Monthly Archives: August 2026

The 2025 Global Study on Closing the IT Security Gap

Ransomware, network and application attacks, insider threats and denial of service attacks are just a few of the threats putting organizations on high alert. The increasing sophistication of cyber criminals—as well as these cyber criminals adopting AI–makes it more important than ever to become aggressive in closing security gaps in the IT infrastructure.

 New approaches to closing the IT security gap are needed. In 2023, organizations had an average of five security breaches over a 12-month period. This increased to an average of six incidents in 2024. With the difficulty in reducing breaches and security incidents, organizations are changing their activities and use of technology. Since 2023 the most significant changes are the use of comprehensive penetration testing (an increase of 17 percent of respondents), implementation of a secure and continuous data protection and backup strategy (an increase of 17 percent of respondents) and prioritization of rapid attack and breach detection (an increase of 16 percent of respondents). For the first time, the study asked if network detection and response (NDR) (42 percent), kernel detection/ silicon root verification (39 percent) and micro segmentation (32 percent) are new technologies deployed to close the IT security gap.

Optimizing AI technologies to close the IT security gap

 AI’s ability to close the cybersecurity gap depends upon close collaboration between network and security teams. Thirty-nine percent of respondents say their organizations have adopted AI to close the IT security gap. In addition to improving collaboration between network and security teams (34 percent of respondents), other AI priorities include aiding in threat investigations (32 percent of respondents) and detecting changes to the organizations’ security posture (30 percent of respondents).

 To have a successful AI strategy, organizations need assurances about AI accuracy, privacy safeguards and data leakage prevention. Organizations considered uncertainties about AI accuracy, difficulties in ensuring data privacy and difficulties in preventing data leakage their greatest challenges with AI (all 44 percent of respondents). Another possible deterrent to closing the IT security gap is not having the confidence that their organizations know and are able to secure all AI assets including infrastructure, models and data. Only 43 percent of respondents say their organizations are very or highly confident they have that visibility.

 Organizations considering the use of AI for business purposes need to evaluate the possible complexity the technology will add to their operations. Fifty-three percent of the 39 percent of respondents who have adopted AI are using AI for business purposes. The security risks created when AI is used for business purposes are increased complexity because of the addition of new security tools (57 percent of respondents), potential theft or leakage of confidential and sensitive data (47 percent of respondents) and the inability to recover lost data in the event of an attack or disaster (44 percent of respondents).

 Why the IT security gap continues to put organizations at risk

 Not having the necessary skilled IT professionals continues to be the number one barrier to closing the IT security gap.  While fewer organizations are reporting shortages in security staffing, skills and experience (30 percent vs. 39 of respondents in 2023), shortages are still affecting organizations’ security posture. Additional barriers to closing the IT security gap include security solutions that can’t keep up with exponentially increasing amounts of data and difficulty in complying with IT security and privacy industry standards or regulations (each 29 percent of respondents).

 Too many vendors to manage and lack of collaboration between network and security teams can weaken organizations’ cybersecurity posture. Fifty-six percent of respondents say managing multiple security vendors is challenging and, as a result, can diminish their organization’s security posture. Forty-seven percent of respondents say it is difficult to achieve collaboration between network and security teams. Such collaboration is critical to preventing friction between IT and security teams that hinder efforts to put an effective strategy in place.

 New approaches to securing the modern workplace

 Secure Access Service Edge (SASE) frameworks combine networking and security capabilities into a unified, cloud-based solution, ensuring seamless access and protection for distributed workforces and enterprise assets.

Organizations are at various stages in their SASE deployment. In 2024, 23 percent of respondents say their organizations have deployed SASE, 23 percent of respondents say they will deploy in 12 months and 19 percent of respondents say their organizations will deploy SASE sometime in the future.

Reduction of costs, improved application performance and improved security posture are priorities for deploying SASE. Thirty-seven percent of respondents say their organizations deployed SASE first to reduce costs and improve application performance for users and branches. Thirty-six percent of respondents say their organizations started their SASE journey with an SSE deployment to improve security posture and increase protection. The number one SASE deployment strategy is to engage a best-in-class SD-WAN vendor that integrates with SSE vendors (30 percent of respondents) followed by engaging a best-in-class SSE vendor that integrates with SD-WAN vendors (27 percent of respondents).

Universal Zero Trust Network Access (ZTNA) is a security framework that allows organizations to grant secure access to applications for subjects regardless of their location. Forty-eight percent of respondents say their organizations have deployed universal ZTNA in some form. According to the research, the three most important characteristics of the universal ZTNA approach are enabling least privilege access to support zero trust (35 percent of respondents), ensuring a seamless access experience for users anywhere (30 percent of respondents) and securing IoT devices and users (29 percent of respondents).

