95% of IT decision makers don’t trust their security vendors, according to a security vendor.
New research from Sophos has found that only 5% of companies have “full trust” in their security providers, with around half (51%) of those surveyed reporting that lack of trust makes them anxious about the risk of being hit with a cybersecurity breach.
The lack of confidence in IT security firms may stem from businesses’ inability to determine whether or not they can trust their vendors.
79% of organisations reported they “find it challenging to assess the trustworthiness of new cybersecurity vendors”, while nearly two-thirds (62%) said they have the same problem with the suppliers they already work with – “a signal that trust gaps donโt disappear once a contract is signed”, according to the report.ย
The most common reasons IT decision makers say they struggle to assess the trustworthiness of a vendor are “information provided by vendors not being factual or detailed enough”, a problem reported by 47% of businesses. Suppliers’ information being hard to interpret or understand was cited by 45% of enterprises.ย
IT skills gap: understanding security vendors
“Many [companies] struggle to interpret vendor claims, assess technical details, or find the information they need to make confident decisions,” the research said.
IT decision makers also acknowledged skills gaps within their organisations, with 43% of them saying that lacking skills or knowledge to assess vendors effectively was a reason for they find it difficult to determine providers’ trustworthiness.
Small businesses were more likely to feel they lacked the necessary skills or knowledge, compared to larger enterprises, the report added.ย
Trust in security vendors is also a bone of contention among companies’ in-house staff. Over three quarters (78%) of survey respondents said that there are differences of opinion between IT teams and senior management on the trustworthiness of vendors, with nearly one third (29%) saying it’s “often” a problem for their teams.ย
According to the Sophos survey, IT staff rank “verifiable artifacts indicative of cybersecurity maturity,” such as bug bounties and third-party assessments, as their primary driver of trust in cybersecurity vendors. That’s ahead of delivering high quality services, good communications during security breaches, expert commentary following major security incidents, and performing well in analyst reports.ย
The research, available here, surveyed 5,000 IT and cybersecurity leaders across 17 countries.
You might also be interested