Information insecurity - how things are getting worse
- Mar 9, 2022
- 2 min read
Updated: Mar 18, 2022
Hackers, crackers, virus writers, spammers, phishers, pharmers, fraudsters and the whole menagerie of cyber-criminals are increasingly adept at exploiting the vulnerabilities in organisations’ software, hardware, networks and processes.
Annual surveys point to a steadily worsening situation. In 2010 the Verizon Data Breach Investigations Report, conducted with the US Secret Service, and drawing data from both the United States and internationally, found that:
data breaches occur within all sorts of organisations;
in their 2009 sample, 143 million records were compromised, across 141 reported breaches;
45 per cent of these breaches originated externally, 27 per cent internally, and 27 per cent were carried out by multiple agents.
The United Kingdom's Information Security Breaches Survey (ISBS 2014), managed by PwC, looked at the state of information security across a representative sample of UK organisations. Key findings were as follows:
81 per cent of large organisations suffered a data breach; 60 per cent of small organisations had a breach;
Large organisations had a median 16 breaches in the year, while small organisations had a median of 6
The average cost to a large organisation of its worst breach was between £600k and £1.15 million.
For a small organisation, the range was between £65k and £115k.
Seventy-three per cent of large respondents suffered from a malware or virus infection.
Fifty-five per cent of large respondents suffered an external attack;
38 per cent suffered a denial of service attack and only 24 per cent per cent were able to identify that their defences had actually been penetrated.
Fifty-eight per cent of organisations suffered staff-related security breaches; 31 per cent of the worst breaches were caused by inadvertent human error.
Surveys and data from other OECD economies suggest that a situation similar to that in the United Kingdom can be found across the world. Hackers, crackers, virus writers, spammers, phishers, pharmers, fraudsters and the whole menagerie of cyber-criminals are increasingly adept at exploiting the vulnerabilities in organisations’ software, hardware, networks and processes.
As fraudsters, spam and virus writers, hackers and cyber criminals band together to mount integrated attacks on businesses and public sector organisations everywhere, the need for appropriate cyber security defences increases.
Often - but not always - information security is in reality seen only as an issue for the IT department, which it clearly isn't. Good information security management is about organisations understanding the risks and threats they face and the vulnerabilities in their current computer processing facilities. It is about putting in place common-sense procedures to minimise the risks and about educating all the employees about their responsibilities.
Most importantly, it is about ensuring that the policy on information security management has the commitment of senior managers. It is only when these procedural and management issues are addressed that organisations can decide on what security technologies they need.
Roughly one-seventh of businesses are still spending less than 1 per cent of their IT budget on information security; although the average company is spending just under 4 per cent, the benchmark against which their expenditure should be compared is closer to the 13 per cent average of organisations where managers genuinely care about information security.
That less than half of all businesses ever estimate the return on their information security investment may be part of the problem; certainly, until business takes its IT governance responsibilities seriously, the information security situation will continue to worsen.


Comments