The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

InformationWeek's Analytics Weblog

Topics:   Analytics : Compliance : Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Verizon Breach Report Challenges Conventional Wisdom


Posted by Mike Fratto, Apr 16, 2009 09:11 AM

Verizon Business' most recent 2009 Data Breach Investigations Report is a must-read report if you're involved in IT. The authors are quick to point out that the report is not a "state of security" report, but an analysis of breaches from Verizon Business' Risk Team and therefore based on in-the-field findings. The report winds up with recommendations. How many is your company following?


The findings challenges commonly held beliefs, like insiders compromise the biggest threat. 74% of the attacks were from external sources and accounted for 266,788,000 records; 32% from partners accouting for 1,509,000 records; a paltry 20% from insiders accounting for 1,330,000 records; and 39% were from multiple sources accounting for 15,796,000 lost records. On a per breach basis, insiders were responsible on average for more records lost per breach, 100,000, while external sources accounted for a median 37,847, and partners 27,000. Which poses a bigger threat? The most active group, external sources, or the more effective group, internal sources? It doesn’t much matter, does it? What this tells me is that information security programs need to focus on protecting information. The insider versus outsider view is a symptom of technology focused security—something long time contributor Greg Shipley noted in 2003’s Network Computing Secure to the Core cover story. His points are just as valid today as then.

In the view of Verizon’s Risk team, the attack difficult of 83% of the breaches are relatively moderate, characterized as needing "skilled techniques, some customization, and/or significant resources required to carry off." That’s a pretty broad definition, but I’d interpret it to mean well within the realm of most IT people and computer nerds. Luckily 95% of the breaches resulting in lost records were rated as high difficulty characterized as "advanced skills, significant customization, and/or extensive resources required."

What may surprising to many folks in security is that PCI enforcement seems to work better than not. There is a lot of discussion as the value of PCI and is a favored whipping post. The data and the authors data indicates that while PCI compliance is not a guarantee against breaches, 81% of companies either weren’t compliant are weren’t PCI assessed at the time of the breach. On table 10 on page 42, the authors relates the number of companies compliant with the top line PCI requirements. Their conclusion is a typical organization met a third of PCI requirements.

The report winds up with conclusions and recommendations. Regardless of whether your company is large or small, in a regulated market or not. There are take ways you can implement that are well within any IT department skill set. Better, get a copy of PCI or ISO 27001:2005 which I described in 2006, and align your IT processes with the goals. Alignment is not about checking boxes but matching processes with the stated goals of PCI or ISO 27001.

« SAP Performs Heart And Lung Transplant On Australian Bank | Main | Google's Gain Is Yahoo's Pain »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. No Silver Bullet for Parallelism
  2. Think Parallel 2010, Five Years of Multicore
  3. It's All In the Strategy, It's All About the Design


Join The InformationWeek Group On LinkedIn


  1. Verizon Wireless Details Android 2.1 Update For Droid
  2. Google Overhauls Maps For Android
  3. 'Hundreds Of Thousands' Of iPads Ordered So Far
  4. Advantages Of PCI-Based SSDs


  1. GAO: Multiple Failures Sunk Border Security System
  2. Adobe Flash CS5 For Windows May Violate Apple Rules
  3. FCC Tests Spectrum Dashboard
  4. Samsung, LG Forecast Smartphone Gains
  5. White House Shutters Financial Systems Standards Effort
  6. NIST Intros Health IT Systems Test Framework

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007