- Security TWENTY
- Women in Security Awards
Cyber attack is again the top threat perceived by businesses. That’s according to research published by the Business Continuity Institute (BCI) in association with BSI (British Standards Institution).
Most, 88pc of organisations are either ‘extremely concerned’ or ‘concerned’ about the possibility of a cyber attack. The threat of a data breach remains in second place (81 percent), while unplanned IT and telecom outage stays in third place (80 percent).
For the first time in the study’s six years, the threat of uncertainty around the introduction of new laws and regulations has entered the list of top ten business continuity concerns in the Horizon Scan Report.
These external events underscore the interconnected nature of risks and demonstrate the need for businesses to take them into account and plan accordingly.
This year’s global top ten threats to business continuity are:
Cyber attack – static
Data breach – static
Unplanned IT and telecom outages – static
Security incident – up one
Adverse weather – up three
Interruption to utility supply – static
Act of terrorism – down three
Supply chain disruption – down 1
Availability of key skills – static
New laws or regulations – new entry
For the first time, the survey also asked which disruptions respondents had experienced during the previous year; to understand what lies behind the worry. The results showed that nine of the top ten concerns also appeared in the top ten list of disruptions, with transport network disruption appearing at the expense of act of terrorism. Unplanned IT and telecom outages came in at number one, followed by interruption to utility supply and then cyber attack. Data breach came in at eighth place.
With the top four threats all showing an increase in concern, it is worrying say the report authors that about one in seven, 14 percent of respondents will experience business continuity budget cuts over the next year.
Despite growing fears over the resilience of their organisations, the report records another fall in use of long-term trend analysis to assess and understand threats, down 1 percent to 69 percent this year. Of those carrying out trend analysis, around a third of organizations (32 percent) do not use the results to inform their business continuity management.
David Thorp, Executive Director at the Business Continuity Institute, said: “Given the diversity of the threats out there, it is absolutely essential to adopt agile and dynamic responses. Planning to recover from a data breach is very different from planning for the aftermath of a terrorist attack, and, as this year’s report highlights, the risk spectrum can be very broad. Malicious internet actors, political shake-ups, and climate change are all amongst the main worries for societies around the world.
“As always, the key takeaway should be that with challenges come opportunities. Change does not have to mean less favourable environments, but the landscape may be different. As organizations venture into uncharted territory now is the time to identify and undertake the measures that will increase resilience within your organization by ensuring that effective business continuity planning is in place.”
And Howard Kerr, Chief Executive at BSI, said 2016 continued to see high profile businesses affected by cyber attack and disruption; so it was not surprising to see it remain the top threat to business. “However, we remain concerned to see that businesses are still not fully utilising the information available to them to identify and remedy weaknesses in their organizational resilience.
“Ultimately, organizations must recognize that, while there is risk, and plenty of it, there is also opportunity. Taking advantage of this means that leaders can steer their businesses to not just survive, but thrive.”
Globally there were some variations to the top three threats. In Belgium, act of terrorism was in third; in central and Latin America, new laws or regulations featured in third place; and in sub-Saharan Africa, exchange rate volatility was third. And as for actual disruptions, adverse weather appeared in second place throughout North America, Asia and Australasia; while the loss of key employee featured in the top three throughout the Middle East and North Africa, Central and Latin America and the UK.