Closing IT security gaps in hybrid cloud environments.

Organizations are securing their hybrid cloud environments in multiple ways. The processes prioritized to minimize the risk in a hybrid cloud environment are the implementation of a defined cybersecurity compliance framework (46 percent of respondents) in 2024, securely shifting workloads from on-premises to the cloud (44 percent of respondents) and the modernization of IT security processes (43 percent of respondents).

Organizations are improving their ability to avoid security exploits and data breaches and secure workloads moving between on-premises and public cloud environments. Organizations appear to be making progress on several security fronts: The percentage of respondents who say challenges associated with avoiding security exploits and data decreased from 51 percent of respondents in 2023 to 43 percent of respondents in 2024. Similarly, the challenge of securing workloads moving from the edge to the cloud decreased from 43 percent in 2023 to 36 percent of respondents in 2024. The primary technology challenge continues to be enabling the free flow of data securely (46 percent of respondents).

Organizations are having greater difficulty in their ability to ensure the privacy of customer information and enable the free flow of information in the hybrid cloud environment.

Since 2023, more respondents say ensuring customers’ privacy and enabling the free flow of information has made it more difficult to secure the hybrid cloud environment (37 percent and 32 percent of respondents, respectively).

Separating storage and compute means they can be consumed, scaled, and priced independently. This allows businesses to pay for what they use and nothing more. Organizations in this research say their current security approach to compute and storage will change. The biggest changes organizations indicate they will face in separating storage and compute will be moving their current security approach to the cloud (28 percent of respondents), managing a combination of solutions from security and hybrid cloud infrastructure providers (25 percent of respondents) and requiring vendors to supply new security solutions (24 percent of respondents).

More organizations are making server decisions based on the security inherent within the platform (62 percent of respondents, a significant increase from 48 percent in 2023). Fifty-eight percent of respondents say their organizations require servers that leverage security certificates to identify that the system has not been compromised during delivery. Fifty-eight percent of respondents say data protection and recovery are key components of their organizations’ security strategy and 58 percent of respondents say their organizations require infrastructures that leverage chip and/or certificates to determine if the system has been compromised during delivery.

Best practices of high-performing organizations

Twenty-one percent of respondents reported that their organizations are highly effective in keeping up with a constantly changing threat landscape and closing their organization’s IT security gap. We refer to these organizations as “high performers” and compare their responses to the non-high performer respondents, referred to as “other”.

Collaboration between network and security teams is essential to a successful security strategy. Fifty-four percent of high performers vs. 40 percent of others have achieved collaboration.

High performers are most likely to have a vendor consolidation strategy. Too many vendors to manage affect an organization’s security posture. Fifty-nine percent of high performers vs. 51 percent of other respondents have a vendor consolidation strategy to improve ROI.

High performers are more likely to adopt AI. There is a significant difference in high performers and others adoption of AI (61 percent of respondents vs. 49 percent).

High performers place a higher value on NAC solutions and the integration of NAC functionality. Respondents were asked to rate the importance of NAC solutions and integration on a scale of 1 = not important to 10 = highly important. The importance of NAC solutions (60 percent vs. 41 percent) and integration of NAC functionality (56 percent vs. 41 percent) are rated higher by high performers.

When it comes to universal zero trust network access, high performers place notably greater importance on seamless access experience for users anywhere. High performers are more positive about seamless access and consistent enforcement at every location (34 percent of high performers vs. 26 percent of other respondents). Twenty-nine percent of high performers vs. 22 percent of the others rate consistent enforcement at every location higher than the other respondents.

High performers are more likely to make the identification and authentication of IoT devices accessing their networks critical to their organizations’ security strategy. Fifty-nine percent of high performers vs. 48 percent of the others are more focused on identifying and authenticating IoT devices with access to their organizations’ security strategy.

High performers are more likely to require infrastructure that leverages chip and/or certificates to determine if the system has been compromised during delivery. Sixty-six percent of high performers v. 49 percent of the others require infrastructure that leverages chip and/or certificates to determine if the system has been compromised during delivery.

Recommendations to close the IT security gap

To close the IT security gap organizations are making significant changes in their strategies to minimize threats within the IT infrastructure. These include implementing NDRs, conducting comprehensive penetration testing, prioritizing rapid attack and breach detection and implementing a secure and continuous data protection and back up strategy. New in this year’s research is organizations’ adoption of AI (39 percent of respondents). Organizations primary goals for AI are to improve collaboration between network and security teams, to aid in threat investigations and to detect changes in the organizations’ security posture.

