A new report shows that cybersecurity incidents often go undetected in organizations due to reactive security approaches and operational deficiencies. The Kaspersky Compromise Assessment division analyzed annual statistics to evaluate how businesses handle active and historical cyberattacks. Consequently, the findings indicate that many enterprises lack the necessary visibility to identify active threats within their networks.

Analysis of Cybersecurity Incidents

The report highlights that 31% of analyzed cybersecurity incidents involved malicious activity that continued for more than three months. Additionally, over half of high-severity compromises remained undetected for at least 90 days. Notably, the oldest incident identified during the analysis period went unnoticed for four years. These statistics demonstrate that traditional security tools often fail to alert teams to persistent threats.

The Role of Monitoring Tools

According to the report, existing monitoring tools and controls are not self-sufficient. Specifically, security teams discovered 20% of all incidents manually. Meanwhile, enterprises missed 60% of threats because their existing tools failed to generate high-confidence alerts. Therefore, organizations must continuously configure their monitoring systems to adapt to changing threat methods.

The human element remains vital in analyzing low-confidence alerts that often go uninvestigated. Security analysts must actively review these alerts to identify hidden activities. Without human intervention, automated tools cannot provide complete protection against sophisticated attacks.

Backup Vulnerabilities and Communication Gaps

Backup systems represent a significant vulnerability for many organizations. The analysis revealed that 40% of discovered web shells resided undetected in backups. As a result, malicious files could be restored after initial incident response activities were completed. Consequently, security teams must thoroughly inspect backup integrity and content.

Furthermore, internal communication issues affected 32% of the compromise assessments. These issues included unclear action confirmations and knowledge loss due to staff turnover. Therefore, organizations need to test their communication workflows alongside technical playbooks.

Recommendations for Threat Response

To improve security postures, organizations must update their response plans to prevent future cybersecurity incidents from remaining undetected. Amged Wageh, an expert at Kaspersky Compromise Assessment, stated that proactive security audits make it more likely that organizations will detect a compromise. He added that integrating regular, third-party assessments reduces the probability of high-severity incidents.

“Proactive security audits make it more likely that organizations will detect a compromise. Integrating regular, third-party compromise assessments into organizational processes can reduce the probability of unexpected high-severity incidents and improve overall risk posture.”

Amged Wageh, Expert at Kaspersky Compromise Assessment

Kaspersky recommends conducting a detection engine health check within 30 days. In addition, organizations should introduce a validation team to review low-confidence events. Finally, establishing operational-level agreements can facilitate communication between different teams during an incident.