The number of security incidents continue to soar
Globally, the total number of security incidents detected by survey respondents
climbed to €32 billion this year, an increase of 48% over 2013.
75% of all Belgian respondents indicate to have encountered a security
incident on a monthly basis.
Security incidents happen on all IT layers (application, data, system and
network) but also on the people layer as 15% of the Belgian respondents have
encountered social engineering attacks against their employees
How can your organisation change the game?
The case of Belgium
Cyber risks will never be completely
eliminated. Today, organisations must
remain vigilant and agile in the face of a
continually evolving threat landscape.
How is Belgium playing the game?
Five actions to adapt
More than 50% of the Belgian respondents
indicated to have lost intellectual property or
encountered the compromise or damage of
customer, employee and internal records.
This figure could be explained by the fact
that, in general, less than 50% of the
respondents have encrypted their data
stores, whereas only 37% reported to use
a data loss prevention solution.
At a worldwide level, financial losses
associated with the security incidents range
from €75.000 to €7.500.000 for 60% of the
organisations and are as such higher than the
European average.
A simple explanation for these important
financial losses is the fact that only
37% of the organisations have a cyberinsurance.
At a European level, the majority of
financial losses include the loss of customer
business followed by legal expenditures. For
Belgium however, the key cost factors are
investigations and forensics.
20% of the Belgian respondents do not
know the number of security incidents on a
yearly basis, while 40% has no insight on the
financial impact of their security incidents.
The majority, about 70%, of the respondents
specified to have classic prevention solutions,
such as firewalls, in place. In contrast, no
more than 40% of the respondents indicated
to use more advanced safeguards like
malicious code-detection tools.
your organisation’s security investments
Further improve. Strengthen collaboration.
The type of respondents would account
for the lacking insight in security
incidents. However, another explanation
could be that organisations have an
ineffective security strategy and practice
in place.
Almost half of the respondents report
having a SIEM solution and securityevent-correlation tools in place.
Moreover we could conclude that not all
organisations employ analytics to model
and identify security incidents.
If you are not connected to
the conversations, you are
going to be lost. In today’s
threat environment,
there is no reason for not
Hayes of CenterPoint
• Belgian organisations, in contrast to European ones, do not plan a
formal collaboration with industry peers to address security risks,
fearing disabuse from involved parties as attention would be
drawn to their potential weaknesses.
• The limited cross-organisation involvement leads to a
decentralised approach for addressing security incidents, postand pre-incident.
• Outsourcing might be a solution to profit from scale advantages on
security expenditures. However, only 29% of Belgian organisations
(50% at European level) indicated conducting compliance audits
of third parties that process personal identifiable information of
employees and customers.