Following are actions to consider in the coming year.

  • Develop an AI strategy. An effective AI deployment is dependent upon removing uncertainties about AI’s accuracy, ensuring the privacy of sensitive and confidential data and assessing the risks to prevent data leakage.
  • Consolidate vendors to reduce redundancies of solutions that increase costs and create inefficiencies for the IT security team. To achieve consolidation of vendors evaluate spend categories to identify vendor overlap and map vendors’ capabilities to determine where cuts can be made.
  • Improve cyber resiliency by taking steps to reduce the time to recover from a critical system failure caused by a cyber incident. As shown in this research, only 35 percent of respondents say recovery can be achieved in less than one hour (12 percent) or in 1 to 4 hours (23 percent). This includes making sure technologies are used efficiently and having a cybersecurity incident response plan in place to navigate a security crisis.

Part 2. Key findings

Ponemon Institute surveyed 2,120 IT and IT security practitioners in the United States (635), the United Kingdom (291), Germany (371), France (197), Australia (180) and Japan (446) in 2024 for publication in 2025. In this report, we present the 2023 and 2024 global findings. The audited findings are presented in the Appendix of this report. We have organized the findings according to the following topics.

  • Barriers to closing the IT security gap
  • Closing the IT security gap with artificial intelligence
  • Imperatives for controlling access: zero trust, NAC, SASE and universal ZTNA
  • Securing the hybrid cloud
  • The separation of compute and storage
  • Country differences
  • Best practices in closing the IT cybersecurity gap

To read the rest of this report, visit Hewlett Packard’s website.

A decade of heartbreaks: His identity has been used in hundreds of romance scams

Bob Sullivan

I sat down at his table and he had probably 100 cards and letters and gifts and boxes and he said, ‘I bet there’s at least 500 …. This isn’t nearly all of it.’ And he really lost count. There were just stacks of love letters and gifts and cards, and it just… the emotional power of sitting at his kitchen table that was just covered in evidence from women who believed that they were in love with him. — ABC News reporter Lisa Fletcher

Cards. Flowers. Candy.  Gifts that just never stop. It might sound quaint at first, even charming.  But every one of these love stories ended the same.  With Pat Marsh pleading for the sender to stop. Sometimes, that conversation happens at his front door…with anger and even violence hovering in the air.

“These people have also come to my house….And this is where it gets dangerous,” he told me for a recent episode of The Perfect Scam, the podcast I host for AARP.

“After about 6 months of this, one night… There was a knock at my door…and I was looking at a guy  and he was like… ‘you told me to come over.’ and I was like, “Dude, get outta here.” And that’s when he grabbed the door and he opened the door and tried to come in…  and my exact words were, ‘You’re playing a dangerous game. You need to get out of here.’ .. I would have shot him, if he had come into my house, I have shot him.”

“These people” are romance scam victims.  And the parade of victims who call, write and visit Pat Marsh has been relentless for nearly a decade. Marsh is a test pilot, a generally fascinating man who caught the attention of criminals back in 2017. They thought he’d make perfect bait for would-be lovers on dating sites, and by all accounts, the criminals were right.

Marsh is the victim of a particularly cruel kind of identity theft. No one can really say how many women and men have been enchanted by the fake Pat Marsh and various variations.  But here’s a hint: One police detective investigating a Pat Marsh romance scam in Easley, South Carolina – a widow who’d had $600,000 stolen — used email records to find 60 more cases.

Marsh is really the victim of industrial-scale crime, says Detective Eric Gillespie.

“The fake Pat Marsh here is actually probably a dozen if not more people,” he told me. “You’ve got professional outfits in West Africa and Southeast Asia that you might have 100 people who are the same person more or less, for lack of a better phrase.”

Even if you don’t believe you could ever be the victim of an online scam — and I think you are foolish for that — you should care about the surge in digital crime.  Pat Marsh is collateral damage in the ongoing international scam wars we are all fighting.  You can be next. All of us can get wrapped up in a scam even if we never communicate with a criminal.  That’s why these stories matter so much.

After a decade’s worth of investigations, TV news stories, and late-night door knocks, Marsh has no idea when his headaches will end.  He really has no control over it. Instead, an entire system needs to be changed. Online dating sites need to police their membership much more aggressively.  Banks and new money systems need to get better at policing suspicious transactions. And we all need to be more sympathetic about the isolation and boredom that create fertile ground for crime.

I hope you’ll listen to this two-part episode about the man with 1,000 fake lovers. If podcasts aren’t your thing, you can find a transcript here.