Intelligent CISO Issue 02 | Page 74

Gregory Webb , CEO , Bromium
so the threat has nowhere to go and nothing to steal .
“ This eliminates reimaging and rebuilds , as machines do not get owned . It also significantly reduces false positives as SOC teams are only alerted to real threats . Emergency patching is not needed as the applications are already protected in an isolated container . Triage time is drastically reduced because SOC teams can analyse the full kill chain .”
Statistics obtained by Bromium via a survey of 500 CISOs from global enterprises unveiled that organisations invest US $ 345,300 per year on detectto-protect / detection-based security tools , but this cost is minimal compared to the hidden human costs . That US $ 345,300 cost is based on average 2,000-person organisation .
The research also showed that labour costs are soaring as a direct result of detection-based technology failures . SOC teams receive more than one million alerts every year , but 75 % are false positives .
SOC teams spend 413,920 hours per year triaging alerts , an additional 2,448 hours rebuilding compromised machines and 780 hours on emergency patching , the research showed .
Meanwhile , Azeem Aleem , Global Director of Worldwide Advanced Cyber Defence Practice at RSA Security , has outlined why it is so important for businesses to mitigate any breaches . He said : “ With every year that passes the attack surface widens , creating more opportunities for hackers and making life even harder for corporate security teams . As businesses forge ahead with digital transformations and move more services online , having cybersecurity in place is a business essential . Any
74 Issue 02 | www . intelligentciso . com