Perception of the initiatives and countermeasures to mitigate cyber risks
| Manufacturers | Logistics service providers | Retailers | ANOVA | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Initiatives | Type of initiative | Mean | St. dev. | Mean | St. dev. | Mean | St. dev. | F-statistics | |
| Employ a CISO or DPO | Internal organizational initiatives | Pre-attack | 3.14 | 1.46 | 3.40 | 1.35 | 3.18 | 1.47 | 0.18 |
| Conduct personnel background checks | Internal organizational initiatives | Pre-attack | 2.62 | 1.28 | 2.93 | 1.14 | 2.76 | 1.35 | 0.47 |
| Presence of an information security strategy | Internal organizational initiatives | Pre-attack | 4.50 | 0.80 | 4.50 | 0.84 | 4.67 | 0.58 | 0.06 |
| Specific data and information insurance | Internal organizational initiatives | Post-attack | 3.33 | 1.63 | 4.00 | 0.82 | 4.00 | 1.00 | 1.19 |
| Employee security awareness training programme (cyber hygiene) | Training and internal awareness | Pre-attack | 3.48 | 1.19 | 3.73 | 1.14 | 3.29 | 1.49 | 0.37 |
| Secure data access and control measures | Internal data management | Pre-attack | 3.67 | 1.23 | 3.50 | 0.55 | 2.00 | 1.73 | 2.53 |
| Accurate record of personnel handling sensitive data | Internal data management | Pre- and trans-attack | 3.58 | 1.16 | 3.83 | 0.41 | 3.00 | 1.73 | 0.58 |
| IPS, data and URL filtering (antivirus and antispam) | Internal IT security and resilience tools | Pre-attack | 4.75 | 0.62 | 4.83 | 0.41 | 4.67 | 0.58 | 0.09 |
| Multiple data backup | Internal IT security and resilience tools | Pre-attack | 4.16 | 0.75 | 4.75 | 0.61 | 3.33 | 0.58 | 4.32* |
| Geographical distributed data centres | Internal IT security and resilience tools | Pre-attack | 3.67 | 1.21 | 4.75 | 0.52 | 2.00 | 0.42 | 9.38* |
| Require suppliers and customers to comply with the privacy and security policies | Compliance and external awareness | Pre-attack | 3.43 | 1.25 | 3.77 | 1.19 | 3.65 | 1.00 | 0.61 |
| Conduct supply chain partners security audits | Compliance and external awareness | Pre-attack | 3.35 | 1.31 | 3.57 | 1.22 | 3.47 | 1.33 | 0.19 |
| Communication procedures with involved supply chain partners | External event management | Trans- and post-attack | 3.67 | 0.89 | 4.17 | 0.75 | 3.00 | 1.73 | 1.43 |
| Business continuity and disaster recovery plans | External event management | Trans- and post-attack | 4.67 | 0.52 | 4.75 | 0.80 | 4.33 | 0.58 | 1.19 |
| Manufacturers | Logistics service providers | Retailers | ANOVA | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Type of initiative | St. dev. | Mean | St. dev. | Mean | St. dev. | ||||
| Internal organizational initiatives | Pre-attack | 3.14 | 1.46 | 3.40 | 1.35 | 3.18 | 1.47 | 0.18 | |
| Internal organizational initiatives | Pre-attack | 2.62 | 1.28 | 2.93 | 1.14 | 2.76 | 1.35 | 0.47 | |
| Internal organizational initiatives | Pre-attack | 4.50 | 0.80 | 4.50 | 0.84 | 4.67 | 0.58 | 0.06 | |
| Internal organizational initiatives | Post-attack | 3.33 | 1.63 | 4.00 | 0.82 | 4.00 | 1.00 | 1.19 | |
| Training and internal awareness | Pre-attack | 3.48 | 1.19 | 3.73 | 1.14 | 3.29 | 1.49 | 0.37 | |
| Internal data management | Pre-attack | 3.67 | 1.23 | 3.50 | 0.55 | 2.00 | 1.73 | 2.53 | |
| Internal data management | Pre- and trans-attack | 3.58 | 1.16 | 3.83 | 0.41 | 3.00 | 1.73 | 0.58 | |
| Internal IT security and resilience tools | Pre-attack | 4.75 | 0.62 | 4.83 | 0.41 | 4.67 | 0.58 | 0.09 | |
| Internal IT security and resilience tools | Pre-attack | 4.16 | 0.75 | 4.75 | 0.61 | 3.33 | 0.58 | 4.32* | |
| Internal IT security and resilience tools | Pre-attack | 3.67 | 1.21 | 4.75 | 0.52 | 2.00 | 0.42 | 9.38* | |
| Compliance and external awareness | Pre-attack | 3.43 | 1.25 | 3.77 | 1.19 | 3.65 | 1.00 | 0.61 | |
| Compliance and external awareness | Pre-attack | 3.35 | 1.31 | 3.57 | 1.22 | 3.47 | 1.33 | 0.19 | |
| External event management | Trans- and post-attack | 3.67 | 0.89 | 4.17 | 0.75 | 3.00 | 1.73 | 1.43 | |
| External event management | Trans- and post-attack | 4.67 | 0.52 | 4.75 | 0.80 | 4.33 | 0.58 | 1.19 | |
Note:
*pā<ā0.05
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.