HomeIntelligenceBrief
BREACH BRIEF🟡 Medium ThreatIntel

Enterprise Survey Highlights Ransomware, Phishing, and Workforce Shortage as Top Security Challenges

ESET’s 2019 enterprise survey found ransomware, phishing, OS diversity, limited visibility, poor employee security habits, and a shortage of security staff as the six biggest challenges. The findings stress the importance of continuous security‑awareness training and auditable visibility for compliance readiness.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 eset.com
🟡
Severity
Medium
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
eset.com

Enterprise Survey Highlights Ransomware, Phishing, and Workforce Shortage as Top Security Challenges

What Happened — In a 2019 interview, ESET’s Principal Product Manager Michal Jankech shared results from a survey of large enterprises. The six most‑cited security challenges were ransomware, targeted attacks, heterogeneous operating systems, insufficient network visibility, poor employee security behavior, and a shortage of skilled security staff.

Why It Matters for Trust & Control Assurance

  • The mix of ransomware and phishing underscores the need for continuous security‑awareness programs that generate defensible evidence of employee training.
  • Gaps in network visibility and staffing shortages make it difficult to maintain an auditable, real‑time view of asset posture—exactly the scenario a continuous control‑assurance platform is built to monitor and document.
  • Heterogeneous OS environments increase the surface area for mis‑configurations, demanding a control‑mapping approach that can prove consistent protection across Windows, macOS, and Linux assets.

Who Is Affected – Large enterprises across sectors (technology, education, finance, manufacturing) that operate multi‑thousand‑employee environments.

Recommended Actions

  • Map “security awareness” and “network visibility” to your audit‑readiness framework; collect training completion logs and asset‑inventory evidence.
  • Prioritize hiring or augmenting security staff through managed services that provide continuous monitoring and documented remediation.
  • Validate that security controls cover all operating systems in use and that configuration baselines are captured as evidence. Source: ESET interview

Technical Notes – The survey notes a shift from ransomware to phishing as the top perceived threat, reflecting attackers’ reliance on social engineering rather than novel exploits. No specific CVEs or malware families are cited. Source: same as above

📰 Original Source
https://www.eset.com/int/about/newsroom/corporate-blog/corporate-blog/interview-addressing-the-lack-of-it-security-specialists-with-technology-1/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →