For the First Time in Five Years, External Threats Overshadow Internal Threats as the Greatest Cybersecurity Concern for the Public Sector
SolarWinds (NYSE:SWI) has released its seventh Public Sector Cybersecurity Survey Report, revealing critical insights from 400 IT decision-makers. Key findings indicate that the general hacking community (56%) is the primary source of threats, followed by careless insiders (52%) and foreign governments (47%). Despite the rise in threats, around 60% of respondents noted stagnation in detection and resolution times. The report highlights a shift towards zero-trust strategies and increased investments in cybersecurity solutions, with 77% prioritizing network security software in the next year.
- Increased awareness of cybersecurity threats, particularly from foreign governments.
- Majority of public sector organizations (75%) are adopting a zero-trust approach.
- 77% of respondents prioritize investments in network security software.
- Detection and resolution times for security threats have not improved; around 60% note no change or worsening.
- Concerns over ransomware (66%), malware (65%), and phishing (63%) have significantly increased.
The growing prominence of the general hacking community and foreign government-led cyberattacks is forcing the public sector to re-evaluate its security posture
“These results demonstrate that while IT security threats have increased—primarily from the general hacking community and foreign governments—the ability to detect and remediate such threats has not increased at the same rate, leaving public sector organizations vulnerable,” said
2021 Key Findings:
-
The general hacking community (
56% ) is the largest source of security threats at public sector organizations, followed closely by careless/untrained insiders (52% ) and foreign governments (47% ). For the first time in five years, careless insiders were not listed as the top security threat.-
State and local governments (
63% ) are significantly more likely than other public sector groups to be concerned about the threat of the general hacking community. -
Federal civilian agency respondents (
58% ) are more likely to indicate careless insiders as a threat compared to the defense community (41% ).
-
State and local governments (
-
Cybersecurity threats from foreign governments (
56% ) are responsible for the greatest increase in concern among public sector respondents.-
Defense respondents (
68% ) are the most likely to note foreign governments as a cybersecurity threat, compared to civilian (53% ), state and local government (46% ), and education (25% ) respondents.
-
Defense respondents (
-
When asked about specific types of security breaches, the public sector’s level of concern over ransomware (
66% ), malware (65% ), and phishing (63% ) has increased the most over the last year. -
Time to detection and resolution have not improved at the rate of increased IT security threats and breach concerns.
-
About
60% of respondents noted both the time to detection and time to resolution remained the same or worsened between 2020 and 2021.
-
About
-
Lack of training (
40% ), low budgets and resources (37% ), and the expanded perimeter (32% ) as a result of increased remote work continue to plague public sector security pros.-
Respondents also pointed to insufficient data collection and monitoring as a key impediment to threat detection (
31% ). -
State government respondents (
50% ) indicate more so than local governments (25% ) that budget constraints are an obstacle to maintaining or improving IT security. - Education respondents are the most likely to struggle to identify the root cause of security issues, hampering their ability to both detect and remediate such threats.
-
Respondents also pointed to insufficient data collection and monitoring as a key impediment to threat detection (
-
Public sector respondents suggest improving investigative and remediation capabilities, as well as reducing barriers to sharing threat information between public and private sectors, as the top priorities for compliance with the Cybersecurity Executive Order.
-
Among SLED organizations,
86% are likely to adopt cybersecurity best practices and activities from the Cybersecurity Executive Order, including almost100% of respondents from K-12 schools.
-
Among SLED organizations,
-
More than
75% of public sector respondents note their organizations rely on a formal or informal zero-trust approach.-
A majority of public sector respondents are familiar with the principle of least privilege (PoLP), and
70% of respondents are either already implementing PoLP or will implement PoLP within the next 12 months.
-
A majority of public sector respondents are familiar with the principle of least privilege (PoLP), and
-
The majority of public sector respondents realize the importance of IT security solutions and prioritize their investments highly in the next 12 months, with network security software (
77% ) being the top priority.-
IT modernization investment priority leans toward replacing legacy applications (
60% ) and migrating systems to the cloud (60% ). -
When it comes to customer experience, IT services management (
59% ) holds investment priority. And for digital transformation, implementing stakeholder platforms and portals (57% ) is key.
-
IT modernization investment priority leans toward replacing legacy applications (
“Public sector organizations are increasingly concerned about the threats from foreign governments,” said
Supporting Quotes:
“Remote access is improving and will continue to be a priority.”
- Defense / Military
“The main difficulty is in finding and hiring qualified IT employees and then retaining them.”
- Federal Civilian
“If you and your customers are based in
- Defense / Military
*In
Additional Resources
-
SolarWinds 2021 Cybersecurity Survey Report - SolarWinds Secure by Design Resources
- SolarWinds Government Solutions
-
SolarWinds and GovLoop eBook: What You Can Do Now to Prepare and Persevere through the Next Cyber Attack - Whitepaper: The Ultimate Guide to Federal IT Compliance
-
SolarWinds 2020Federal Cybersecurity Survey press release
Connect with
#SWI
#SWIcorporate
#SWIresearch
#SWIsecurity
About
The
© 2022
View source version on businesswire.com: https://www.businesswire.com/news/home/20220111005056/en/
REQ
Phone: 1-703-287-7820
ebrown@req.co
Phone: +1-301-672-5351
pr@solarwinds.com
Source:
FAQ
What are the key findings of the SolarWinds Public Sector Cybersecurity Survey Report 2021?
How does SolarWinds plan to address cybersecurity concerns raised in the survey?
What percentage of respondents are aware of the zero-trust approach according to SolarWinds' survey?
What challenges do public sector organizations face in cybersecurity according to the survey?