Verizon Business has released a comprehensive study based on 4 years of data entitled the “2008 Data Breach Investigations Report” [PDF]. They have also released a podcast to go along with their study (Part 1 here).

The study looks into 500 forensic investigations and 230 million records, looking into hundreds of corporate data breaches. The report is very detailed, revealing a lot of information that could help companies understand the nature of data breaches better.

The study found that:

  • 73% of breaches result from external sources (39% from business partners, a number that is growing steadily)
  • 18% of breaches result from insider threats
  • Most breaches result from a combination of events, not a single hack or intrusion
  • 62% of breaches were attributed to significant internal errors
  • For deliberate breaches, 59% were from hacking and intrusions
  • 90% of known vulnerabilities exploited in hack attempts had patches available for at least six months prior to the breach
  • 90% of breaches involved an “unknown” system, data, network connection or user account
  • 75% of breaches are discovered by a third party, not the victimized organization
  • In 59% of data breaches, security policies and procedures existed but were not implemented
  • 66% of breaches involved data the company did not know was on their system

The study indicates that many data breaches are avoidable, and steps should be taken to prevent them. Dr. Peter Tippett, VP of Research and Intelligence for Verizon Business Security Solutions, says that companies must be “proactive in their approach to security — [it is] the absolute key to safeguarding data.”

Have a policy and implement it. Know what data you have and who has access to it. Monitor event logs. And have an incidence response plan. Increase awareness and keep them well trained – run drills.

Via databreachwatch.org, CNet Tags: , , , , , , , , ,

Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • del.icio.us
  • Digg
  • StumbleUpon
  • Technorati