The survey reveals that 88% of respondents felt greater pressure to keep their organization safe
Vectra AI, a cybersecurity leader in detecting and resolving cyber threats for hybrid and multicloud enterprises, has published a new survey on how Italian organizations are addressing modern cyber threats. According to what emerges from the Security Leaders Research Report, conducted with Sapio Research, 24% of those interviewed in Italy have suffered a significant security incident in the last year. The report involved 200 cybersecurity managers working in organizations with more than a thousand employees based in Italy.
In our country, prevention still trumps detection. In fact, the majority of Italian companies believe that preventing hackers is more important than detecting the threats they represent. 78% of security leaders believe that preventing hackers from breaching defenses is more important than detecting their presence once a breach has occurred. For this reason, 52% of Italian companies invest more in prevention tools than in detection solutions, with only 17% ready to do the opposite.
However, 62% of Italian IT managers have experienced a significant security incident that required a response, and 66% believe it is possible or probable that their organization will have suffered a breach in 2021 without it being detected. 40% admit they are unable to detect modern cyber threats, with 27% complaining of poor visibility between different environments (cloud, endpoint, data center, IoT).
"Digital transformation is driving change at an ever-increasing pace, but businesses aren't the only ones innovating – cybercriminals are doing it too. As the threat landscape evolves, traditional defenses are increasingly ineffective, and organizations need modern tools that illuminate blind spots to deliver visibility from cloud to on-premise," he points out Massimiliano Galvagna, Country Manager for Italy of Vectra AI.
As threats have evolved, pressure on security managers has also grown over the past year. 88% reveal they have felt an increased responsibility to keep the organization safe, with 40% feeling close to burnout. 41% also believe their organization could have more security talent to join its team.
The main concern for security managers in Italy remains ransomware, with 60% of those interviewed worried that a similar attack would succeed by stealing data from their organization. 53% fear supply chain attacks and 51% are afraid of not detecting threats due to the increasing number of security alerts. 49% are concerned that cloud adoption increases IT complexity and exposes the company to greater risks.
The survey reveals a widespread belief among security leaders that traditional tools and logic prevent organizations from protecting themselves from modern threats. According to those interviewed, a new approach is needed to detect and stop attacks that overcome the defenses posed by the tools currently in use. The report highlights, in particular, that 88% of security managers have purchased a security solution that has failed on at least one occasion.
49% of respondents believe their board of directors is a decade behind when it comes to security discussions, while 83% say the board's decisions on this matter are influenced by existing relationships with security vendors and traditional IT providers. Another 55% say it is difficult to communicate the value of safety to the board of directors as it is difficult to measure. As a result, security leaders rely on their channel partners more than ever: 93% are grateful to have a channel partner they can trust to guide them in choosing solutions.
From the GDPR to the Network and Information Security Directive, cybersecurity practices and standards are influenced by regulations. The report found that 69% of respondents felt that regulators were well equipped to make cybersecurity decisions, with only 32% believing that more industry input was needed. Additionally, just 22% say lawmakers don't have a deep enough understanding of the practical challenges of writing laws for cybersecurity professionals.
"Faced with a rapidly evolving and increasingly complex security landscape, more often than not, cybercriminals have the advantage. This means organizations must adopt a new approach to security that revolves around detection and response, moving away from prevention strategies," adds Galvagna. “This new approach to security can create the right conditions for effective cyber risk management, but for the entire security industry to embrace this proactive culture, there needs to be greater communication and collaboration between the board of directors and regulators to ensure all parties are on the same page.”






