Showing posts with label Security Surveys. Show all posts
Showing posts with label Security Surveys. Show all posts

Tuesday, August 10, 2010

Another Survey Tells Same Sad Story of Growing Internet Dangers

McAfee released a report today showing that incidents of malware (malicious software) reached its highest levels ever in the first half of 2010. The company identified 6 million malicious files in the second quarter, making for a total of 10 million malicious files over the first six months of the year. Among the most common attack vectors were attacks targeted to social media users. Password stealing Trojan horses — commonly used used in online bank thefts — were among the most common payloads.

The report reconfirms everything we've been saying since we began our blog 18 months agoThere has been a sea change in cybercrime. Threats are more sophisticated than ever, weaknesses and vulnerabilities abound. Defenses have not kept pace.

The report is a reminder to every organization to take a critical look at its defenses — everything from policies and employee awareness training to modern intrusion prevention systems. It needs to make sure it's employing a cost-effective defense-in-depth strategy covering all three critical information security management domains:
  1. Corporate security management
  2. Security management of the IT infrastructure
  3. Point-in-Time security of the IT infrastructure
It's also a time to talk to your attorney and your insurance broker. Your attorney can make sure you're aware of your legal responsibilities and can provide counsel on sharing sensitive information with 3rd parties. Your insurance broker can help you mitigate some of your security risk through cyber-insurance policies.

Thanks to Terry Corbell for alerting us to this story.

Tuesday, April 27, 2010

Report Shows Weaknesses in Anti-Virus Engines

Brian Krebs reports on a research report just released by Google on the increasing difficulty defenses have in countering cybercriminals spreading fake anti-virus programs, commonly known as scareware. Using data provided by Google, purveyors of scareware programs have aggressively stepped up their effort to evade detection by legitimate anti-virus programs, both anti-virus software and Google's own detection efforts.

According to Google's Niels Provos, "We found that if you have anti-virus protection installed on your computer but the [malware detection] signatures for it are out-of-date by just a couple of days, this can drastically reduce the detection rates. It turns out that the closer you get to now, the commercial anti-virus programs were doing a much worse job at detecting pages that were hosting fake anti-virus payloads."

As to the danger, Krebs writes: "Fake anti-virus attacks use misleading pop-ups and videos to scare users into thinking their computers are infected and offer a free download to scan for malware. The bogus scanning programs then claim to find oodles of infected files, and victims who fall for the ruse often are compelled to register the fake anti-virus software for a fee in order to make the incessant malware warnings disappear. Worse still, fake anti-virus programs frequently are bundled with other malware. What’s more, victims end up handing their credit or debit card information over to the people most likely to defraud them."

Read the story and link to the Google report at KrebsOnSecurity.com ...

For what to do if you become a scareware victim, read Brian Krebs tutorial here ...

Thursday, April 22, 2010

Symantec 2009 Global Internet Security Threat Report

Symantec has published their 2009 Global Internet Security Threat Report. According to the report, the top web-based attacks in 2009 were on Internet Explorer and Adobe Acrobat/Reader. The report notes the growth in PDF attacks, from 11% of web-based attacks in 2008 to 49% in 2009. The report covers topics like threat activities, vulnerability trends, phishing and the underground economy.


Download the Executive Summary from Symantec ... 

Download the entire Report ...

Monday, April 5, 2010

Cyber Security Survey Finds Businesses' Most Valuable Data at Risk

The survey, conducted by Forrester Consulting, identified two primary types of information needing to be secured: (1) Sales lists, strategies and other secrets conferring competitive advantage and (2) custodial information, like credit card numbers, requiring protection. One of the conclusions of the survey: Investments are overweighed against protection and toward compliance.
 
Read more at eSecurity Planet ...

Tuesday, March 23, 2010

Riskiest Online Cities: The Emperor Has No Clothes

Yesterday's news brought an intriguing headline "The Norton Top 10 Riskiest Online Cities Report Reveals Who's Most Vulnerable to Cybercrime." I read the story, examined the report and sadly concluded that there was much less here than meets the eye.

As novelist G.K. Chesterton once wrote “It’s not that they don’t know the answer. It’s that they don’t know the question.”

The report measured the online risk of a city by looking several pieces of data, including:

  • Cybercrimes data from Symantec Security Response, including number of malicious attack, number of potential malware infection, number of spam zombies, number of bot infected computer, and level of Internet access
  • Expenditures on computer hardware and software
  • Wireless hotspots
  • Broadband connectivity
  • Internet usage
  • Online purchases

The report leaves much to be desired for at least three reasons.

First, the data collected may not meaningfully relate to online risk. Expenditures on computer hardware and software may mean little or nothing since one large supercomputer can cost the same as zillions of PCs and actually lower risk.

Second, missing from this list are things that would serve to mitigate risk such as:
  • Number of information systems security professionals in the City
  • Average number of information security professionals per 1,000 computers and per company
  • Percentage of computers who connect to hotspots using a VPN
  • Percentage of companies ISO27001 certified
  • Numbers of CISSPs, CISMs, etc
  • Percentage of businesses / homes with professionally managed firewalls

My third objection may be the most fundamental of all. Just exactly what is "online risk" supposed to mean when applied to a city as opposed to an organization or individual. My online risk goes up or down as the total number of bot infected or spam zombie computers in the world goes up or down. My online risk is pretty much the same whether there are more bot infected or spam zombie computers in Seattle or Los Angeles; it’s the total number that matter, not where they happen to be located.

My risk is my risk: It depends on my specific online habits and the specific security measures I take, not whether I'm more likely to be attacked from down the street or halfway around the country [or even the world].

If a city’s online risk is to measure the likelihood of my being attacked by virtue of being online in that city — analogous to what physical risk measures when we say that one city is safer than another — than the factors Norton used in the survey are, I contend, simply the wrong factors.

As you see, my objections are less related to security than to the nature of the survey itself.

Nice try Norton. But you need to go back to the drawing board, if there's even a drawing board here.

Monday, February 22, 2010

Symantec 2010 State of Enterprise Security Study Shows Frequent, Effective Attacks on Worldwide Business

CNN Money: 75 Percent of Organizations Have Suffered a Cyber Attack Losing an Average of $2 Million Annually. ... Symantec Corp. (NASDAQ: SYMC) today released the findings of its global 2010 State of Enterprise Security study. The study found that 42 percent of organizations rate security their top issue. This isn't a surprise, considering that 75 percent of organizations experienced cyber attacks in the past 12 months. These attacks cost enterprise businesses an average of $2 million per year. ... organizations reported that enterprise security is becoming more difficult due to understaffing, new IT initiatives that intensify security issues and IT compliance issues. The study is based on surveys of 2,100 enterprise CIOs, CISOs and IT managers from 27 countries in January 2010.

Read more ...

Tuesday, December 8, 2009

Cisco Publishes 2009 Annual Security Report

What's happening: Cisco Security Intelligence Operations announces the Cisco 2009 Annual Security Report. The updated report includes information about 2009 global threats and trends, as well as security recommendations for 2010.

Report Highlight: Online criminals have taken advantage of the large social media following, exploiting users' willingness to respond to messages that are supposedly from people they know and trust.

What to Do: Review the report and strengthen defenses accordingly.

**********************************
Cisco 2009 Annual Security Report

Tuesday, October 27, 2009

New Study Continues to Show Internet Becoming Increasingly Dangerous as Malware Infections Rise Rapidly

What's happening: According to the latest statistics, the number of web sites hosting malware—either intentionally or inadvertantly—continues to rise at an alarming rate.

What it means: This latest report confirms what IBM said in their "Online Threat Report" of last August. (See our blog post: IBM Online Threat Report: Trust No One)

What to do: Management needs to make sure their information systems security management program is up-to-date, with the defense-in-depth required to deal with these new threats.

**********************************

cnet News: Elinor Mills: Web-based malware infections rise rapidly, stats show

The number of Web sites hosting malicious software, either intentionally or unwittingly, is rising rapidly, according to statistics to be released on Tuesday from Dasient. More than 640,000 Web sites and about 5.8 million pages are infected with malware, according to Dasient, which was founded by former Googlers to offer services to help Web sites stay malware-free and off blacklists. That figure for infected pages is nearly double what Microsoft estimated in a report in April. Meanwhile, the Google blacklist of malware infected sites has more than doubled in the last year, registering as many as 40,000 new sites in one week.

http://news.cnet.com/8301-27080_3-10383512-245.html

Tuesday, September 15, 2009

Like Generals, in Battle Against Cybercrime IT Staff Are Fighting Yesterday's War

What's happening: A new study from the respected SANS Institute finds that as IT departments have become better at defending against yesteday's cyberthreats, cybercriminals have moved on to a new generation of ever-more sophisticated attacks.

What it means: Sensitive corporate information — including access to the corporate coffers — is not being adequately protected.The security-software company McAfee estimated that companies around the world lost more than $1 trillion to cybercrime in 2008, .

What to do: Senior management must proactively manage the way IT staff manages network security. Review IT vulnerability management plans. Consider investing in a modern intrusion detection / prevention system. Since technology defenses alone are inadequate, make sure staff is trained to meet their security responsibilities and that they know cybercrime warning signals. Talk to your insurance broker about cybercrime insurance.

**********************************

Security Pros Are Focused on the Wrong Threats
By Riva Richmond
New York Times

Corporate information technology departments are prioritizing the wrong threats to their computer systems, focusing on old problems and leaving their companies open to a raft of new cyberattacks aiming at private customer and corporate information.

http://bits.blogs.nytimes.com/2009/09/15/security-pros-are-focused-on-the-wrong-threats/?hpw

Thursday, August 27, 2009

IBM Online Threat Report: Trust No One

From ChannelWeb's Rick Whiting: http://www.crn.com/security/219500277;jsessionid=LU4KR1SCVNOGRQE1GHOSKH4ATMY32JVN

Security threats on the Internet, including a 508 percent increase in the number of malicious Web links, have created "an unprecedented state of Web insecurity," according to a report from IBM.

The X-Force 2009 Mid-Year Trend and Risk Report, issued Wednesday, said that security threats to Web surfers are no longer limited to "malicious domains or untrusted Web sites" and now include dangerous content on legitimate Internet sites. The result is "an unprecedented state of Web insecurity as Web client, server and content threats converge to create an untenable risk landscape," according to the report.

"The trends highlighted by the report seem to indicate that the Internet has finally taken on the characteristics of the Wild West, where no one is to be trusted," said X-Force director Kris Lamb, in a statement about the report. "There is no such thing as safe browsing today and it is no longer the case that only the red light district sites are responsible for malware. We've reached a tipping point where every Web site should be viewed as suspicious and every user is at risk."

Friday, July 24, 2009

Forty-Four Percent of US SMBs Admit to Falling Victim to Cybercrime, According to Latest Panda Security Survey

29 percent of US small and medium-sized businesses lack antispam, 22 percent have no antispyware and 16 percent operate without a firewall - 50 percent lost time or productivity as a result of being infected - 39 percent of respondents said either they or their employees have not received training about IT threats that could affect them. http://finance.yahoo.com/news/FortyFour-Percent-of-US-SMBs-prnews-2714742551.html?x=0&.v=1

Monday, July 13, 2009

What CEOs Don't Know About Cybersecurity: A new study hints at how often cyberthreats aren't communicated to the boss.

Forbes Magazine: Being the chief executive has its privileges. And one of them may be a blissful ignorance of your company's data breach risks.

According to a study to be released Tuesday by the privacy-focused Ponemon Institute, companies' chief executives tend to value cybersecurity just as--if not more--highly than their executive colleagues. But ... the CEOs interviewed in Ponemon's survey seemed especially unconcerned about cybercrime as a source of data breaches. While 31% named stolen PCs or thumb drives as a source of data loss, only 3% cited malicious hackers as the top threat for their company's data security--about a fifth as many as the lower level employees who cited cybercriminals as the most important threat.

http://www.forbes.com/2009/07/13/poneman-cybersecurity-breaches-technology-security-poneman.html?partner=alerts

Tuesday, February 10, 2009

Average cost of a data breach in 2008 grew to $202 per record, Ponemon Study Says

DarkREADING: Data Breach Costs Rose Significantly In 2008, Ponemon Study Says. Companies report average loss of $6.6 million per breach, study says.

The average cost of a data breach in 2008 grew to $202 per record compromised, an increase of 2.5 percent since 2007 ($197 per record) and 11 percent compared to 2006 ($182 per record), according to the study. The average total cost per reporting company was more than $6.6 million per breach -- up from $6.3 million in 2007 and $4.7 million in 2006 -- and ranged from $613,000 to almost $32 million.

http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=213000466