Over the years, organizations have been investing more in automation and agility. However, the risks are growing, as there is actually a lack of awareness of the existence of privileged credentials in DevOps, RPA (robotic process automation), and the cloud.
According to CyberArk's 2019 Global Advanced Threat Landscape report, less than 50% of organizations have an access security strategy for DevOps, IoT, RPA, and other technologies.

Thus, hackers have the ability to exploit legitimate access and move in this way towards achieving their goal.
Preventing this lateral movement is one of the reasons organizations are mapping out their security investments. 28% of total planned security spending over the next two years is focused on stopping privilege escalation and lateral movement.
Of those surveyed, 78% identified hacker attacks as one of the top three threats: organized crime, activists, and privileged insiders. On the other hand, 60% of respondents cited phishing , followed by ransomware and Shadow IT.
In practice, the research showed that while organizations consider privileged access security a key component of an effective cybersecurity program, this understanding has not yet translated into action to protect digital transformation technologies.
84% of organizations surveyed said that IT and critical data will never be fully secure without securing privileged accounts and credentials. However, only 49% have a security strategy in place to safeguard them.

CyberArk executive vice president of global business development, Adam Bosnian, said that more and more organizations are understanding the importance of cyber kill chain and why lateral movement is critical to security. He added that this awareness is not enough and needs to be translated into implementing proactive strategies to significantly reduce risk.
The survey also shows that 41% of organizations are willing to pay fines for non-compliance with basic regulations, but will not change security policies even after a successful cyberattack.
The survey also looked at the impact of major regulations on organizations. This section of the survey found that 46% of organizations are fully prepared for a breach within 72 hours. 62% of Australian respondents said they were fully prepared to comply with the entire statute, which came into effect in February 2019. Finally, only 37% are ready to implement California’s consumer protection legislation in 2020.
