2017 State of Digital Risk Management Key Findings -...

49
1 © 2016 Proofpoint, Inc. 2017 STATE OF DIGITAL & SOCIAL MEDIA RISK MANAGEMENT

Transcript of 2017 State of Digital Risk Management Key Findings -...

Page 1: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

1 © 2016 Proofpoint, Inc.

2017 STATE OF DIGITAL & SOCIAL MEDIA RISK MANAGEMENT

Page 2: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

2 © 2016 Proofpoint, Inc.

ABOUT THE STUDY2017 STATE OF DIGITAL & SOCIAL MEDIA RISK MANAGEMENT

Page 3: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

3 © 2016 Proofpoint, Inc.

ABOUT THE STUDY

§ Survey-based study conducted by JEM Consulting & Advisory Services, a Silicon Valley-based management consultancy for the digital age

§ Sponsored by Proofpoint§ Online survey conducted Q1 2017§ 202 responses to survey by leaders with responsibility for digital

governance and / or digital risk management§ Sample included: § 90% US-based organizations§ All sizes from SMB – large enterprise organizations§ All sectors§ 50+ industries, including both B2B & B2C

Page 4: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

4 © 2016 Proofpoint, Inc.

Howmanyemployeesdoesyourorganizationhave?

12.3,12%

2.5,3%

7.4,8%

8.9,9%

19.2,19%20.2,20%

7.9,8%

7.4,7%

4.9,5%

9.4,9%

1-4

5-9

10-19

20-99

100-499

500-9,999

10,000+

10,001- 25,000

25,001- 50,000

50,000+

Page 5: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

5 © 2016 Proofpoint, Inc.

Isyourorganization:

Publiccompany27%

Privatecompany59%

Non-profitorganization

4%

Educationalinstitution

5%

Governmentalorganization

5%

Publiccompany

Privatecompany

Non-profitorganization

Educationalinstitution

Page 6: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

6 © 2016 Proofpoint, Inc.

Whatisyourfunction?

22%DIGITALTEAM

47%IT

7%MARKETING

5%SOCIALMEDIA

19%VARIOUS

Page 7: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

7 © 2016 Proofpoint, Inc.

TOP FINDINGS2017 STATE OF DIGITAL & SOCIAL MEDIA RISK MANAGEMENT

Page 8: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

8 © 2016 Proofpoint, Inc.

7 Key Findings1. Organizations face a wide, complex and increasing number and range of digital

and social media risks. 2. Organizations are concerned about a wide range of social media risks, from

brand reputation resulting from employee mistakes, to hacks, fraud and counterfeiting using fake social media accounts; integration with other systems such as CRM and intranet and regulatory compliance (FTC and HIPAA).

3. As the number and types of risks continue to expand, the responsibility for managing digital and social media risks extends well beyond the IT department.

4. While most organizations have established policies, procedures and programs to manage more traditional IT security and digital risk effectively, they are less mature in their management of new types of digital and social media risks

5. Digital governance teams and Digital Centers of Excellence are becoming more common at organizations to help manage digital and social media risks.

6. Companies are slow to adopt tools and technologies to help them manage this growing number of digital and social media risks.

7. Most organizations do not have a fully optimized, managed, and resourced process and program for managing digital and social media risk.

Page 9: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

9 © 2016 Proofpoint, Inc.

KEY FINDING # 1Organizations face a wide, complex and increasing number and range of digital and social media risks.

Page 10: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

10 © 2016 Proofpoint, Inc.

Whatarethebiggestchallengesyoucurrentlyfacewithregardtoyourdigitalriskmanagement?(Pleaseselectallthatapply)

Page 11: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

11 © 2016 Proofpoint, Inc.

KEY FINDING # 2Organizations are concerned about a wide range of social media risks, from brand reputation to hacks, fraud, integration with other systems to regulatory compliance.

Page 12: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

12 © 2016 Proofpoint, Inc.

RISKFACTOR Percent

Brandreputation 64.9%

Securityofyouremployees'socialchannels 50.5%

Integrationswithothersystems(e.g.,CRM,intranet)

47.5%

FTCregulatorycompliance 39.6%

HIPAA Compliance 5.0%

Concerns About Employee Use of Social Media

Page 13: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

13 © 2016 Proofpoint, Inc.

KEY FINDING # 3As the number and types of risks continue to expand, the responsibility for managing digital and social media risks extends well beyond the IT department.

Page 14: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

14 © 2016 Proofpoint, Inc.

