Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Big win for South African innovation agency - Technology Innovation Agency CEO Titus Mathe

      Big win for South African innovation agency

      9 June 2026
      Eskom Green to build 32GW of renewables by 2040 - Mteto Nyati - Mteto Nyati

      Eskom Green to build 32GW of renewables by 2040

      9 June 2026
      South Africa's EV sales nearly double - but the base is still tiny

      South Africa’s EV sales nearly double – but the base is still tiny

      9 June 2026
      MTN enlists Alipay owner to turn MoMo into a super app

      MTN enlists Alipay owner to turn MoMo into a super app

      9 June 2026
      The clock is ticking on South African banks' biggest advantage

      The clock is ticking on South African banks’ biggest advantage

      9 June 2026
    • World
      Meta declares war on Israeli spyware firm

      Meta declares war on Israeli spyware firm

      8 June 2026
      Meta takes on OpenAI and Anthropic in enterprise AI

      Meta takes on OpenAI and Anthropic in enterprise AI

      4 June 2026
      AI demand sparks 'chipflation' warning

      AI demand sparks ‘chipflation’ warning

      4 June 2026
      Astronomers discover exoplanets with magnetic fields

      Strange winds reveal magnetic fields on distant ‘hot Jupiters’

      2 June 2026
      AI giant Anthropic files for landmark US listing

      AI giant Anthropic files for landmark US listing

      1 June 2026
    • In-depth
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
      Alfa's electric rebel - Alfa Romeo Junior Elettrica Veloce

      Alfa’s electric rebel

      29 April 2026
      Africa switches on as Europe dims the lights

      Africa switches on as Europe dims the lights

      9 April 2026
      The biggest untapped EV market on Earth is hiding in plain sight

      The biggest untapped EV market on Earth is hiding in plain sight

      1 April 2026
    • TCS
      Watts & Wheels S1E5: 'A Bentley of the bush and a car that swims'

      Watts & Wheels S1E5: ‘A Bentley of the bush and a car that swims’

      8 June 2026
      TCS | Charge's R1.8-billion bet on an off-grid EV future - Charge chairman Joubert Roux

      TCS | Charge’s R1.8-billion bet on an off-grid EV future

      18 May 2026
      TCS+ | The Up&Up Group on the hidden cost of AI - Jason Harrison

      TCS+ | The Up&Up Group on the hidden cost of AI

      13 May 2026
      Michael Rossouw

      TCS+ | The retirement decision most South Africans get wrong

      6 May 2026
      TCS | The Cape Town start-up listening for TB with AI - Braden van Breda

      TCS | The Cape Town start-up listening for TB with AI

      4 May 2026
    • Opinion

      Clashing judgments leave South Africa’s crypto law unsettled

      2 June 2026
      The author, Pambos Soteriades

      The trap inside South Africa’s banking MVNO boom

      1 June 2026
      The hidden cost of social media age bans is everyone's privacy - Petrus Potgieter

      The hidden cost of social media age bans is everyone’s privacy

      29 May 2026
      Treasury's crypto crackdown is a betrayal of Mandela's promise - Duncan McLeod

      Treasury’s crypto crackdown is a betrayal of Mandela’s promise

      22 May 2026
      South Africa is sleepwalking into another AI policy failure - Celeste Labuschagne

      South Africa is sleepwalking into another AI policy failure

      20 May 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Top cybersecurity challenge is inadequate identification of key risks

    Top cybersecurity challenge is inadequate identification of key risks

    Promoted | Some 40% of chief security officers say their organisations are not well prepared for today’s rapidly evolving threat landscape, new findings from the largest cybersecurity benchmarking study of global executives show.
    By Skybox Security17 August 2022
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Skybox Security has released new findings from the largest cybersecurity benchmarking study of global executives. The research shows that traditional security approaches that rely on reactive, detect-and-respond measures and tedious manual processes can’t keep pace with the volume, variety and velocity of current threats. As a result, 27% of all executives and 40% of chief security officers (CSOs) say their organisations are not well prepared for today’s rapidly shifting threat landscape.

    For full research citations and in-depth analysis, download the report

    In summary

    • 25% increase in 2021 in material cybersecurity breaches – those generating a large loss, compromising many records or having a significant impact on business operations
    • Top four causes of breaches are avoidable, according to cybersecurity researchers
    • 48% of organisations with no breaches in 2021 were risk-based cybersecurity leaders

    A tipping point

    On average, organisations experienced 15% more cybersecurity incidents in 2021 than in 2020. In addition, “material breaches”— defined as “those generating a large loss, compromising many records or having a significant impact on business operations” — jumped 24.5%.

    The top four causes of the most significant breaches reported by the affected organisations were:

    • Human error
    • Misconfigurations
    • Poor maintenance/lack of cyber hygiene
    • Unknown assets

    “What’s notable about this list is that all of these conditions result from mistakes or manual processes inside organisations — which means they are all, in principle, avoidable,” said Ran Abramson, threat intelligence analyst at Skybox Research Lab. “The clear implication is that, however pernicious external threats have become, cybersecurity teams still have the power to repel them. And that’s the good news: with the right practices and tools – including automation to maximise efficiency and get the most out of limited staff – breaches can be prevented.”

