Survey: Foreign States Considered Bigger IT Security Threat Than Ever

A new survey of public sector IT professionals conducted in January by independent research firm Market Connections found that careless or untrained insiders remains the top-ranked threat to higher education institutions’ network security, while the threat of malicious attacks by foreign governments is considered a bigger threat than in years past, according to the survey results.

The eighth edition of the Public Sector Cybersecurity Survey Report released today details the results of the survey, conducted on behalf of IT security provider SolarWinds; the survey polled 400 IT operations and security decision-makers, including 100 education practitioners, according to a news release.

“The threat foreign governments pose to the security of government IT systems has steadily increased throughout the years,'' said SolarWinds’ Brandon Shopp. “However, it is reassuring to see this year’s data showing public sector organizations continue to recognize top security threats, adopt zero trust strategies, and seek vendor attestations and SBOMs to better secure the software supply chain — all of which are crucial to maintaining a high standard of security across federal and state government, as well as in the education and defense sectors.”

Key Findings: Current Security Threats 

  • Careless/untrained insiders were ranked as the top threat by 58% of respondents; close behind were foreign governments (56%) and the general hacking community (52%). In 2021 — the last year this survey was conducted — the general hacking community ranked first.

  • 13% of higher education respondents said their organization has been impacted by ransomware in the last 12 months.

  • Education respondents were the least concerned about the threat of a ransomware attack when compared to other public sector respondents, with 26% of education respondents ranking ransomware as a top concern while 32% of federal government respondents ranked ransomware as a top threat and 42% of state and local government respondents saying the same.

  • Education respondents were significantly more likely to rank worm (23%) and mobile trojans (21%) as a threat than state and local and federal government respondents.

  • 65% of higher education respondents reported that their organizations were impacted by spam in the past 12 months.

Key Findings: IT Complexity

  • IT complexity (27%) surpassed budget constraints as the “most significant obstacle” in hardening their cybersecurity posture as identified by respondents.

  • 66% of respondents said their IT environment is “extremely/very complex to manage,” and only 5% of respondents reported that they feel “extremely confident” in their ability to manage their environments.

  • 58% of higher education respondents said they are “moderately confident” in their organization’s ability to manage its IT environment; 33% said they are “very confident.”

  • The education sector showed the largest increase in IT complexity, with 33% of education respondents reporting increasingly complex IT environments — about three times more than education respondents in the 2021 survey.

  • Education respondents were the least likely to be confident in their ability to manage their IT environment at 42%.

  • 52% of education respondents said they “lack visibility across their IT environments” and 53% of education respondents said they lack visibility across teams.

Key Findings: Zero Trust

  • 92% of education respondents said it’s “very or somewhat important” to implement a zero-trust approach, an increase of 10% over 2021 and the highest among all public sector groups.

  • 33% of higher education respondents shared that their organization is following the DoD zero trust strategy and roadmap — which was the leading response for higher education respondents, SolarWinds’ report said.

“This year’s data highlights the increasing need for continued partnership between the public and private sectors,” said SolarWinds CISO and Vice President Tim Brown. “If we continue to work together to assess top threats, secure IT environments, arm IT teams with the appropriate defenses, and implement formal strategies like zero trust, public sector organizations will be better positioned to continue mission-critical activities without interruption.”

Learn more at SolarWinds.com or download the full survey results.

About the Author

Kristal Kuykendall is editor, 1105 Media Education Group. She can be reached at [email protected].


Featured

  • person signing a bill at a desk with a faint glow around the document. A tablet and laptop are subtly visible in the background, with soft colors and minimal digital elements

    California Governor Signs AI Content Safeguards into Law

    California Governor Gavin Newsom has officially signed off on a series of landmark artificial intelligence bills, signaling the state’s latest efforts to regulate the burgeoning technology, particularly in response to the misuse of sexually explicit deepfakes. The legislation is aimed at mitigating the risks posed by AI-generated content, as concerns grow over the technology's potential to manipulate images, videos, and voices in ways that could cause significant harm.

  • close-up illustration of a hand signing a legislative document

    California Passes AI Safety Legislation, Awaits Governor's Signature

    California lawmakers have overwhelmingly approved a bill that would impose new restrictions on AI technologies, potentially setting a national precedent for regulating the rapidly evolving field. The legislation, known as S.B. 1047, now heads to Governor Gavin Newsom's desk. He has until the end of September to decide whether to sign it into law.

  • illustration of a VPN network with interconnected nodes and lines forming a minimalist network structure

    Report: Increasing Number of Vulnerabilities in OpenVPN

    OpenVPN, a popular open source virtual private network (VPN) system integrated into millions of routers, firmware, PCs, mobile devices and other smart devices, is leaving users open to a growing list of threats, according to a new report from Microsoft.

  • interconnected cubes and circles arranged in a grid-like structure

    Hugging Face Gradio 5 Offers AI-Powered App Creation and Enhanced Security

    Hugging Face has released version 5 of its Gradio open source platform for building machine learning (ML) applications. The update introduces a suite of features focused on expanding access to AI, including a novel AI-powered app creation tool, enhanced web development capabilities, and bolstered security measures.