Even Regulation Can't Make Some Organizations Invest More In Cybersecurity
A recent study from Nexia International and CohnReznick found that 20 percent of organizations required by regulation to maintain some form of cyber programming lack a cyber program.
December 12, 2017 at 10:00 AM
6 minute read
Despite a year full of devastating, massive scale breaches, many organizations still lack the cybersecurity infrastructure and training needed to adequately protect them from cyber attacks. In many cases, even the threat of regulatory scrutiny may not be enough to encourage organizations to invest more heavily in cybersecurity resources.
A recent survey coauthored by consulting group Nexia International and professional services firm CohnReznick polled more than 350 organizations and found that 46 percent do not have a formal cybersecurity program; an additional 20 percent of respondents lack a cybersecurity program even when government, industry or consumer regulations require them to have one.
Survey respondents cited time and budgets as their biggest obstacles to implementing organizational cybersecurity: Fifty-one percent noted that lack of time dedicated to cybersecurity issues was an “extreme” challenge for organizations, while an additional 45 percent said the same of limited budgets.
That lack of investment shows up in the kinds of safety precautions many organizations have failed to take. Likewise, many have failed to understand their own cybersecurity vulnerabilities. Twenty percent have not conducted a cybersecurity assessment at all. Only 25 percent offer cybersecurity training to their employees on an annual basis.
Cohn Reznick partner David Rubin found the lack of investment surprising, especially given the current cybersecurity landscape. He noted that regulatory concerns seem to be the biggest incentive to bolster resource investments to cybersecurity.
“The driver of cyber-investment is still regulation rather than data risk management,” he said.
Both regulators and third-party vendors seem to be stepping up their scrutiny of organizational cybersecurity—Rubin sees local cybersecurity regulations and vendor cybersecurity contractual stipulations on the rise. These still may not be enough to get some companies to invest more heavily in their cybersecurity infrastructures and programs.
“It really becomes still a question of how many companies will be willing take the risk that they won't get hit even with those regulations. It's going to take, I think, some companies seeing or industries seeing that regulations are being enforced, or they're losing business for them to take it seriously,” Rubin said.
For attorneys looking to help clients who've shirked their cybersecurity investments, Rubin suggested that having a well-oiled response plan and a gentle push to do more preventative work can help.
“What I do feel they can do is educate their clients. The focus should be to understand their client vulnerabilities, the impact of those vulnerabilities, and what things they can have their clients to do prevent, and get their clients ready in the event that they need to respond so that it's almost a muscle reflex in terms of what they do and how they respond to an incident,” he said.
That preventative work should involve some form of education, Rubin added. “The survey clearly indicated to use that there's not enough training going on,” he said. “Training is a very, very important component to an effective cyber-component. Policies that people are trained on are an effective part of a cyber program,” he said.
Despite a year full of devastating, massive scale breaches, many organizations still lack the cybersecurity infrastructure and training needed to adequately protect them from cyber attacks. In many cases, even the threat of regulatory scrutiny may not be enough to encourage organizations to invest more heavily in cybersecurity resources.
A recent survey coauthored by consulting group Nexia International and professional services firm CohnReznick polled more than 350 organizations and found that 46 percent do not have a formal cybersecurity program; an additional 20 percent of respondents lack a cybersecurity program even when government, industry or consumer regulations require them to have one.
Survey respondents cited time and budgets as their biggest obstacles to implementing organizational cybersecurity: Fifty-one percent noted that lack of time dedicated to cybersecurity issues was an “extreme” challenge for organizations, while an additional 45 percent said the same of limited budgets.
That lack of investment shows up in the kinds of safety precautions many organizations have failed to take. Likewise, many have failed to understand their own cybersecurity vulnerabilities. Twenty percent have not conducted a cybersecurity assessment at all. Only 25 percent offer cybersecurity training to their employees on an annual basis.
Cohn Reznick partner David Rubin found the lack of investment surprising, especially given the current cybersecurity landscape. He noted that regulatory concerns seem to be the biggest incentive to bolster resource investments to cybersecurity.
“The driver of cyber-investment is still regulation rather than data risk management,” he said.
Both regulators and third-party vendors seem to be stepping up their scrutiny of organizational cybersecurity—Rubin sees local cybersecurity regulations and vendor cybersecurity contractual stipulations on the rise. These still may not be enough to get some companies to invest more heavily in their cybersecurity infrastructures and programs.
“It really becomes still a question of how many companies will be willing take the risk that they won't get hit even with those regulations. It's going to take, I think, some companies seeing or industries seeing that regulations are being enforced, or they're losing business for them to take it seriously,” Rubin said.
For attorneys looking to help clients who've shirked their cybersecurity investments, Rubin suggested that having a well-oiled response plan and a gentle push to do more preventative work can help.
“What I do feel they can do is educate their clients. The focus should be to understand their client vulnerabilities, the impact of those vulnerabilities, and what things they can have their clients to do prevent, and get their clients ready in the event that they need to respond so that it's almost a muscle reflex in terms of what they do and how they respond to an incident,” he said.
That preventative work should involve some form of education, Rubin added. “The survey clearly indicated to use that there's not enough training going on,” he said. “Training is a very, very important component to an effective cyber-component. Policies that people are trained on are an effective part of a cyber program,” he said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1ClaimClam Wanted to Boost Class Action Claims Rates. But Judges and Attorneys Fought Back
- 2'We Will Sue ... Immediately': AG Bonta Says He's Ready to Spend $25M Battling Trump
- 311 Red State AGs Demand Damages in Antitrust Lawsuit Shaming ESG Climate Investors
- 4In-House Moves of Month: Discover Fills Awkward CLO Opening, Allegion GC Lasts Just 3 Months
- 5Delaware Court Holds Stance on Musk's $55.8B Pay Rescission, Awards Shareholder Counsel $345M
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250