
| Characteristic | Yes, we have | No, but we plan to | No, we have not | I do not know |
|---|---|---|---|---|
| Technical | - | - | - | - |
| Improve security of our computers, devices, system | 83% | 8% | 3% | 6% |
| Improve data protection capabilities | 78% | 11% | 5% | 6% |
| Conduct penetration testing (e.g. simulated attack) | 53% | 13% | 21% | 13% |
| Policy and Procedure | - | - | - | - |
| Implement awareness training for employees | 66% | 18% | 11% | 5% |
| Strengthen cybersecurity policies and procedures | 62% | 19% | 10% | 9% |
| Review/update our cyber incident response plan | 47% | 23% | 16% | 14% |
| Risk Assessment and Preparation | - | - | - | - |
| Assess cyber risk/controls against cybersec. standards | 63% | 14% | 14% | 9% |
| Identify external services, resources, experts to support | 45% | 20% | 20% | 15% |
| Risk assessment of our vendors/supply chain | 33% | 18% | 31% | 18% |
| Tabletop exercises and/or training for management | 29% | 27% | 30% | 14% |
| Model potential cyber loss scenarios | 28% | 21% | 35% | 16% |
| Benchmark cyber risks against peers/other organizations | 28% | 15% | 40% | 17% |
Download
Sources
Release date
September 2019
Region
Worldwide
Survey time period
February and March 2019
Number of respondents
1,118 respondents
Special properties
senior executives
Supplementary notes
Original question: "Please indicate whether your organization has taken the specific actions listed below within the past 12 to 24 months."
Values may not add up to 100 percent due to rounding.
Citation formats