    Risk-based approach prevents breaches

    The study surveyed executives and analysed the cybersecurity investments, practices and performance of 1 200 companies and public-sector organisations in 16 countries and a wide range of industries. It’s the largest cybersecurity benchmarking study with C-level decision-makers ever undertaken. The research findings uncover that conventional cybersecurity approaches are falling short, and organisations that shift to modern, risk-based strategies are more successful in preventing breaches.

    Source: Skybox Security

    Though organisations, on average, saw a significant uptick in incidents and material breaches in the past two years, a distinct subset had few or no breaches at all. So, what sets these exceptional organisations apart? The researchers found that firms with fewer breaches were different from the rest of the pack in two fundamental respects:

    1. Organisations that prevented breaches ranked higher in cybersecurity progress as measured by the NIST framework. The framework, developed by the National Institute of Standards and Technology, provides guidelines that help companies evaluate and improve their cybersecurity maturity in activities such as detecting and responding to incidents.
    2. Beyond the NIST framework, organisations with no breaches took what the researchers call “a risk-based approach” to cybersecurity. Forty-eight percent of organisations with no breaches in 2021 had implemented risk-based cybersecurity management strategies. They also performed better in key cybersecurity metrics: 46% were top performers in time to respond to a breach, and 50% were top performers in time to respond.

    Looking more closely at the ingredients of a risk-based approach and the specific practices that distinguish risk-orientated organisations from their less proficient peers, the benchmark study found that risk-based leaders excelled in key areas beyond the NIST framework, including:

    • Attack surface visibility and context
    • Attack simulation
    • Exposure analysis
    • Risk scoring
    • Vulnerability assessments
    • Research (threat intelligence)
    • Technology assessments and consolidation

    “You must take a risk-based approach because you can’t secure everything 100%. There are a lot of questions to ask: what is the business of the business? What does the risk profile look like? What are the threats? What are the implications? And what is the governance process an organisation goes through to make risk-based decisions?” said Gary McAlum, board director at the National Cybersecurity Center.

    The business impact of successful risk-based security management — versus the old status-quo, detect-and-respond approach — is measured in this research. By preventing or mitigating breaches, risk-based methods could have saved companies millions annually and prevent untold damage to reputation, customer trust, company morale and market standing.

    “The cybersecurity industry is witnessing a paradigm shift in cyber risk. To prevent breaches, chief information security officers must make a strategic shift – from the traditional volume play of identifying vulnerabilities and merely adhering to cybersecurity frameworks to taking a strategic, risk-based view of reducing actual exposure,” said Gidi Cohen, CEO and founder at Skybox Security.

    “At the board level, leaders want to understand their risk profile rather than how many vulnerabilities were patched each month. CISOs need to validate and report on how they’re taking measurable, proactive steps to reduce risk systematically and reduce the financial impact a breach could have on their company.”

    For full research citations and in-depth analysis, download the report.

    About Skybox Security
    Over 500 of the largest and most security-conscious enterprises in the world rely on Skybox for the insights and assurance required to stay ahead of dynamically changing attack surfaces. Our Security Posture Management Platform delivers complete visibility, analytics and automation to quickly map, prioritise and remediate vulnerabilities across your organisation. The vendor-agnostic solution intelligently optimises security policies, actions and change processes across all corporate networks and cloud environments. With Skybox, security teams can now focus on the most strategic business initiatives while ensuring enterprises remain protected.

    • This promoted content was paid for by the party concerned
    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Gidi Cohen Skybox Skybox Research Lab Skybox Security
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleAcrobat Sign and Microsoft accelerate digital transformation
    Next Article Chip makers are flashing a big warning for the global economy

    Related Posts

    4 tips for exposure management of your business applications - Skybox Security

    4 tips for exposure management of your business applications

    19 February 2025
    Network professionals lose nearly half their week to manual tasks that could be automated - Skybox Security report

    Network professionals lose nearly half their week to manual tasks that could be automated

    3 December 2024

    Skybox: half of firms fear security incidents due to siloed network and security teams

    17 October 2024
    Add A Comment

    Comments are closed.

    Company News
    Avert IT Distribution, AnyDesk create growth opportunities for African IT partners

    Avert IT Distribution, AnyDesk create growth opportunities for African IT partners

    9 June 2026
    South Africa's cloud reckoning: have your say

    South Africa’s cloud reckoning: have your say

    9 June 2026
    South Africa's operators solved fintech. Digital identity is next - Contactable

    South Africa’s operators solved fintech. Digital identity is next

    9 June 2026
    Opinion

    Clashing judgments leave South Africa’s crypto law unsettled

    2 June 2026
    The author, Pambos Soteriades

    The trap inside South Africa’s banking MVNO boom

    1 June 2026
    The hidden cost of social media age bans is everyone's privacy - Petrus Potgieter

    The hidden cost of social media age bans is everyone’s privacy

    29 May 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Big win for South African innovation agency - Technology Innovation Agency CEO Titus Mathe

    Big win for South African innovation agency

    9 June 2026
    Eskom Green to build 32GW of renewables by 2040 - Mteto Nyati - Mteto Nyati

    Eskom Green to build 32GW of renewables by 2040

    9 June 2026
    Avert IT Distribution, AnyDesk create growth opportunities for African IT partners

    Avert IT Distribution, AnyDesk create growth opportunities for African IT partners

    9 June 2026
    South Africa's cloud reckoning: have your say

    South Africa’s cloud reckoning: have your say

    9 June 2026
    © 2009 - 2026 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}