McAfee this week published a report that turns familiar survey findings on their heads by reporting that most cybersecurity breaches are the result of lax IT processes rather than mistakes made by end users.
Surveying 700 cybersecurity professionals working in organisations with more 1,000 employees, the “Grand Theft Data II” report finds 52 per cent of respondents claim IT is at fault when a data leakage event occurs, versus 29 per cent who cite business operations.
Candace Worley, the chief technical strategist for McAfee, said that while the number of incidents in which IT teams are deemed at fault may seem high, it’s important to remember that IT teams also have the most opportunity to make a mistake by, for example, misconfiguring a server.
Overall, the survey finds 61 per cent of respondents claim their current employer has been impacted by a data breach. The survey also finds that on average survey respondents have dealt with six breaches over the course of their professional lives. That number, however, may be low depending on whether respondents viewed a data breach to be an event significant enough to be worth reporting, noted Worley. However, the survey also finds that nearly three-quarters of the breaches cybersecurity professionals have needed to address either required public disclosure or affected financial results.
The survey also finds the causes of most data breaches have not changed much in recent years. The top three methods employed by cybercriminals to exfiltrate data, according to the survey results, are database leaks, cloud applications and removable USB drives. In addition, 61 per cent of all incidents are discovered by the internal security team.
While the number security incidents are clearly up, Worley said it’s not clear whether there are truly more attacks being launched, cybercriminals are just becoming more successful or whether IT security teams have simply become better at discovering them. All three of those factors are likely at play, noted Worley.
Cyberattacks: Preparing For The Inevitable
It is generally accepted that it is when, not if, large organisations will be the target of malicious cyberattacks. The importance of being prepared has been laid out in a blog post Sweat In Peace, Don't Bleed In War, written by Meredydd Hughes, a former UK chief constable with substantial crisis management experience.read more
Varonis Blog Highlights 110 Cybersecurity Statistics
Cybersecurity company Varonis has issued its predictions for the forthcoming year with a blog post entitled 110 Cybersecurity Statics For 2020. The blog states that cybersecurity issues are becoming a day-to-day struggle for businesses. Recent trends and cybersecurity statistics reveal a huge increase in hacked and breached data from sources that are increasingly common in the workplace, like mobile and IoT devices.read more
UK To Go On The Cyber Offensive
The UK Government is about to launch a new proactive and offensive cybersecurity team that will wage cyberwarfare against hostile nation-states and online crime organisations. It would be naive to believe that the UK has not launched cyberattacks against third parties, but the killing of Qassem Soleimani has brought this out into the open.read more
Are You Ready For Iranian Revenge Cyberattacks?
Following the killing of Qassem Suleimani no-one can be sure of what military action Iran will take, but experts agree that its cyberattacks will increase against countries and governments it sees as hostile.read more