Cyber security

Cybersecurity: businesses are better prepared but still vulnerable when it comes to crisis management

The EY Cyber Barometer 2025 report, based on a survey of over 300 Italian companies, reveals more structured defences and a narrowing gap between SMEs and large enterprises. However, only 6.7 per cent have achieved the highest level of formalisation in their incident response plans.

 (Adobe Stock)

2' min read

Translated by AI
Versione italiana

2' min read

Translated by AI
Versione italiana

When a cyberattack brings a business to a standstill, the contingency plan must work even when it’s not just sitting on the shelf. It is essential to know who makes the decisions, which systems to restore first and how to carry on with work. EY’s Cyber Barometer 2025 focuses on this gap between written procedures and the ability to implement them: defences are becoming more widespread, but crisis management remains weak.

The survey examines over 300 Italian companies subject to financial audit, compared with over 100 in the previous edition, which covered the two-year period 2023–2024. The assessments combine interviews, documents and operational evidence, ranging from records to system configurations. The scores, on a scale of zero to five, indicate the extent to which controls are organised, implemented and verified. They do not measure immunity to attacks.

Loading...

The EY press release reports an overall maturity level of around 55 per cent, compared with the previous figure of 46 per cent. However, the expansion of the sample calls for caution when making comparisons. The gap between businesses of different sizes is also narrowing: SMEs stand at 46.5 per cent, whilst large companies are at around 50 per cent. The latter maintain an advantage in more complex activities, such as incident monitoring and response. In smaller businesses, by contrast, security is more often entrusted to the expertise of individual staff members.

The widest disparities are evident across different sectors. Digital and ICT sectors have reached a maturity level of 65–67 per cent, whilst traditional and manufacturing sectors range between 35 per cent and 50 per cent. For those selling digital services, ensuring continuity means safeguarding the product itself. In other sectors, security appears to be more fragmented and plays a lesser role in business decision-making.

The data on incident response plans show just how much work remains to be done. 54.6 per cent of respondents score three or four out of five, but only 6.7 per cent achieve the highest level. Almost 19 per cent score zero or one, with procedures either non-existent or largely informal. For IT business continuity plans, the proportion at the highest level drops to 4.6 per cent.

Other common shortcomings relate to supplier security and the verification of the effectiveness of controls. An attack can also originate via a partner or an external service. Investments must therefore also cover regular drills and audits, with responsibilities clearly defined before an emergency arises. It is during these drills that a company can discover whether it is truly capable of restoring its systems and continuing to operate.

Copyright reserved ©
  • Luca Tremolada

    Luca TremoladaGiornalista

    Luogo: Milano via Monte Rosa 91

    Lingue parlate: Inglese, Francese

    Argomenti: Tecnologia, scienza, finanza, startup, dati

    Premi: Premio Gabriele Lanfredini sull’informazione; Premio giornalistico State Street, categoria "Innovation"; DStars 2019, categoria journalism

Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti