Cybersecurity Trends and Why It’s More Important Than Ever

  • Andrew Chanthavong
  • Written by Andrew Chanthavong on March 23, 2023

Key Takeaways

  • Cybersecurity spending is being outpaced by cybercrime costs, demonstrating widespread vulnerability to outside attacks.
  • Businesses should continue investing in cybersecurity measures, especially as we enter the projected 2023 recession.
  • New, growing cybersecurity capabilities like threat detection software and cyber insurance will better insulate procurement from cyberattack consequences.

With recent hiring cutbacks and layoffs – and what seems like an impending 2023 recession – companies are looking for new places to cut costs, and procurement is left wondering how to implement new, more severe cost savings goals. With that being said, cybersecurity should not be an area procurement cuts back on. While it was one of the fastest-growing industries from 2015 to 2022, cybersecurity has recently seen slower growth than its historical trends. However, the rate of cyberattacks has only increased.

 

What are the latest cybersecurity trends?

Cybersecurity spending grew quickly between 2017 and 2020 but began rising exponentially after the coronavirus pandemic spurred the remote work movement (12-17% YoY growth from 2017-2021). During this period, there was a widespread shift to contracting with large, established cybersecurity firms. Partnering with a single, enterprise-level cybersecurity firm provides clients with a single point of contact for all cybersecurity needs, improving operational efficiency while reducing potential issues related to integration.

Unfortunately, cyberattacks and their financial costs have also snowballed during the last five years. According to a recent study by insurance firm Embroker, cybercrime costs are forecast to increase from $3 trillion in 2015 to over $10.5 trillion in 2025. There have been several factors contributing to these increased costs.

  • The implementation of remote work policies across the country has been a significant driver of cyberattack growth, adding millions of vulnerable endpoints in the form of employee laptops, mobile devices, and tablets.
  • Combined with vulnerabilities in file sharing and communication software like Slack and Microsoft Teams, malicious attackers have more potential attack points than ever.
  • Phishing and social engineering attacks remain the most common method of cyberattacks, while ransomware tactics are continually growing in frequency and complexity.

Concerns surrounding cyberattacks have led to the market growing rapidly in recent years, demonstrated by high stock prices for leading providers like CrowdStrike Holdings Inc. and Fortinet Inc. between 2020 and late 2022. However, cybersecurity companies have not been immune to recent economic conditions and the projected 2023 recession. According to a recent survey, 36% of IT professionals think that their organization is spending too little on cybersecurity, which is a 33% increase compared to 2022. This reduction in business investment has resulted in many smaller cybersecurity firms beginning layoffs in 2022 and early 2023. In contrast, large, enterprise-level cybersecurity firms have remained insulated from widespread layoffs as of March 2023.

 

 

What is the danger of underinvesting in cybersecurity?

Underinvestment in cybersecurity can lead to a variety of consequences for procurement professionals, with the most notable being supply chain attacks. Businesses can often be partnered with dozens of suppliers, adding sources of vulnerability to outside interference and data breaches. From supply chain attacks, hackers can gain access to sensitive customer information, confidential trade secrets, and passwords.

 

The 2013 Target data breach was one of the most notable supply chain attacks in history: over 40 million credit and debit card records were stolen from customers after hackers targeted a vulnerable node from one of the corporation's third-party suppliers. After the attack, Target was responsible for paying an $18.5 million settlement. Researchers estimate the company lost over $200 million in the following year as consumers avoided shopping at the retail store.

 

The ongoing digital transformation of businesses has kept cybersecurity demand high in the last year. Due to this trend, cybersecurity positions are the least likely to be cut compared to other positions at tech firms like HR, finance, operations, marketing, and sales, demonstrating the market's resiliency.

 

However, Silicon Valley Bank's recent collapse is forecast to significantly slow the growth of cybersecurity start-ups due to now limited credit lines and reduced access to venture capital (VC). SVB was known as the most abundant source of VC funding available to budding start-ups in the sector. With the funding now gone, small firms must either reduce costs through layoffs or find a new funding source in a highly competitive environment.

 

Why should procurement invest in cybersecurity in the face of budget cutbacks?

You should understand that investing in cybersecurity is a long-term strategy that provides preemptive savings to your business. The collapse of Southwest Airlines' technical systems in December 2022 shows the dire financial consequences of neglecting necessary, protective business investments.

 

Cybersecurity investment maintains supply chain continuity and keeps company confidential information such as financial data, supplier contracts, and intellectual property safe. Due to growing cyberattacks and privacy concerns, various jurisdictions have implemented specific cybersecurity measures to protect sensitive customer data. These include but are not limited to:

  • The EU General Data Protection Regulation (GDPR)
  • The California Consumer Privacy Act (CCPA)
  • The Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)

The consequences of non-compliance to any of these data protection regulations are severe. Direct financial penalties include hefty fines proportionate to a firm's global revenue. A privacy breach will also damage an organization's reputation and erode customer, supplier, and partner trust. This trend is clearly illustrated by the 2013 attack on Target, where consumers shifted their spending to competitors amid privacy concerns.

 

 

What next steps can procurement take?

You should continue to invest in cybersecurity measures like:

  • IT departments
  • System upgrades
  • Threat detection capabilities
  • Cybersecurity insurance

Investment is especially important in the current uncertain economic environment. Threat detection software protects against cyberattacks in real-time, alerting businesses when a breach occurs. In the event of Target's breach, threat detection software would have allowed a much more rapid response to the attack, potentially saving the retailer millions in damages. Procurement professionals should look into their current threat detection capabilities to avoid similar consequences.

 

Like threat detection software, the cyber insurance market has rapidly grown by over 61% between 2020 and 2021. These insurance policies minimize financial losses that result from data breaches. Additionally, investing in cyber awareness training reduces the risk that procurement users will fall victim to common scams like phishing and social engineering.

 

As you saw in both the 2013 Target attack and during the 2022 holidays, investing in regular system upgrades and maintenance is typically much cheaper than disaster-level events. Reputational damage is challenging to recover from and often leads to a considerable reduction in annual profit levels when consumers shift spending to competitors.

 

Procurement should also continue to prioritize conducting due diligence on suppliers. Supplier cybersecurity measures, policies, and practices should be regularly reviewed to minimize the risk of costly supply chain attacks. To address this, procurement professionals should include cybersecurity requirements in their contracts with suppliers. Cybersecurity KPIs ensure that cybersecurity concerns are being recorded and handled by suppliers.

 

Cybersecurity investment is only growing in importance as businesses continue to undergo widespread digital transformation. In the wake of budget cuts and the projected recession of 2023, it may be tempting to reduce cybersecurity spending to preserve profit. However, the preemptive savings associated with cybersecurity almost always outweigh the financial cost of a data breach.

 

Follow ProcurementIQ on LinkedIn to get notified of the latest procurement news and market developments from our experts to yours.

 

 

Stay Updated
Read Our Newsletter and Get the Latest Posts to Your Inbox

No spam ever. Read our Privacy Policy and Terms of Service

Post Tags:
  • Economic Trends
  • Technology
  • Supply Chain Trends
Share Post:
Let's Get Strategic
Ready to source smarter with ProcurementIQ?