of Organisational Security?
- Will New Sustainable Tech Become a Major Cyber-attack Vector?
- What’s the State of Cybersecurity Automation in 2023?
“MTPD is a central figure to use in BC planning. Knowing your MTPD will determine the RTO your Disaster Recovery systems need to deliver and how long you can afford to wait before declaring an incident and invoking DR to kick-off recovery. Your MTPD should be non-negotiable, and non-adjustable. This is where testing really comes in because it gives your team an opportunity to practice that recovery process – not just what to recover, but when.
“Determine your MTPD – and make it a hard line. Once you allow wiggle room, you will miss your recovery objectives. Ultimately, deciding on what outcome is unacceptable to you will help you put effective boundaries in place.”





