These concerning findings were just some of the insights gleaned from Sophos’ latest commissioned research, The State of Cybersecurity 2023: The Business Impact of Adversaries, which was conducted by tech market research company Vanson Bourne at the beginning of this year.
The survey posed a series of cybersecurity-related questions to a pool of around 3,000 leaders responsible for IT and cybersecurity efforts across small-, medium-, and large-sized companies over 14 different countries.
Breaking down the fact that 93% of respondents are finding threat hunting and resolution difficult, the respondents rated at least one of the following as “challenging”:
- Identifying the root cause of the incident (75% find challenging)
- Identifying signals from noise (71%)
- Prioritising which signals/alerts to investigate (71%)
- Getting sufficient data to properly identify a malicious or benign signal (71%)
- Remediating malicious alerts or incidents in a timely manner (71%)
- Keeping accurate records of investigations (68%)
Further, the research uncovered that companies at both ends of the spectrum — smaller companies with less than $10 million USD in annual revenue, and large companies with revenue over $5 billion — are the most likely orgs to have difficulties with security operations tasks.
Sophos points to a number of reasons that underpin why, exactly, firms are finding the threat hunting process arduous, including: the shortage of in-house cybersecurity expertise and skills prompted by the current cybersecurity skills gap; an overwhelming volume of alerts coming through; and too much time being spent on incident response, rendering firms unable to keep up with the ongoing threat and reality of security attacks and issues.
Speaking of which, Sophos highlighted that the rate at which adversaries are acting is faster than organisations can keep up with. “The study revealed that today’s reality is a two-speed cybersecurity system with adversaries and defenders moving at different speeds,” wrote the study’s authors. “Through automation, cybercrime ‘as-a-service’ models, stealthy impersonation, and adaptation, adversaries are accelerating and can now execute a wide range of sophisticated attacks at scale.”
Recommended
- Scot-Secure 2023 | Delivering Impactful Cybersecurity Workshops
- Branson’s Rocket Company Virgin Orbit Files for Bankruptcy
- ICO Fines TikTok £12.7M for Misuse of Children’s Data
The pressure of potential threats is felt deeply, according to the research’s findings. 57% of respondents said that they lose sleep thinking about the impact of being hit by a cyber-attack, while 52% of respondents said they believe cyber-threats are now too advanced for their organisation to deal with on their own.
In terms of how potential threats are ranked, the respondents said the following are a top concern:
- Data exfiltration (41%)
- Phishing (40%)
- Ransomware (35%)
- Cyber extortion (33%)
- Denial of Service attacks (32%)
- Business email compromise (31%)
- Active adversaries (30%)
- Mobile malware (30%)
- Cryptominers (22%)
- Wipers (16%)
So that firms can effectively move ahead of adversaries, the report lays out the following suggestions: “Firstly, organizations need to set up an incident response process that can scale, achieved through minimizing the attack surface and the volume of alerts that require attention, and optimizing response time by leveraging specialist services.”
Secondly, “they need to implement adaptive defenses that automatically adjust to the situation. This allows them to slow down adversaries and buy defenders time to respond.”
Lastly, “they also need to set up a virtuous cycle that combines technology and human expertise to turbo-charge defenses, enabling an increase in speed, efficacy, and impact. Together they accelerate the defender flywheel, enabling them to pull ahead.”
However, as the statistics show, the closing of the cybersecurity skills gap would also help to alleviate the pressure in the ongoing race between defenders and adversaries.
The full report can be read here.





