Transcript
indicating their greater cybersecurity coverage might have made some of those threats a little bit less concerning. On the other hand, supply chain attacks where attackers, for example, target trusted third-party vendors, they were far more concerning to these respondents. And as you can see, supply chain attacks is a little above halfway down on the list for all respondents. Those who indicated a slightly lower cybersecurity maturity, and that's 38% of respondents, were most concerned about things like unpatched systems, connections to other systems, credentials compromised, weak access controls, and insider threats. So these organizations have an increased investment and maturity of people processing technology across multiple security domains, supporting cybersecurity beyond core protections, but they're missing either strong executive support or they're missing full visibility across the enterprise. So it's interesting to look at the fact that nearly 40% of respondents, yes, unpatched systems are a concern for everybody. They're a little less of a concern for those with a greater cybersecurity maturity. They were sort of only fourth on the list as against first. But it is interesting that those with a greater maturity are more concerned about supply chain attacks, credentials compromised. These are things that are not coming into the top five for respondents that have less executive support or less visibility across the enterprise. And then at the bottom of the list, those with the lowest cybersecurity maturity, in other words, they might have some core protections in place, but they're primarily focused on regulatory compliance with limited advanced cybersecurity capabilities. That was 19%. Or they may be just mostly reactive from their cybersecurity, from a cybersecurity standpoint, and they have sort of a minimal investment in securing critical systems only. That's another 10%. So that 29% of respondents or a little less than a third, they were most concerned about data exfiltration, supply chain attacks, weak access controls, ransomware attacks, or custom code vulnerability. So there, what you can sort of read into that is that the correlation between more traditional SAP security concerns, which is weak access controls, and the primary focus on regulatory compliance or mostly reactive policies indicates that many of those organizations, they might not have moved entirely beyond GRC-type concerns to broader cybersecurity threats. Also, potentially, they're also, what was I going to say? Yes, they are concerned about data exfiltration, but they're more concerned about custom code vulnerability, whereas you notice that wasn't even in the top five for the other two groups, and in fact, it's towards the bottom of the list for respondents as a whole, indicating that maybe those other groups, those that have a greater investment in cybersecurity or particularly have something that might be having more of an impact, which is a stronger executive support, might have already been able to partially or fully address some of those challenges.