Insider threat exaggerated, says study
Insiders are not, after all, the main threat to networks, a detailed new analysis of real-world data breaches has concluded.
Verizon's 2008 Data Breach Investigations Report, which looked at 500 breach incidents over the last four years, contradicts the growing orthodoxy that insiders, rather than external agents, represent the most serious threat to network security at most organizations.
Seventy-three percent of the breaches involved outsiders, 18 percent resulted from the actions of insiders, with business partners blamed for 39 percent -- the percentages exceed 100 percent due to the fact that some involve multiple breaches, with varying degrees of internal or external involvement.
"The relative infrequency of data breaches attributed to insiders may be surprising to some. It is widely believed and commonly reported that insider incidents outnumber those caused by other sources," the report states.
"Our caseload showed otherwise for incidents resulting in data compromise. This finding, of course, should be considered in light of the fact that insiders are adept at keeping their activities secret."
Fifty-nine percent of breaches were attributed to hacking, 31 percent involved malicious code, 22 percent exploited vulnerability, with 15 percent involving a physical threat. Sixty-two percent -- the overwhelming majority - had at their root human error.
Nevertheless, the report cautions from using the statistics to dismiss the internal threat altogether. When internal or partner security compromises happen, they tend to involve greater amounts of data. Where data loss was involved, external security breaches resulted in a media of 30,000 records being compromised, some way behind the figure for internal breaches, at 375,000.
When internal hacks occur, they tend to be nastier, with 50 percent blamed on IT staff themselves, way ahead of other types of employee.
The report concludes that honest network admins are obsessed with outdated ideas of perimeter security. Had data security been looked at within the network, almost nine out of ten data breaches could have been avoided.
"While a strong network perimeter is important, it cannot be the only or even the main layer of protection around sensitive information assets," the authors say.
» posted by abennett
Techworld.com
Build your tech library with our book giveaways.
Windows PowerShell 2.0 Unleashed
By Tyson Kopczynski, Pete Handley, Marco Shaw; Published by Sams
Windows PowerShell Unleashed will not only give you deep mastery over PowerShell but also a greater understanding of the features being introduced in PowerShell 2.0–and show you how to use it to solve your challenges in your production environment. Enter now!

Ubuntu Server Administration
By Michael Jang; Published by McGraw-Hill Osborne Media
Realize a dynamic, stable, and secure Ubuntu Server environment with expert guidance, tips, and techniques from a Linux professional. Ubuntu Server Administration covers every facet of system management -- from users and file systems to performance tuning and troubleshooting. Enter now!








