<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Canadian companies averaged 25 cybersecurity incidents in past year in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Canadian-companies-averaged-25-cybersecurity-incidents-in-past/m-p/64338#M991</link>
    <description>&lt;P&gt;According to the most recent EY 2023 Cybersecurity Leadership Insights study, 81% of Canadian companies have averaged&amp;nbsp; 25 Security in the past year....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://www.consulting.ca/news/3761/canadian-companies-averaged-25-cybersecurity-incidents-in-past-year" target="_blank"&gt;https://www.consulting.ca/news/3761/canadian-companies-averaged-25-cybersecurity-incidents-in-past-year&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not been able to see the entire report yet but find it hard to believe that 81% of Canadian Companies have had this happen.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has the study, would you send a link?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 00:42:16 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2023-11-08T00:42:16Z</dc:date>
    <item>
      <title>Canadian companies averaged 25 cybersecurity incidents in past year</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Canadian-companies-averaged-25-cybersecurity-incidents-in-past/m-p/64338#M991</link>
      <description>&lt;P&gt;According to the most recent EY 2023 Cybersecurity Leadership Insights study, 81% of Canadian companies have averaged&amp;nbsp; 25 Security in the past year....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://www.consulting.ca/news/3761/canadian-companies-averaged-25-cybersecurity-incidents-in-past-year" target="_blank"&gt;https://www.consulting.ca/news/3761/canadian-companies-averaged-25-cybersecurity-incidents-in-past-year&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not been able to see the entire report yet but find it hard to believe that 81% of Canadian Companies have had this happen.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has the study, would you send a link?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 00:42:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Canadian-companies-averaged-25-cybersecurity-incidents-in-past/m-p/64338#M991</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2023-11-08T00:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Canadian companies averaged 25 cybersecurity incidents in past year</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Canadian-companies-averaged-25-cybersecurity-incidents-in-past/m-p/64355#M994</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...81% of Canadian companies have averaged&amp;nbsp; 25 Security [incidents] in the past year ... hard to believe ...&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Will be interesting to see how EY defined "security incident".&amp;nbsp; Guessing it&amp;nbsp;did not establish a minimum business loss (time/money).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two examples of why this matters: A colleague's highly privileged account was used 120 miles from our office. IR team called; the colleague confirmed attended to a break/fix call while visiting that location.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, a few weeks ago, our SIEM flagged a command I ran as an IOC.&amp;nbsp; IR team calls, confirms it was me, that this fits within my role, and then whitelisted the command for my team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In both cases, something unusual was observed, a incident ticket was created and there was an of investment of time to investigate and resolve. Both tickets show 1 hour and 0 dollars, so they will be included in our workload metrics, but not in the business-facing reports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 03:26:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Canadian-companies-averaged-25-cybersecurity-incidents-in-past/m-p/64355#M994</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-11-08T03:26:35Z</dc:date>
    </item>
  </channel>
</rss>

