November 20, 2014 By Jaikumar Vijayan 3 min read

A majority of information technology (IT) managers remain surprisingly confident in their company’s ability to deal with emerging enterprise threats, according to two recent surveys.

In one survey, fielded by Enterprise Management Associates on behalf of software vendor SolarWinds, 84 percent of 312 IT managers surveyed said they considered their organizations to be “very secure” against cyberthreats. This despite the fact that almost the same number said their companies had experienced a significant enterprise security incident within the past year.

Fifteen percent described their controls as “extraordinarily secure” and felt confident placing their companies among the top 10th percentile of organizations with the best enterprise security controls. Thirty-seven percent felt their controls were superior enough to put them in the 20th to 11th percentile.

Extreme Confidence

A similar survey of 250 IT security professionals by ThreatTrack Security revealed the same optimism among technology managers for 2015. Though close to 7 in 10 of those who responded to the survey expected their companies to be targeted by cyberattackers in the next year, a full 94 percent were confident that their ability to deflect such attacks would improve, as well.

In companies with a chief information security officer, the optimism was even greater, with 96 percent expressing confidence about their ability to prevent a data breach at their companies.

“Enterprise security staffers are so confident that 81 percent of survey respondents said they would ‘personally guarantee that their company’s customer data will be safe in 2015,'” ThreatTrack said in a prepared statement announcing the results of its survey.

Misplaced Optimism?

To some, the rosy outlook held by IT managers might appear incongruous in light of all the data breaches that have occurred over the past 12 months, including those at Target, Home Depot, JPMorgan Chase, Community Health Systems, Dairy Queen and UPS Stores.

The breaches have been truly remarkable both in scope and in the level of sophistication used by attackers to steal data. Hundreds of millions of personal and financial records have been compromised in these breaches, and companies are being forced to spend huge amounts of money to address the issues that led to such compromises.

That so many IT managers remain so confident in the face of all that has been going on in recent months suggests a troubling sense of complacency, said Mav Turner, director of SolarWinds security, in a recent interview.

One of the reasons could be that companies are spending more on information security these days; therefore, they assume they are better prepared to deal with threats, Turner said.

Increasing Security Investments

For example, 74 percent of those who participated in the SolarWinds survey said their security budgets had increased over the past year — in some cases by as much as 25 percent. Information security budgets, as a percentage of overall IT budgets, have also steadily ticked upward recently. Close to 9 out of 10 IT managers surveyed felt they had the security resources required to adequately defend their companies against cyberthreats.

Such trends are encouraging, but it’s a mistake for companies to assume they are secure simply because they are spending more on security.

“The overall message we have gotten out of this survey is that companies are putting budget behind security, and they think that is good enough,” Turner said.

What appears to be lacking are best practices and measures for tracking and managing the effectiveness of the security controls that are being implemented, he said. For instance, nearly 40 percent of IT managers in the SolarWinds survey said their organizations either had no defined security best practices or did not follow them. Turner believes this apparent lack of attention to such issues could undermine some of the benefits of new security investments and leave companies more exposed to threats than many security professionals might imagine.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today