Latest news

The Ponemon Institute polled 3,529 IT and IT security professionals in U.S., Canada, UK, Australia, Brazil, Japan, Singapore and United Arab Emirates, to understand the steps they are taking in the aftermath of malicious and non-malicious data breaches.
All participants in the study represent organizations that had one or more data security breaches in the past 24 months.
Highlights of the research include the following findings:
- Data breaches are on the rise and organizations are unprepared to detect them or resolve them — According to the majority of respondents, data breaches have increased in both severity (54 percent) and frequency (52 percent) in the past 24 months. While 63 percent say that knowing the root causes of breaches strengthens their organization’s security posture, only 40 percent say they have the tools, personnel and funding to pinpoint the root causes.
- Breaches remain undiscovered and unresolved for months — On average, it is taking companies nearly three months (80 days) to discover a malicious breach and then more than four months (123 days) to resolve it.
- Security defenses are not preventing a large portion of breaches — One third of malicious breaches are not being caught by any of the companies’ defenses - they are instead discovered when companies are notified by a third party, either law enforcement, a partner, customer or other party - or discovered by accident. Meanwhile, more than one third of non-malicious breaches (34 percent) are discovered accidentally.
- Malicious breaches are targeting key information assets within organizations — Nearly half of malicious breaches (42 percent) targeted applications and more than one third (36 percent) targeted user accounts.
- Impact and cost of breaches — On average, malicious breaches ($840,000) are significantly more costly than non-malicious data breaches ($470,000). For non-malicious breaches, lost reputation, brand value and image were reported as the most serious consequences by participants. For malicious breaches, organizations suffered lost time and productivity followed by loss of reputation.


Spotlight

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Is Microsoft is reading your Skype communications?
Posted on 15 May 2013. | The question of whether Skype allows U.S. intelligence and law enforcement agencies to access the communications exchanged by its users has still not been adequately answered by Microsoft.

Internet Explorer best at blocking malware
Posted on 14 May 2013. | While Chrome’s malware download protection improved significantly, Internet Explorer 10 continues to outperform the other browsers with a block rate of 99.96%.

Researcher refuses to help Saudi telco to spy on people
Posted on 14 May 2013. | You would think that a Saudi Arabian telecom firm interested in monitoring its users' mobile communications would not be asking a well-known pro-privacy researcher for help, but you would be wrong.

Malicious browser extensions are hijacking Facebook accounts
Posted on 13 May 2013. | Facebook users - especially those in Brazil - are being targeted with malicious browser extensions trying to hijack Facebook profiles, warns Microsoft.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