Whichdepartments/functionsareprimarilyresponsibleformanagingdigitalriskinyourorganization?(Selectallthatapply.)

Other: HR, Privacy/Protection, Legal, Knowledge Management, Data Team, etc

Page 15: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

15 © 2016 Proofpoint, Inc.

Whoisresponsiblefordataprotectioninyourorganization?

Page 16: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

16 © 2016 Proofpoint, Inc.

KEY FINDING # 4While most organizations have established policies, procedures and programs to manage more traditional IT security and digital risk effectively, they are less mature in their management of new types of digital and social media risks.

Page 17: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

17 © 2016 Proofpoint, Inc.

Doesyourorganizationhaveanti-virusmeasuresinplace?(Policies,Procedures,Technologies)

Yes88%

No12%

Yes

No

Page 18: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

18 © 2016 Proofpoint, Inc.

Dothesecoverallsystemareas,includingliveanddevelopmentenvironments,desktops,servers,gateways,laptops

andothermobiledevices?

Yes89%

No11%

Yes

No

Page 19: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

19 © 2016 Proofpoint, Inc.

Hasyourorganizationperformedanyexternalorinternalsecurityreviewsinthepast12months?

82%YES

18%NO

Yes

No

Page 20: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

20 © 2016 Proofpoint, Inc.

Doesaninformationsecuritypolicyexist?

Yes79%

No21%

Yes

No

Page 21: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

21 © 2016 Proofpoint, Inc.

Ifyes,areperiodicreviewsandupdatesofthepolicyperformed?

Yes91%

No9%

Yes

No

Page 22: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

22 © 2016 Proofpoint, Inc.

DoesyourorganizationhaveaPrivacyPolicy?

Yes78%

No22%

Yes

No

Page 23: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

23 © 2016 Proofpoint, Inc.

Ifyes,isyourprivacypolicycompliantwiththeEUDataProtectionDirective?

Yes67%

No12%

N/A21%

Yes

No

N/A

Page 24: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

24 © 2016 Proofpoint, Inc.

Isyourorganizationregisteredinaccordancewiththerelevantdataprotectionauthorities?

Yes67%

No16%

N/A17%

Yes

No

N/A

Page 25: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

25 © 2016 Proofpoint, Inc.

DoesyourorganizationhaveaDataProtectionandPrivacycomplianceprogram?

Yes72%

No23%

Idon'tknow5%

Yes

No

Idon'tknow

Page 26: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

26 © 2016 Proofpoint, Inc.

Doyouhaveacomplianceprogramcoveringclientconfidentialityanddataprotection?

Yes75%

No22%

Idon'tknow3%

Yes

No

Idon'tknow

Page 27: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

27 © 2016 Proofpoint, Inc.

Doesacomprehensiveinventoryexistthatdetailsallinformationassets,softwareassets,hardwareassetsandservices?

80%YES

14%NO

6%DON’TKNOW

Yes

No

Idon'tknow

Page 28: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

28 © 2016 Proofpoint, Inc.

Doesaformalprocessexistforreportingandhandlingsecurityincidents,weaknessesandsoftwareissues?

Yes75%

No25%

Yes

No

Page 29: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

29 © 2016 Proofpoint, Inc.

Doesyourorganizationhaveclearlydefinedresponsibilitiesandproceduresformanagingsecurityincidents?

Yes81%

No19%

Yes

No

Page 30: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

30 © 2016 Proofpoint, Inc.

Doesaformalbusinesscontinuityplanexist?

Yes71%

No29%

Yes

No

Page 31: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

31 © 2016 Proofpoint, Inc.

Doyouhaveatrainingprogramforyouremployeestoeducatethemregardingsecurity,privacyanddataprotectionpolicies

andriskmitigation?

Yes72%

No28%

Yes

No

Page 32: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

32 © 2016 Proofpoint, Inc.

Ifyes,isthetrainingmandatory?

Yes82%

No18%

Yes

No

Page 33: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

33 © 2016 Proofpoint, Inc.

Areyouconcernedaboutemployeesmistakenlysharingconfidential,regulated,orembarrassinginformationviatheirsocialmediaactivity?

Notconcerned20%

Somewhatconcerned45%

Veryconcerned35%

Notconcerned

Somewhatconcerned

Veryconcerned

Page 34: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

34 © 2016 Proofpoint, Inc.

Areyouconcernedabouthackersandtrollstargetingemployees'socialmediaaccounts?

Notconcerned18%

Somewhatconcerned39%

Veryconcerned43%

Notconcerned

Somewhatconcerned

Veryconcerned

Page 35: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

35 © 2016 Proofpoint, Inc.

