The majority (59%) of mid-sized companies are reporting less confidence in detecting cyber threats compared to just over half of enterprises (52%), according to new research by Threat Detection & Response provider.
Solid protection against cyber threats is an urgent priority for firms, with an increasing number of businesses grappling with ransomware attacks. In fact, e2e-assure’s research shows that the vast majority (75%) of CISOs and cyber security decision-makers have experienced a cyber-attack, and the frequency of breaches doesn’t appear to be slowing down. In fact, according to recent research by GOV.UK, a fifth of businesses said they had experienced breaches or attacks at least once a week in the last 12 months.
Despite mid-sized companies being the most likely to outsource their cyber operations (57%), the research shows that they fare the worst in comparison to enterprises. 47% report that their provider is underperforming compared with 37% of enterprises. Perhaps as a result, only 22% of mid-sized firms believe they are resilient.
62% of mid-market companies said they don’t have flexible contracts that can adapt the scope of the original contract signing, compared with 46% of enterprises. A further 66% of mid-sized companies said they did not have transparent pricing from their provider, compared with 44% of large organisations.
The survey also found services are less likely to be personalised for mid-sized organisations, with 57% of these less likely to have client-centric delivery teams compared with 50% of enterprises. Over half (58%) of mid-sized organisations said they were not benefitting from tooling than can be tailored to their specific business needs, compared with 50% of enterprises.
This means mid-sized organisations are ultimately not benefiting from the same degree of specialist expertise as enterprise organisations, putting them at a potential higher risk of compromise.
Rob Demain, CEO of e2e-assure, said:
With mid-sized organisations the most prominent outsourcers in our study, but with the majority stating that they’re unhappy with their current support, it’s clear that there is an integral need for a shift in both the service and commercial offerings from cyber security providers to better support mid-sized companies to protect themselves against breaches.
Rob Demain, CEO of e2e-assure
However, with nearly a third (29%) of mid-sized companies stating that they will be looking for an outsourced provider when they next procure their security operations, it’s clear there is an appetite from cyber security professionals to pass more responsibility on.
With the findings highlighting the need for a shift in the service offerings from providers, five key themes emerged for cyber defence rejuvenation in 2024:
- Providers will need to prove their value
- Security teams will relinquish more control to trusted providers
- Contracts will need to be more commercially flexible
- Service and tooling flexibility is a priority for organisations
- Quality cyber defence needs to become more accessible to organisations of all sizes
To read the full report which also reveals the rise of hybrid cyber security models, the key frustrations of cyber security teams and advice on how they can stay ahead of cyber threats, please visit this link: https://info.e2e-assure.com/redefining-soc/signup/
Joanne is the editor for Workplace Wellbeing Professional and has a keen interest in promoting the safety and wellbeing of the global workforce. After earning a bachelor's degree in English literature and media studies, she taught English in China and Vietnam for two years. Before joining Work Well Pro, Joanne worked as a marketing coordinator for luxury property, where her responsibilities included blog writing, photography, and video creation.