January 16, 2018 By Larry Loeb 2 min read

Companies in Asia-Pacific take almost twice as long to detect a cyberattack as organizations based in other regions, according to recent research.

A report by FireEye and Marsh & McLennan revealed that the median dwell time — the time between a cyber intrusion and its detection — amounted to 172 days in the region, compared to the global median of 99 days. This gap is due largely to structural problems, low security investments and other issues.

Dwelling on Dwell Time in Asia-Pacific

The Asia-Pacific region consists of East Asia, South Asia, Southeast Asia and Oceania. According to the report, the Europe, Middle East and Africa region tallied a median dwell time of 106 days, while the Americas came in at 99 days.

As a result of the region’s heterogeneity, companies located in Asia-Pacific vary widely in terms of their security commitments, preparedness and awareness, the study noted. This inconsistency, along with a lack of investment in security infrastructure, geopolitical tensions and a severe shortage of cybersecurity practitioners, contributes to the high dwell time. A preponderance of legacy systems may also lead to complacency and longer dwell times, according to the report.

In addition, most countries in Asia-Pacific lack regulations that require organizations to report security incidents. The study mentioned, however, that Singapore and Australia do have plans to implement such requirements in 2018.

Financial Services Under Attack

Citing results from Marsh & McLennan’s “2017 Global Cyber Survey,” FireEye noted that 39 percent of international corporations across industry sectors in Asia-Pacific ranked financially motivated attacks as the most significant cyberthreat, as reported by ZDNet.

Furthermore, almost one-third of FireEye clients that suffered cyberattacks in the past year were part of the financial services sector. For comparison, 10 percent of targeted companies hailed from the energy and utilities industry, followed by the telecommunications sector at 9 percent.

Reducing high dwell time can only come from better security practices and more evolved security programs. The report pointed to a particular need for heightened awareness, stronger threat mitigation measures, and stricter privacy and reporting regulations in the Asia-Pacific region.

More from

Threat intelligence to protect vulnerable communities

2 min read - Key members of civil society—including journalists, political activists and human rights advocates—have long been in the cyber crosshairs of well-resourced nation-state threat actors but have scarce resources to protect themselves from cyber threats. On May 14, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released a High-Risk Communities Protection (HRCP) report developed through the Joint Cyber Defense Collaborative that addresses the threat to these vulnerable groups, with findings contributed by the X-Force Threat Intelligence team.Cyber criminals seek stolen credentialsThe HRCP…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

3 recommendations for adopting generative AI for cyber defense

3 min read - In the past eighteen months, generative AI (gen AI) has gone from being the source of jaw-dropping demos to a top strategic priority in nearly every industry. A majority of CEOs report feeling under pressure to invest in gen AI. Product teams are now scrambling to build gen AI into their solutions and services. The EU and US are beginning to put new regulatory frameworks in place to manage AI risks.Amid all this commotion, hackers and other cybercriminals are hardly…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today