McAfee this week published a report that turns familiar survey findings on their heads by reporting that most cybersecurity breaches are the result of lax IT processes rather than mistakes made by end users.
Surveying 700 cybersecurity professionals working in organisations with more 1,000 employees, the “Grand Theft Data II” report finds 52 per cent of respondents claim IT is at fault when a data leakage event occurs, versus 29 per cent who cite business operations.
Candace Worley, the chief technical strategist for McAfee, said that while the number of incidents in which IT teams are deemed at fault may seem high, it’s important to remember that IT teams also have the most opportunity to make a mistake by, for example, misconfiguring a server.
Overall, the survey finds 61 per cent of respondents claim their current employer has been impacted by a data breach. The survey also finds that on average survey respondents have dealt with six breaches over the course of their professional lives. That number, however, may be low depending on whether respondents viewed a data breach to be an event significant enough to be worth reporting, noted Worley. However, the survey also finds that nearly three-quarters of the breaches cybersecurity professionals have needed to address either required public disclosure or affected financial results.
The survey also finds the causes of most data breaches have not changed much in recent years. The top three methods employed by cybercriminals to exfiltrate data, according to the survey results, are database leaks, cloud applications and removable USB drives. In addition, 61 per cent of all incidents are discovered by the internal security team.
While the number security incidents are clearly up, Worley said it’s not clear whether there are truly more attacks being launched, cybercriminals are just becoming more successful or whether IT security teams have simply become better at discovering them. All three of those factors are likely at play, noted Worley.
Europol Releases Latest IOCTA Report
Each year, Europol’s European Cybercrime Centre (EC3) publishes the Internet Organised Crime Threat Assessment (IOCTA), its flagship strategic report on key findings and emerging threats and developments in cybercrime — threats that impact governments, businesses and citizens in the EU.read more
European Cybersecurity Month 2019 Is launched
October marks the kick-off of the European Cybersecurity Month (ECSM), coordinated by the European Union Agency for Cybersecurity (ENISA), the European Commission and supported by the Member States. This campaign will focus on expanding awareness about cybersecurity to citizens across Europe.read more
Remote Desktop Attacks Increasing
The Remote Desktop Protocol (RDP) is being used by cyberattackers to penetrate and extract data from a network before introducing their malicious software to perform internal reconnaissance, according to a new Vectra 2019 Spotlight Report on RDP.read more
LexisNexis Report On Cybercrime Has Shock Figures
LexisNexis Risk Solutions has released at the Digital Identity Summit its Cybercrime Report providing a comprehensive view into the shifting global fraud landscape from January 2019 through June 2019. During this period, the LexisNexis Digital Identity Network recorded 16.4 billion transactions, of which 277 million were human-initiated attacks, a 13 per cent increase over the second half of 2018.read more