Wednesday, April 20, 2011

Underground Economies - McAfee and SAIC report


A new report labeled "Underground Economies", where McAfee and SAIC collaborated to investigate perceptions around intellectual capital of companies has been published. The report surveyed over 1,000 senior IT decision makers across the world, getting their opinion on where they thought their valuable data was, their attitude to outsourcing control of it, and questions around how it was protected and the risk of it being "misplaced".

Some of the highlights of the report are:

  • Employees' adherence (or lack of) to security procedures is considered to be a greater challenge to organizations' information security than the fact that there are multiple systems within the organization, or the insecurity of supply chain partner systems
  • Around half of organizations are looking to increase their IT security spending in regard to hardware upgrades, software upgrades and external hosting of data and other services
  • More than a quarter of organizations assess the threats or risks posed to their data twice a year or less often
  • Securing mobile devices continues to pose a challenge to businesses
  • Cloud based services may represent a new target not only for data theft, but also for cheap infrastructure or resources within criminal enterprises
  • One in ten organizations will only report breaches/losses that they are legally obliged to, and no more

Some emerging trends that are changing the ways companies are defying sophisticated attacks and insider leaks are:

  • Deep Packet Inspection
  • Human Behavior Based Network Security
  • Insider Threat Tools
  • Advanced Forensics
  • Advanced Malware Analysis

The complete report is here. (Registration required)

No comments: