- Unauthorized application use: 70% of IT professionals believe the use of unauthorized programs resulted in as many as half of their companies' data loss incidents.
- Misuse of corporate computers: 44% of employees share work devices with others without supervision.
- Unauthorized physical and network access: 39% of IT professionals said they have dealt with an employee accessing unauthorized parts of a company's network or facility.
- Remote worker security: 46% of employees admitted to transferring files between work and personal computers when working from home.
- Misuse of passwords: 18% of employees share passwords with co-workers. That rate jumps to 25 percent in China, India, and Italy.
Tuesday, April 5, 2016
Plugging Data Leaks
Tuesday, September 17, 2013
World's Biggest Data Breaches [Infographic]
Cool and disturbing at the same time. A fully interactive version can be found here where you can click each circle to get more information. I thought about adding all the numbers but stopped at 140,621,000 between 2012 and 2013.
ps
Related:
- How To Cushion The Impact Of A Data Breach
- Security Spending On The Rise As Threats Proliferate
- Quantifying Reputation Loss From a Breach
- 5 Stages of a Data Breach
- 20,000 For Every 1
- Lost Records a Day Shows Doctors are Blasé
- The Real Reasons to Secure Your Infrastructure
- Small Business is a Big Target
| Connect with Peter: | Connect with F5: |
| |
Tuesday, July 16, 2013
20,000 For Every 1
On average.
Earlier this month, the State of California released its first annual data breach report showing that in 2012, 131 data breaches were reported putting more than 2.5 million Californians personal data at risk. The real kicker is that of the 2.5 million, 1.4 million would have been fine if the companies had simply encrypted the data. Yup, over half would've been safe if proper care was taken to protect the data. A bit aggravating isn't it? With all the basic solutions available and data breach media attention you'd think encryption was a no brainer. Add to that, if it was scrambled, it wouldn't have even needed to be reported according to state law! Companies can even avoid data breach lawsuits (in California) for encrypting data. So many reasons.
Retail had the most intrusions with 26% followed closely by finance and insurance with 23% of the total. Health care accounted for 15% with education and government both taking 8%. The remaining 15% represented the ever popular 'other.' Over half included included compromised social security numbers and 5 involved more than 100,000 citizens.
Security and computer failures, including skimmed point-of-sale devices, accounted for the majority of the intrusions with outsiders doing the most damage. Always check those ATMs, gas station pumps, unattended kiosks and other machines you slide with your cards. Sadly, even with personal diligence, once the company has it, they seemingly still let it roam free. I guess the good news is the requirement to report the breaches so individuals are aware and can take action.
This is is the first state-based, state-specific review of reported data breaches and the California Attorney General's Office recommends that companies focus on improving the following areas of privacy and security:
- Encryption - If you have unencrypted personal information, you'll probably be next.
- Security Training – Review and update security procedures, as well as provide regular training to maintain compliance.
- Readability of Consumer Breach Notifications – Companies should ensure that recipients actually understand the content of such notices.
- Offering Credit Monitoring Assistance – When offered to consumers, it can limit future issues.
Hopefully, in the near future other states will release their own reports to better understand their situations in context to the all the yearly, national reports.
ps
Related:
- Lessons From The California AG’s Data Breach Report For The Health Care Industry
- California's first data-breach report finds 131 incidents hit 2.5 million citizens
- CA Data Security Breach Reporting
- California data breach study indicates lack of encryption
- California data breach report: 2.5M residents at risk of identity theft
| Connect with Peter: | Connect with F5: |
| |
Wednesday, April 24, 2013
Targets of Opportunity
#dbir
...Is one of the findings in #Verizon's 2013 Data Breach Investigations Report, which is chuck full of interesting data. 75% of the attack victims were selected because they had a weakness that an attacker knew how to exploit rather than being specifically chosen. The difficulty of the initial compromise was low for 68% of the breaches meaning the attackers used basic methods or automated tools and scripts. It also means that there are sloppy configurations, needless services and exposed vulnerabilities that are bringing this attention.
Overall, the report covers 47,000 reported security incidents, of which, there were 621 confirmed data breaches. This is important since they focus on the 621 confirmed data loss incidents rather than the 47,000 reports. There will probably be a ton of articles reporting the results but a good place to start is securosis.com with their How to Use the 2013 Verizon Data Breach Investigations Report. This is a great primer for the document.
There is a pretty even distribution of industries hit from financial to retail and restaurants to manufacturing, transportation and utilities to government and defense contractors. The overwhelming majority of attacks are perpetrated by outsiders at 92% of the confirmed data breaches with insiders at 14%. Interestingly, for all reports (the 47,000 not just the 621 confirmed) insiders accounted for 69% of the incidents. Typically this was due to carelessness rather than criminal misuse. 76% of the network intrusions exploited weak or stolen credentials and most often, the attack was driven by financial motives at 75%.
Some other interesting data for me was that 66% of the breaches remained undiscovered for months or more and 69% of those were discovered by outside entities. So organizations are in the dark about their intrusions, and it takes an outsider to point it out. It's like those people who drive away with the gas hose still hooked to their tank.
I was also curious about breaches as a result of BYOD. Not many. In 2011 they only saw 1 breach that involved personally owned devices and only a couple more in 2012. They will keep watching and do expect that it may increase but for now, so far so good. Could be because while BYOD is a hot topic, most surveys indicate that only around half the organizations are digging in.
There is a ton more valuable data in the report and it is an easy, fun read for 63 pages of stats. Right on page 2 they say, 'Some organizations will be a target regardless of what they do, but most become a target because of what they do. If your organization is indeed a target of choice, understand as much as you can about what your opponent is likely to do and how far they are willing to go.' Put it on your list.
ps
Related:
- 2013 Data Breach Investigations Report
- How to Use the 2013 Verizon Data Breach Investigations Report
- Verizon's 2013 Data Breach Investigations Report: Highlights
- OBSERVATIONS ON THE 2013 VERIZON DATA BREACH INVESTIGATIONS REPORT
- Hacktivists Change Tactics From Data Breaches to Disruption: Verizon
| Connect with Peter: | Connect with F5: |
| |

