Thales News Release

Survey: 94% Of Australian Organisations Vulnerable To Data Threats

August 17, 2016

85% of organisations already breached by cyberattacks, 31% breached in the last year 2016 Vormetric Data Threat Report – Australia Edition

SYDNEY, Australia. – August 16, 2016 – Thales eSecurity, a Thales company, and a leader in enterprise data protection for physical, virtual, big data, and cloud environments, today announced the results of the Australia Edition of the 2016 Vormetric Data Threat Report (DTR). The report is issued in conjunction with analyst firm 451 Research, reporting responses from senior IT security executives at large enterprises worldwide, including 100 from Australian organisations. This edition of the fourth annual report extends earlier findings of the global report, focusing on responses from IT security leaders in Australian organisations, which detail IT security spending plans, perceptions of threats to data, rates of data breach failures and data security stances.

“A staggering 85 percent of Australian respondents claim to have been breached at some point in the past, well ahead of the global average of 61 percent,” said Garrett Bekker, senior analyst, information security, at 451 Research and the author of the 2016 Vormetric Data Threat Report. “Another concern, planned increases in security spending to protect data, at 50 percent, are below any other region surveyed except for Japan at 32 percent.”

Key findings from the report include:

  • 94 percent of Australian organisations feel somewhat or more vulnerable to data threats, and had the highest rate worldwide of feeling ‘very or extremely’ vulnerable at 54 percent.
  • 85 percent had experienced a data breach in the past, well ahead of second-ranked Germany at 72 percent and the global average of 60 percent. 31 percent had been breached in the last year, also well ahead of the global average of 22 percent
  • When asked to pick the three most important reasons for securing sensitive data, the top answers were ‘compliance’, given by 51 percent of Australian organisations, ‘reputation and brand protection’, given by 39 percent and ‘this organization has experienced a data breach in the past’, given by 37 percent
  • 46 percent of Australian respondents planning to adopt Internet of Things (IoT) technologies, with protecting IoT devices from privileged user access the top IoT concern at 35 percent
  • 34 percent are plan to store sensitive data in the cloud, and 75 percent are worried about data breaches at their cloud provider
  • Planned increases in IT security spending by Australian organisations for the next 12 months are highest for ‘network defences’ 32 percent), ‘analysis and correlation tools’ (32 percent) and ‘endpoint and mobile defences’ (29 percent)

Click To Tweet: Aussie IT Security Pros worried about their data

Compliance continues to act as a security driver – but compliance alone is not enough

Although there is a growing appreciation that the impact a data breach has on a brand’s reputation cannot be underestimated, Australian organisations continue to strongly associate compliance with security, despite data breaches continuing to affect organisations that have been certified as compliant.

“Compliance does not ensure security,” continues Bekker. “As we learned from data theft incidents at companies that had reportedly met compliance mandates (such as KMART Australia, Vodafone, David Jones and Woolworth), being compliant doesn’t necessarily mean you won’t be breached and have your sensitive data stolen. Australian organisations don’t seem to fully appreciate this, with more than half (51 percent) rating compliance as a top reason for protecting data, and with compliance the topmost IT security spending priority (52 percent).”

Organisations are spending ineffectively to prevent data breaches

With nearly one in three Australian organisations experiencing a breach in the last 12 months, it is surprising that the increased spending rate to protect data is second to last in the world at 50 percent. Even more surprising is where any increase will be spent. Most are planning investments in tools like network (32 percent) and endpoint defences (29 percent) which have been proven to be largely ineffective against current threats to company data.

“Enterprises and public sector organisations are being asked to better safeguard confidential and sensitive information,” said Tina Stewart, vice president of marketing for Vormetric. “It’s therefore surprising that companies continue to use the same perimeter-based tools that consistently fail against modern, multi‐layered attacks. Technology that concentrates fundamentally on controlling access to data and protecting tdata is a far more affective approach..”

The research report is available from Thales and can be found here.

About 451 Research

451 Research is a preeminent information technology research and advisory company. With a core focus on technology innovation and market disruption, we provide essential insight for leaders of the digital economy. More than 100 analysts and consultants deliver that insight via syndicated research, advisory services and live events to over 1,000 client organizations in North America, Europe and around the world. Founded in 2000 and headquartered in New York, 451 Research is a division of The 451 Group.

About Vormetric, a Thales company

Thales eSecurity’s comprehensive high-performance data protection platform helps companies move confidently and quickly. Our seamless and scalable platform is the most effective way to protect data wherever it resides—any file, database and application, in any server environment. Advanced transparent encryption, powerful access controls and centralized key management let organizations encrypt everything efficiently, with minimal disruption. Regardless of content, database or application—whether physical, virtual or in the cloud—Vormetric Data Security enables confidence, speed and trust by encrypting the data that builds business. Vormetric Data Security was recently acquired by Thales Group and is now a Thales company.

Please visit: and find us on Twitter @Thalesesecurity.

About Thales

Thales is a global technology leader for the Aerospace, Transport, Defence and Security markets. With 62,000 employees in 56 countries, Thales reported sales of €14 billion in 2015. With over 22,000 engineers and researchers, Thales has a unique capability to design and deploy equipment, systems and services to meet the most complex security requirements. Its exceptional international footprint allows it to work closely with its customers all over the world.

Positioned as a value-added systems integrator, equipment supplier and service provider, Thales is one of Europe’s leading players in the security market. The Group’s security teams work with government agencies, local authorities and enterprise customers to develop and deploy integrated, resilient solutions to protect citizens, sensitive data and critical infrastructure.

Drawing on its strong cryptographic capabilities, Thales is a global leader in data protection and one of the world leaders in cybersecurity products and solutions for defence, critical infrastructure and telecommunication operators, industrial and financial companies. Covering the entire cybersecurity chain, Thales offers a comprehensive range of services and solutions that includes: cybersecurity consulting and testing, cyber-secured software centric system design / development / integration and certification, provision and through-life management of data protection products and services, secured IT outsourcing and cloud computing solutions, as well as managed security services based on our network of Security Operation Centers in France, the United Kingdom and the Netherlands.


Andy Kicklighter
Thales Media Relations
+1 408-908-6260
akicklighter@vormetric.comDorothée Bonneil
Thales Media Relations – Security
+33 (0)1 57 77 90 89
dorothee.bonneil@thalesgroup.comLiz Harris
Thales Media Relations
+44 (0)1223 723612