November 20, 2014 By Jaikumar Vijayan 3 min read

A majority of information technology (IT) managers remain surprisingly confident in their company’s ability to deal with emerging enterprise threats, according to two recent surveys.

In one survey, fielded by Enterprise Management Associates on behalf of software vendor SolarWinds, 84 percent of 312 IT managers surveyed said they considered their organizations to be “very secure” against cyberthreats. This despite the fact that almost the same number said their companies had experienced a significant enterprise security incident within the past year.

Fifteen percent described their controls as “extraordinarily secure” and felt confident placing their companies among the top 10th percentile of organizations with the best enterprise security controls. Thirty-seven percent felt their controls were superior enough to put them in the 20th to 11th percentile.

Extreme Confidence

A similar survey of 250 IT security professionals by ThreatTrack Security revealed the same optimism among technology managers for 2015. Though close to 7 in 10 of those who responded to the survey expected their companies to be targeted by cyberattackers in the next year, a full 94 percent were confident that their ability to deflect such attacks would improve, as well.

In companies with a chief information security officer, the optimism was even greater, with 96 percent expressing confidence about their ability to prevent a data breach at their companies.

“Enterprise security staffers are so confident that 81 percent of survey respondents said they would ‘personally guarantee that their company’s customer data will be safe in 2015,'” ThreatTrack said in a prepared statement announcing the results of its survey.

Misplaced Optimism?

To some, the rosy outlook held by IT managers might appear incongruous in light of all the data breaches that have occurred over the past 12 months, including those at Target, Home Depot, JPMorgan Chase, Community Health Systems, Dairy Queen and UPS Stores.

The breaches have been truly remarkable both in scope and in the level of sophistication used by attackers to steal data. Hundreds of millions of personal and financial records have been compromised in these breaches, and companies are being forced to spend huge amounts of money to address the issues that led to such compromises.

That so many IT managers remain so confident in the face of all that has been going on in recent months suggests a troubling sense of complacency, said Mav Turner, director of SolarWinds security, in a recent interview.

One of the reasons could be that companies are spending more on information security these days; therefore, they assume they are better prepared to deal with threats, Turner said.

Increasing Security Investments

For example, 74 percent of those who participated in the SolarWinds survey said their security budgets had increased over the past year — in some cases by as much as 25 percent. Information security budgets, as a percentage of overall IT budgets, have also steadily ticked upward recently. Close to 9 out of 10 IT managers surveyed felt they had the security resources required to adequately defend their companies against cyberthreats.

Such trends are encouraging, but it’s a mistake for companies to assume they are secure simply because they are spending more on security.

“The overall message we have gotten out of this survey is that companies are putting budget behind security, and they think that is good enough,” Turner said.

What appears to be lacking are best practices and measures for tracking and managing the effectiveness of the security controls that are being implemented, he said. For instance, nearly 40 percent of IT managers in the SolarWinds survey said their organizations either had no defined security best practices or did not follow them. Turner believes this apparent lack of attention to such issues could undermine some of the benefits of new security investments and leave companies more exposed to threats than many security professionals might imagine.

More from

We are moving!

< 1 min read - SecurityIntelligence.com is being sunset, but have no fear!We have a new home for all of your favorite security and X-Force content.Follow us to www.ibm.com/think to maintain access to the stories and news you love, both new and old.Security Intelligence will officially sunset on Friday, March 28, 2025. To access the latest security thought leadership, go here. To access the latest X-Force research, go here.If you are experiencing cybersecurity issues or an incident, contact X-Force® to help:US hotline: 1-888-241-9812 | Global hotline:…

Bypassing Windows Defender Application Control with Loki C2

10 min read - Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.Typical outcomes of a WDAC bypass bug bounty submission:Bypass is fixed; possible bounty awardedBypass is not fixed but instead "mitigated" by being added to the WDAC recommended block list. Likely no bounty awarded but honorable mention is typically givenBypass is not…

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today