Study: most data breaches preventable.

AuthorSwartz, Nikki
PositionUP FRONT: News, Trends & Analysis - Report

The Verizon Business Risk Team reviewed more than 500 corporate data breaches between 2004 and 2007 and found that 87 percent could have been prevented--if only the companies had the proper security measures in place at the time of the breach.

After four years of forensic research involving more than 230 million records, the "2008 Data Breach Investigations Report" found that 73 percent of breaches resulted from external sources, while 18 percent were caused by insiders. Thirty-nine percent implicated business partners--a number that increased five-fold over the time period of the study--while 30 percent involved multiple parties.

The first-of-its-kind study looked at data breaches in a wide variety of industries, including retail, food and beverage, technology, and financial services. According to the findings:

* Most breaches resulted from a combination of events rather than from a single action. Specifically, 62 percent were attributed to a significant error; 59 percent resulted from hacking and intrusions; 31 percent incorporated malicious code; 22 percent exploited a weakness; and 15 percent were due to physical threats.

* Of those breaches caused by hacking, 39 percent were aimed at the application or software layer. Fewer than 25 percent of attacks took advantage of a known or unknown vulnerability. Significantly, 90 percent of known vulnerabilities exploited had patches available for at least six months prior to the breach.

* Nine of 10 breaches involved some type of "unknown"--unknown systems, data, network connections, and/or account user privileges. Also, 75 percent of breaches were discovered by a third party rather than the affected organization.

* Seventy-five percent of all data breaches result in compromised data within a matter of days. Despite this, the study "also reveals that 63 percent of companies don't learn about data breaches until months after their data has been compromised. Even after breaches are discovered, the study finds that nearly half of them take weeks to fix.

The study urges businesses to be proactive and provides key recommendations to help them protect themselves:

* Align process with policy--In 59 percent of data breaches, organizations had...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT