Only Half of All Organizations Have Refreshed Their Security Strategy Based on the Pandemic

Stu Sjouwerman | Apr 19, 2022

Only Half of All Organizations Have Refreshed Their Security Strategy Based on the PandemicA new study published by Ponemon Institute shows that a material portion of organizations are still using pre-pandemic security processes and policies, putting the org at risk.

It seems logical that with all the shifts in how cyberthreats are being delivered, executed, and monetized over the last two years, that every single organization would be taking note and aligning their protective, preventative, detective, and responsive strategies to align. But according to Ponemon’s latest report, Security Innovation: Secure Systems Start with Foundational Hardware, we find some great details around how organizations have and haven’t changed their strategies.

According to the report, only 53% of organizations have refreshed their security strategy over the last two years.

Of those that have refreshed their strategy, the following priorities have changed:

  • Emphasis on the remote workforce (66%)
  • Expanded use of automation and AI tools for security operations (56%)
  • Use of cybersecurity compliance, risk management and privacy frameworks (52%)
  • Heightened awareness among employees about cyber hygiene (54%)
  • Increased accountability among employees (40%)

While the strategy changes above are certainly moving organizations in the right direction, it’s a bit saddening to see of the 53% that have refreshed strategies, about half of those are doing the right thing.

Focusing in on Security Awareness Training for a moment, 54% of 53% of organizations means only about 28% of organizations are putting a newfound emphasis on educating employees on how to identify and avoid phishing and social engineering attacks.

If the pandemic has taught us nothing else about the state of cyberattacks, it has shown us that phishing and social engineering are the most often used – and most effective – initial attack vector, requiring a focused defense – one found in Security Awareness Training.

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.