
| Characteristic | Share of respondents |
|---|---|
| Organization is falling short addressing cyber risks | 87% |
| We are not investing enough resource (budget, people, technologies, etc.) to address our risks | 31% |
| Security is not always addressed during application development | 30% |
| We are not proactive enough when it comes to our security strategy | 28% |
| Inadequate security training for users (full & part-time employees, contractors, or outsourced users) | 27% |
| Insufficient communications between security team and lines of business | 26% |
| We struggle to find, acquire, and/or retain the technical or professional expertise we need | 20% |
| Addressing risks that have arisen from the new work environment brought on by the pandemic | 20% |
| Lack of security team involvement prior to implementing new technologies | 19% |
| Poor visibility into IT environment | 18% |
| The complexity of our security environment makes it diffcult to retrieve timely, actionable intelligence from our systems | 18% |
| Lack of security team involvement in vendor and 3rd party management | 16% |
| Non-routine updates of incident respone plan | 12% |
| Lack of security during due diligence phase of M&A | 11% |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Loading statistic...
Download
Source
Release date
November 2020
Region
Worldwide
Survey time period
2020
Number of respondents
522 respondents
Special properties
survey respondents are involved in IT and/or corporate/physical security decisions
Method of interview
Online survey
Supplementary notes
The source does not provide information regarding multiple answering options.
Citation formats









