Showing posts with label Industry Report. Show all posts
Showing posts with label Industry Report. Show all posts

Thursday, February 16, 2012

Cool Websense Security Survey Infographic

Content Security and Data Loss Prevention company, Websense in conjunction with independent research firm Dynamic Markets just released their "Security Pros & ‘Cons’" survey. IT managers and non-IT employees in the U.S., UK, Canada, and Australia where they asked about the latest threats to corporate and personal security, including modern malware and advanced persistent threats (APTs).
Websense has condensed the findings of the study into an easy to read infographic. The portion of the infographic below is one of the more interesting data points collected regarding a "false sense of security" that is felt by many IT managers. They know that they need to protect their organization against modern malware and web 2.0 threats, but 52% of IT managers do not protect their organization from confidential data being uploaded to the web.
Fortunately, help is on the horizon as headline-grabbing security incidents have promoted data security talks amongst top management and have driven focus on security, including the need for additional budget. Click here to download the full report 

Monday, November 28, 2011

Cyber Monday Means Loss of Productivity

As Black Friday has come and gone many consumers are excited for Cyber Monday. The only problem? Many Americans who plan to partake in the deals offered online are doing so at work. According to a recent survey done by the staffing firm Adecco,nearly half of American workers (46 percent) plan to make a dent in their holiday shopping during work hours – either through online shopping while at work, shopping on lunch breaks, taking sick days or cutting out a little early periodically. Another similar survey done by Randstad shows that 40% of employees plan to only spend an hour online shopping at work while 1 in 3 plan to spend over 5 hours of their work day shopping online.


The lure of online deals does not only pose a threat to productivity, but it can also expose the corporate network to malware. Malware and spam attacks are often quickly formulated and executed based on current events and popular online happenings. These malicious websites are found as links that are a part of common searches such as "Cyber Monday Deals". 


Since many people will be ordering online the use of online postal tracking will go up as well, because of this hackers will be sending postage and shipping related emails to trick people into downloading malicious attachments. Websense Security Labs cites this type of spam as one of the "Top 5 Malicious Spam Subjects" .


Security Labs has detailed the type of subjects and email contents everyone should be on the lookout for.

  • USPS Invoice copy ID46298 (numbers vary)
  • FedEx: New Agent File Form, trackid: 1V6ZFZ7FEOHUQ (numbers vary)
  • DHL Express Notification for shipment 90176712199 (numbers vary)
The email will look like this:
The moral of the story is to shop at home, be careful, and no matter how good the deal looks, do not suspend judgement to click on a strange looking link. Also remember that shipping companies will never require you to download an email attachment to get information about your packages and if you are still concerned, check their website for accurate and up to date information.


Thursday, November 10, 2011

Two-fer Thursday!

It is rare that we see two security and data breach related reports cause a stir on the same day. However, today Forrester and lesser known Risk Based Security Inc. delivered two reports with a similar theme -- data breaches can and will affect you personally as well as your organization.


Forrester reports that in a questionnaire distributed to 2,300 IT executives via LinkedIn 25% responded that their organization has had a data breach in the last year. Even more surprising, 21% declined to answer despite being assured that names and responses are kept confidential. 7% of very honest IT executives reported that they don't know and Forrester believes that many of the remaining who reported no breaches in the last year, were probably breached but just don't know it yet.


The above findings by Forrester make this second report more understandable but no less shocking. According to Risk Based Security Inc. and research done by the Open Security Foundation as of October 2011 there have been over 1 billion records exposed. In the first nine months of 2011 we have seen  176,385,870 records exposed compared to 88,473,589 records for all of 2010.


All of these statistics server to prove a point that organizations still are not taking the necessary measures to protect their data and the data of their customers and clients. When it comes to securing your organization taking a holistic approach is the first step to enforcing better protection. By better understanding business needs and processes your security department can better determine where risks reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.


Links to the above reports
Forrester
Risk Based Security Inc.

Monday, November 7, 2011

Advanced Persistent Threats -- Something to worry about or just another buzzword?

In recent months there has been increased discussion in the media about advanced persistent threats (APTs) and even more discussion about how to define an APT. McAfee defines an APT as a "targeted cyberespionage or cybersabotage attack that is carried out under the sponsorship or direction of a nation-state for something other than a pure financial/criminal reason or political protest." Other definitions are more broad describing an APT as a cybercrime category in which the attacker utilizes the full spectrum of attack vectors to reach and compromise the their target. 


Whatever definition is used often is the definition that best serves the main goal of the article or advertisement, which has lead many IT security professionals to put advanced persistent threats in the "buzzword" category. It seems that despite those non-believers almost two-thirds of enterprise information security managers believe their businesses have been targeted by advanced persistent threats and  72% expect to see such attacks continue in the future. These numbers are according to an Enterprise Strategy Group report on  advanced persistent threats. These managers believe that these attacks are being carried out, in order of likelihood, by hacktivist groups such as Anonymous, organized crime rings, competitors conducting reconnaissance or perpetrating industrial espionage, foreign governments, and terrorists.

Whether or not APT is just another catchy acronym we can see that based on the survey results, organizations are responding in the correct way. 51% of respondents said that senior executives have increased the amount of money allocated to training employees on security strategies, 33% now meet more frequently with their Chief Information Security Officer (CISO) or IT risk team and 18% have created the role of CSO or CISO, or another type of senior security position.  The trend of organizations to staff Risk and Security related positions, as direct report positions to the Board of Directors, continues to demonstrate the importance of integrating technology with business process.  Risk and Security of the organization and its critical technology infrastructure (uptime and productivity) and its confidential and sensitive data (GRC, Brand Loss, IP Loss) should be a fundamental to any best-practices organization.   


With the increasing sophistication of the threat matrix, reliance on under managed technologies (AV, IPS, IDS) is simply not enough.  As we continue to build more efficient and open B2B and B2C models, an organization must take into account the context of the information being accessed starting with the roles of people accessing that information, the sensitivity of the information, and the actual use of the information, and enforcement policies.   This takes coordination, via the CISO, of Executives, HR, Legal,  Technology , and Business Unit leaders.

Wednesday, June 22, 2011

Mansfield, Ohio -- Area Agency on Aging: Breached due to Lost Laptop

On June 3, an employee of the Area Agency of Agency in Mansfield, Ohio had a laptop stolen from their car. This resulted in the exposure of personal data related to 43,000 customers.  The laptop was assigned to a Passport case manager. The personal data was health related in nature and also contained the  personal contact information of 35,000 related clients' personal representatives.  


According to a report in The Morning Journal  the Area Agency on Aging had the following response to the Breach:


“The Area Agency on Aging understands the importance of safeguarding our consumer’s personal information and takes that responsibility very seriously,” said Duana Patton, chief executive officer. “We deeply regret that this incident occurred, and we have already taken steps to ensure our laptops are properly equipped to secure personal information from unauthorized access in the future.” 


Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information. 


Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained  unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill. 


According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon

77% Of Business Experienced Data Loss Last Year

A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.

The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.

Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.

Friday, February 25, 2011

Mobile Internet Adoption Introduces a New Level of Risk


The graph above shows mobile Internet growth accelerating at rates unseen before. This growth is higher than the Internet adoption rate of AOL or Netscape. Businesses see this growth, and are actively devising business strategies to drive revenue via these devices.
  
Mobile devices are becoming as powerful as our desktops and laptops, and the data that is stored on these mobile devices needs to be equally protected.

How will we manage this quickly-growing service? Going forward, Mobile Internet devices like SmartPhones and tablet PCs need security too. It is not just your internal network. Proactively manage your risk by creating a risk strategy with these devices in mind.