Sloppy IT Processes Risk Cyberattacks - McAfee

McAfee this week published a report that turns familiar survey findings on their heads by reporting that most cybersecurity breaches are the result of lax IT processes rather than mistakes made by end users.


Surveying 700 cybersecurity professionals working in organisations with more 1,000 employees, the “Grand Theft Data II” report finds 52 per cent of respondents claim IT is at fault when a data leakage event occurs, versus 29 per cent who cite business operations.


Candace Worley, the chief technical strategist for McAfee, said that while the number of incidents in which IT teams are deemed at fault may seem high, it’s important to remember that IT teams also have the most opportunity to make a mistake by, for example, misconfiguring a server.


Overall, the survey finds 61 per cent of respondents claim their current employer has been impacted by a data breach. The survey also finds that on average survey respondents have dealt with six breaches over the course of their professional lives. That number, however, may be low depending on whether respondents viewed a data breach to be an event significant enough to be worth reporting, noted Worley. However, the survey also finds that nearly three-quarters of the breaches cybersecurity professionals have needed to address either required public disclosure or affected financial results.


The survey also finds the causes of most data breaches have not changed much in recent years. The top three methods employed by cybercriminals to exfiltrate data, according to the survey results, are database leaks, cloud applications and removable USB drives. In addition, 61 per cent of all incidents are discovered by the internal security team.


While the number security incidents are clearly up, Worley said it’s not clear whether there are truly more attacks being launched, cybercriminals are just becoming more successful or whether IT security teams have simply become better at discovering them. All three of those factors are likely at play, noted Worley.

more news

Half Of Global Organisations Not Prepared For Cyberattacks


It is believed that more than 4,000 cyberattacks occur daily worldwide, but half of organisations across the globe admit they are not prepared for such events.

read more

Secure Your Physical Business Against Data Theft


Data theft does not just happen in cyberspace, but in the physical business environment, too. Lax physical security can allow criminals to access your computers, filing cabinets, documents left on desktops, etc. Here are some tips for you to ensure your everyday working environment is safe and secure.

read more

UK Launches Third NCSC Annual Review


Paymaster General and Minister for the Cabinet Office Oliver Dowden MP has launched the UK's National Cyber Security Centre's third Annual Review. In his presentation speech, he said: "Thank you, everyone, for joining us this morning. Cybersecurity is genuinely a massive priority for the government and it gives me great pleasure to launch the National Cyber Security Centre’s third Annual Review.

read more

Kaspersky Releases Information Security Report


To budget for information security, companies need to consider factors such as average potential losses, preferably by incident type, as well as other businesses’ average, outlays on security. Precise data on such questions do not get published, which is why Kaspersky conducts an annual survey of employees who make business decisions related to IT security for a variety of companies. The results of its 2019 survey have just been published.

read more