Home > Security News > Survey: Data breaches difficult to spot, prevent
Security News:
EMAIL THIS

Survey: Data breaches difficult to spot, prevent

By Bill Brenner, Senior News Writer
31 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

IT security professionals are struggling to detect and prevent data breaches, according to the results of a recent survey of 853 U.S. security executives conducted by the Ponemon Institute LLC.

Nearly two-thirds of security executives said they have no way to prevent a data breach, while most respondents said their organizations lack the accountability and resources necessary to enforce data security policy compliance, according to the Elk Rapids, Mich.-based think tank. The study, conducted in June and July, was sponsored by Palo Alto, Calif.-based security firm PortAuthority Technologies Inc.

There's a lot of frustration at the CIO level, because there's a feeling that the responsibilities should be shared across the management structure more than they are.
Larry Ponemon
Chairman and Founder, Ponemon Institute
"I don't think I expected two-thirds to say they can't prevent a breach," said Larry Ponemon, chairman and founder of the Ponemon Institute. "If your first line of defense says you can't win the war, it indicates a big problem."

According to the Ponemon Institute's final report on the survey:

  • 59% of respondents said they can effectively detect a data breach, but a staggering 63% don't think they can prevent a data breach.

  • High false positive rates of up to 35% affect the ability of many organizations to detect a breach.

  • 41% of respondents don't believe they are effectively enforcing data security policies. The top reason given for failed enforcement is lack of resources.

  • Respondents said there's a 68% probability they can detect a large data breach involving more than 10,000 data files.

  • But they said small data breaches involving fewer than 100 files are only likely to be detected 51% of the time.

  • Only 16 % of respondents believe they are invulnerable to a data breach.

  • Excessive cost was the main reason 35% of respondents said they're not using leak-prevention technologies.

    Ponemon said the findings suggest IT pros are between a rock and a hard place because they're shouldering the lion's share of responsibility for preventing breaches but don't have the resources to be 100% effective.

    "There's a lot of frustration at the CIO level, because there's a feeling that the responsibilities should be shared across the management structure more than they are," he said. "They're also concerned about their ability to enforce security policies. Even when someone finds the culprit behind a breach, policies aren't enforced and mistakes are repeated in terms of what users do in their computing habits."

    But Ponemon said respondents don't see their situation as hopeless.

    "A lot of these people feel their current problem is a resource issue, but that technology can help them solve some of the problems," he said.

    Raj Dhingra, PortAuthority Technologies' vice president of products and marketing, said his company sponsored the study because it wanted to pinpoint the root causes of corporate data breaches. "We feel this study helps bring greater understanding of these issues, while validating that the industry requires much more than just monitoring of information leaks, but automated enforcement to best prevent information leaks," he said.

    Tags: Security Industry Market Trends, Predictions and ForecastsIdentity Theft and Data Security BreachesVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Industry Market Trends, Predictions and Forecasts
    M86 buys Web security gateway vendor Finjan
    Information Security Decisions 2009: Presentation downloads
    Bruce Schneier on outsourcing, awareness training
    Marcus Ranum on cyberwarfare, infosec careers
    McAfee survey finds faults in midmarket enterprise security
    Email archiving vendor sues Gartner over Magic Quadrant
    Information Security magazine October issue PDF
    Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
    Information Security magazine Security 7 Award winners
    Security Squad: Privacy gone awry
    Security Industry Market Trends, Predictions and Forecasts Research

    Identity Theft and Data Security Breaches
    Chip and PIN adoption serves lesson for U.S. payment industry
    Group to shed light on secure identity management threats
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Heartland CIO on PCI, E3 project
    Visa probes tokens, encryption for PCI card data protection
    University data breach exposes 163,000 women to identity theft
    TJX thrives following breach, bucks sour economy
    Security expert's PCI analysis misguided, says PCI Council GM
    External attacks start with unintentional mistakes, survey finds

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    backscatter body scanning  (SearchSecurity.com)
    marketecture  (SearchSecurity.com)
    NCSA  (SearchSecurity.com)
    Palladium  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts