Commentary

Randy George
 

Verizon Releases Data Breach Investigation Report

The Verizon Business Investigative Response team recently released a report detailing the facts and figures associated with system breaches from more than 500 cases over the past 4 years. The report mostly contains obvious information regarding the who, what, where, and how of most data breaches, but it's worth reading. There were some pretty interesting statistics and factoids contained in the piece.

The Verizon Business Investigative Response team recently released a report detailing the facts and figures associated with system breaches from more than 500 cases over the past 4 years. The report mostly contains obvious information regarding the who, what, where, and how of most data breaches, but it's worth reading. There were some pretty interesting statistics and factoids contained in the piece.As I read through the report, here's what jumped out at me.

• 73% of data breaches resulted from external sources, including business partners.


More Software Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

• The Retail, Food & Beverage and Financial Services industries were disproportionate targets of data breaches, clearly due to their concentration and possession of personal credit card data.

• While 73% of data breaches came from outside sources, the damage done in terms of the number of records compromised paled in comparison with the damage done by internal attacks. The median number of records compromised by an internal job was 375,000.

• 80% of breaches were classified as low to medium in terms of difficulty to execute. Only 17% were deemed to be of a high difficulty to execute, which high difficulty being defined as needing specialized skills and resources in order to pull off the hack.

• 70% of the time, victims of breaches are notified by third parties. That's a pretty interesting fact, so what's the cause? Do IT shops lack the tools? Does the market lack an integrated, easy to manage offering to solve the problem? Are IT shops just not watching? I suspect all three are factors.

Here's the most shocking and alarming statistic for me: • 90% of breaches utilized exploits for which there was a patch available for at least 6 months. Now I won't claim to be the most diligent engineer when it comes to applying security patches to my servers, but if you get hacked using an exploit for which there's been a fix for 6 months, you, and I, have no one to blame but ourselves.

Want to read the full report? Follow this link.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links