One fifth of organisations across the Asia Pacific were hit by at least seven cyber attacks in the past 12 months, according to new research from Trend Micro.
Trend Micro’s Cyber Risk Index found 18% of APAC organisations suffered seven or more attacks infiltrating their networks or systems over the past year, and the majority (81%) suffered one or more attacks.
Over two thirds (76%) of surveyed organisations in APAC expect that such attacks are somewhat to very likely to be successful in the coming 12 months.
Trend Micro says this is the third CRI study and shows a significant increase in cyber risk in 2020.
“The CRI is fast becoming an indispensable resource for CISOs looking to assess their readiness to respond to cyber attacks,” says Dhanya Thakkar, vice president, Asia Pacific, Middle East, and Africa.
“This year we have added data from Europe and APAC to provide truly global insight. It will help organisations across the world find better ways to cut through complexity, mitigate insider threats and skills shortages, and enhance cloud security to minimise cyber risk and drive post-pandemic success.”
The CRI is based on a numerical scale of -10 to 10, with -10 representing the highest level of risk. The current global index stands at -0.41, representing elevated risk. Although risk is lowest in APAC (-0.02) due to perceived greater cyber preparedness, all organisations show an elevated risk as all regions exhibit approximately the same level of risk.
Responding organisations in APAC claimed their top cyber-threat risks are:
2. Man-in-the-middle attack
4. Phishing and social engineering
Across APAC, organisations key concerns are:
1. Customer turnover
2. Stolen or damaged equipment
3. Lost intellectual property (including trade secrets)
4. Disruption or damages to critical infrastructure
5. Productivity decline
“Trend Micro’s CRI is a useful tool for companies to better understand their cyber risk,” says Dr. Larry Ponemon, CEO for Ponemon Institute.
“Expanding this to be a global resource in 2020 opens the door for more organisations to leverage this useful information,” he says.
“Businesses of all sizes and industries across the globe can use the CRI to improve their protection strategy and better prepare their cybersecurity posture in the year to come.”
There were differences between certain regions as well. In the US respondents were unique in listing the cost of outside consultants as a top negative consequence of attack, while in APAC damage to critical infrastructure concerned organisations.
The top APAC security risks within IT infrastructure were highlighted as:
1. Organisational misalignment and complexity
2. Cloud computing infrastructure and providers
3. Shortage of qualified personnel
4. Negligent insiders
5. Malicious insiders