Areyouconcernedaboutsocialmediascamsandphishing?

Notconcerned20%

Somewhatconcerned33%

Veryconcerned47%

Notconcerned

Somewhatconcerned

Veryconcerned

Page 36: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

36 © 2016 Proofpoint, Inc.

Areyouconcernedaboutfraudandcounterfeitingusingfakesocialmediaaccounts?

Notconcerned20%

Somewhatconcerned35%

Veryconcerned45%

Notconcerned

Somewhatconcerned

Veryconcerned

Page 37: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

37 © 2016 Proofpoint, Inc.

Doesyourorganizationhaveasocialmediapolicy?

Yes67%

No33%

Yes

No

Page 38: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

38 © 2016 Proofpoint, Inc.

Ifyes,doesyourorganizationhavesocialmediatrainingforemployees?

Yes80%

No20%

Yes

No

Page 39: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

39 © 2016 Proofpoint, Inc.

Ifyes,isthistrainingmandatory?

52%YES

20%YES,FORCERTAIN

EMPLOYEES

28%NO

Yes,forallemployees

Yes,forcertainemployees

No

Page 40: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

40 © 2016 Proofpoint, Inc.

KEY FINDING # 5Digital governance teams and Digital Centers of Excellence are becoming more common at organizations to help manage digital and social media risks.

Page 41: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

41 © 2016 Proofpoint, Inc.

Doesyourorganizationhaveadigitalgovernanceteamand/orDigitalCenterofExcellence?

70%YES

30%NO

Yes

No

Page 42: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

42 © 2016 Proofpoint, Inc.

KEY FINDING # 6Companies are slow to adopt tools and technologies to help them manage this growing number of digital and social media risks.

Page 43: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

43 © 2016 Proofpoint, Inc.

Doyouusetool(s)/vendor(s)tomanageyourdigitalrisk?

50%YES

50%NO

Yes

No

Page 44: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

44 © 2016 Proofpoint, Inc.

Doyouuseanytoolstohelpmitigatesocialmediabrand,securityandcompliancerisks?

33%YES

67%NO

Yes

No

Page 45: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

45 © 2016 Proofpoint, Inc.

KEY FINDING # 7Most organizations do not have a fully optimized, managed, and resourced process and program for managing digital and social media risk.

Page 46: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

46 © 2016 Proofpoint, Inc.

Howwouldyourateyourorganization’smaturitylevelasitrelatestodigitalandsocialmediariskmanagement?

MATURITY LEVELASSESSMENT Percent1.InitialStage(developingacomprehensiveprogram,butmanagedthroughindividualefforts)

31.2%

2.Defined(processisdefinedandconfirmedasastandardbusinessprocess)

26.2%

3.Managed(managedinaccordancewithagreed-uponmetrics)

33.2%

4.Optimized(fullymanaged,resourcedandincludescontinuousprocessimprovement)

9.4%

Page 47: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

47 © 2016 Proofpoint, Inc.

RECOMMENDATIONS BEST PRACTICES2017 STATE OF DIGITAL & SOCIAL MEDIA RISK

Page 48: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

48 © 2016 Proofpoint, Inc.

Recommendations for Best Practices

§ More comprehensive and effective communication and collaboration between the growing number of departments and functions responsible for risk management

§ Formalize policies, processes and programs to address all areas of digital and social media risk

§ Develop and mandate employee training and enablement to understand and manage these risks

§ Deploy new tools and technologies to proactively identify and manage advanced attacks delivered via email, social media and mobile apps

§ Comprehensive approach to risk management, including strategy, governance and enablement through a Digital Center of Excellence

Page 49: 2017 State of Digital Risk Management Key Findings - …ww1.prweb.com/prfiles/2017/07/06/14486286/2017 State of Digital...2017 STATE OF DIGITAL & SOCIAL MEDIA ... a Silicon Valley-based

49 © 2016 Proofpoint, Inc.

Recommendations for Best Practices§ Formalize and integrate disparate functional approaches to and

responsibilities for digital and social media risk management into a Digital Center of Excellence (DCOE)

§ Cross-functional leadership of DCOE§ DCOE acts as a trusted strategic partner to help teams understand and

embed new digital and social media technologies and programs safely and effectively

§ DCOE provides digital leadership, oversight, training, best-in-class advice, communicate best practices

§ Result: A comprehensive approach to digital and social media strategy, enablement, governance and risk management; greater collaboration and communication; improved efficiencies and effectiveness