How most businesses are still getting security wrong

By on
How most businesses are still getting security wrong

The vast majority of breaches use old techniques that are easily preventable, according to a new report.

Verizon's 2017 Data Breach Investigations Report has revealed that of the almost 2,000 breaches and security incidents that were analysed, a whopping 81% used easily-guessed or stolen passwords.

Furthermore, over 65% of malware infections were delivered via email attachments – a technique that has been around for decades. Pretexting – a form of social engineering used to obtain privileged information – is also on the rise.

With so many enterprises falling victim to age-old tactics, why are businesses still failing to take basic security measures like strong password hygiene and regular data backups?

“It's a very good question, and it's one we ask ourselves on a recurring basis, because this is not the only year that we find that the human vector is probably the most susceptible, and theoretically the easiest one by which to combat things," said Verizon's director of international security solutions, Ali Neil.

“You don't have to pay a fortune for a SIEM (security information and event management) solution or an intrusion detection solution, you actually have to enforce some basic standards,” he added. “Our message is that training is the simplest thing you can do with people.”

“You can't patch stupidity”

Not everyone agrees, however. Fraser Kyne, an IT executive at tech company Bromium, said that companies need to spend less time focusing on employee training, not more.

“What most interested me in this year's report was that phishing attacks are actually becoming even more prevalent,” he said. “One in 14 users are being duped into clicking on a bad link or attachment; but even worse, a quarter of those people go on to do it again. There is a phrase that I think is very apt here – ‘You can't patch stupidity’.

“Organisations therefore need to shift the onus away from controlling user behaviour if they are to get a handle on the situation. The best way of mitigating phishing attacks is to have a safety net in place, allowing end users to click with freedom, without having to worry too much about stumbling upon a bad link or malicious attachment.”

Ransomware up by 50%

Verizon's latest annual security report included further interesting findings, such as the fact that organised crime gangs were behind more than half of all breaches, almost 70% of all threats to healthcare come from within the organisation, and around 50% of attacks on educational institutions were perpetrated by state-affiliated hackers.

Unsurprisingly, ransomware has also gone up by 50% compared to last year's report. Across the numerous reports put out by the security industry, a consistent rise in ransomware activity is one of the universal constants.

“Our vision is to unite industries with the end goal of confronting cybercrime head-on, and we are achieving this,” said Verizon enterprise solutions' executive director of global security services, Bryan Sartin.

“The success of the Data Breach Investigations Report series is thanks to our contributors who support us year after year. Together we have broken down the barriers that used to surround cyber crime – developing trust and credibility. No organisation has to stand in silence against cybercrime - the knowledge is out there to be shared.”

This article originally appeared at IT Pro.

Copyright © ITPro, Dennis Publishing

Most Read Articles


What would you like to see more of on BiT?
How To's
Photo Galleries
View poll archive

Log In

  |  Forgot your password?