Nearly half of (45 per cent) of New Zealand businesses rate themselves as not secure on both managing security from different endpoints and protecting company data when employees are working remotely. Only 50 per cent of businesses feel confident they would cope if their business experienced a significant cybersecurity breach. These are among the key findings of the HP New Zealand IT Security Study, which HP says covered 434 New Zealand small to large businesses across the services, production, retail and hospitality, health and education, and distribution industries. The research was conducted in September by Perceptive on behalf of HP New Zealand. “The consequences of a data breach are severe; from financial to brand and reputation damage,” says Grant Hopkins, managing director at HP New Zealand. “Organisations need to be vigilant about implementing processes that regularly monitor, detect and report data breaches,” says Hopkins, in a statement. “Running regular risk assessments and managing your endpoint security is critical in keeping businesses data safe.” The survey points out that as more Kiwis work remotely, use personal devices in the workplace, and work in public spaces, traditional security measures and antivirus programmes are becoming less effective. Sixty percent of businesses regularly allow remote working (and remote access to company data) but only 42 per cent of them have a security policy in place. Furthermore, while visual hacking represented the area of greatest perceived weakness, only one in five businesses have integrated privacy screens on desktops/laptops to protect this type of breach. The survey finds Only 41 per cent of respondents have conducted an IT risk assessment in the past year. Nearly a third, 29 per cent, of those who have experienced a cyberattack or a breach in the last 12 months have not done this assessment. Meanwhile, many IT departments tend to focus their efforts around PCs, tablets and other connected devices, but they neglect one of the largest areas of vulnerability: the printer. The study found that New Zealand businesses have printers that are relatively insecure with 30 per cent not offering any security features and only 35 per cent of businesses including printers in their IT security assessment. Without embedded security measures like real-time threat detection, automated monitoring, and data encryption, printers are left open and vulnerable to attack. Not only does this make the confidential and sensitive documents that are printed, scanned and copied by the printer easily accessible for hackers, but risks the entire network being hacked, while bypassing the firewall altogether, says HP. “Endpoint security – at the device level – is critical. Organisations tend to rely solely on third party software security to protect their devices when, in reality, stronger and better business security must be integrated into the device itself,” says Hopkins. “With hackers able to bypass traditional network perimeter security and antivirus programmes, it’s time we scrutinise a hardware’s security as closely, if not more, than our external security solutions.” Today’s SMBs must implement processes and technologies designed to both proactively detect and prevent against a cyberattack. An antivirus product only protects from malware running in the Operating System (OS). There are many other threats and security risks to a PC, for example those that aim to modify Boot-time or Runtime firmware. “Security threats are evolving every day. Due to reduced effectiveness of firewall protection, every device on an organisation’s network is at risk, and unfortunately printing and imaging devices are often overlooked and left exposed,” he says. Get the latest on digital transformation: Sign up for CIO newsletters for regular updates on CIO news, career tips, views and events. Follow CIO New Zealand on Twitter:@cio_nz Related content feature Red Hat embraces hybrid cloud for internal IT The maker of OpenShift has leveraged its own open container offering to migrate business-critical apps to AWS as part of a strategy to move beyond facilitating hybrid cloud for others and capitalize on the model for itself. By Paula Rooney May 29, 2023 5 mins CIO 100 Technology Industry Hybrid Cloud feature 10 most popular IT certifications for 2023 Certifications are a great way to show employers you have the right IT skills and specializations for the job. These 10 certs are the ones IT pros are most likely to pursue, according to data from Dice. By Sarah K. White May 26, 2023 8 mins Certifications Careers interview Stepping up to the challenge of a global conglomerate CIO role Dr. Amrut Urkude became CIO of Reliance Polyester after his company was acquired by Reliance Industries. He discusses challenges IT leaders face while transitioning from a small company to a large multinational enterprise, and how to overcome them. By Yashvendra Singh May 26, 2023 7 mins Digital Transformation Careers brandpost With the new financial year looming, now is a good time to review your Microsoft 365 licenses By Veronica Lew May 25, 2023 5 mins Lenovo Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe