Study: Most Data Breaches Preventable
Date : 23 Oct 2008 Category : TechnologyThe first-of-its-kind study looked at data breaches in a wide variety of industries, including retail, food and beverage, technology, and financial services. According to the findings:
* Most breaches resulted from a combination of events rather than from a single action. Specifically, 62 percent were attributed to a significant error; 59 percent resulted from hacking and intrusions; 31 percent incorporated malicious code; 22 percent exploited a weakness; and 15 percent were due to physical threats.
* Of those breaches caused by hacking, 39 percent were aimed at the application or software layer. Fewer than 25 percent of attacks took advantage of a known or unknown vulnerability. Significantly, 90 percent of known vulnerabilities exploited had patches available for at least six months prior to the breach.
* Nine of 10 breaches involved some type of "unknown" -- unknown systems, data, network connections, and/or account user privileges. Also, 75 percent of breaches were discovered by a third party rather than the affected organization.
* Seventy-five percent of all data breaches result in compromised data within a matter of days. Despite this, the study also reveals that 63 percent of companies don't learn about data breaches until months after their data has been compromised. Even...