Home > Security News > Survey: Data breaches difficult to spot, prevent
Security News:
EMAIL THIS

Survey: Data breaches difficult to spot, prevent

By Bill Brenner, Senior News Writer
31 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

IT security professionals are struggling to detect and prevent data breaches, according to the results of a recent survey of 853 U.S. security executives conducted by the Ponemon Institute LLC.

Nearly two-thirds of security executives said they have no way to prevent a data breach, while most respondents said their organizations lack the accountability and resources necessary to enforce data security policy compliance, according to the Elk Rapids, Mich.-based think tank. The study, conducted in June and July, was sponsored by Palo Alto, Calif.-based security firm PortAuthority Technologies Inc.

There's a lot of frustration at the CIO level, because there's a feeling that the responsibilities should be shared across the management structure more than they are.
Larry Ponemon
Chairman and Founder, Ponemon Institute
"I don't think I expected two-thirds to say they can't prevent a breach," said Larry Ponemon, chairman and founder of the Ponemon Institute. "If your first line of defense says you can't win the war, it indicates a big problem."

According to the Ponemon Institute's final report on the survey:

  • 59% of respondents said they can effectively detect a data breach, but a staggering 63% don't think they can prevent a data breach.

  • High false positive rates of up to 35% affect the ability of many organizations to detect a breach.

  • 41% of respondents don't believe they are effectively enforcing data security policies. The top reason given for failed enforcement is lack of resources.

  • Respondents said there's a 68% probability they can detect a large data breach involving more than 10,000 data files.

  • But they said small data breaches involving fewer than 100 files are only likely to be detected 51% of the time.

  • Only 16 % of respondents believe they are invulnerable to a data breach.

  • Excessive cost was the main reason 35% of respondents said they're not using leak-prevention technologies.

    Ponemon said the findings suggest IT pros are between a rock and a hard place because they're shouldering the lion's share of responsibility for preventing breaches but don't have the resources to be 100% effective.

    "There's a lot of frustration at the CIO level, because there's a feeling that the responsibilities should be shared across the management structure more than they are," he said. "They're also concerned about their ability to enforce security policies. Even when someone finds the culprit behind a breach, policies aren't enforced and mistakes are repeated in terms of what users do in their computing habits."

    But Ponemon said respondents don't see their situation as hopeless.

    "A lot of these people feel their current problem is a resource issue, but that technology can help them solve some of the problems," he said.

    Raj Dhingra, PortAuthority Technologies' vice president of products and marketing, said his company sponsored the study because it wanted to pinpoint the root causes of corporate data breaches. "We feel this study helps bring greater understanding of these issues, while validating that the industry requires much more than just monitoring of information leaks, but automated enforcement to best prevent information leaks," he said.

    Tags: Security Industry Market Trends, Predictions and ForecastsIdentity Theft and Data Security BreachesVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Security Industry Market Trends, Predictions and Forecasts
    Cybersecurity czar candidate questions clout of new position
    Gartner sees better days ahead for security budgets
    Sophos CEO on Symantec, McAfee after Utimaco acquisition
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Security budgets take hit in media, tech industry, survey finds
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Opinion: Gartner gets NAC wrong, again
    Cloud computing security group releases report outlining trouble areas
    White House cybersecurity advisor calls for public-private cooperation
    Security Industry Market Trends, Predictions and Forecasts Research

    Identity Theft and Data Security Breaches
    TJX to pay $9.75 million for data breach investigations
    Man pleads guilty in online banking hacking scam
    White House cybersecurity czar faces major hurdles
    Heartland breach cost $12.6 million, CEO says
    An inside look at security log management forensics investigations
    LexisNexis investigates breach, notifies thousands
    Senators hear call for federal cybersecurity restructuring
    Former Federal Reserve Bank employee arrested
    Attackers cash in on fundamental data handling mistakes, Verizon finds
    Courts turn aside data breach suits

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    backscatter body scanning  (SearchSecurity.com)
    marketecture  (SearchSecurity.com)
    NCSA  (SearchSecurity.com)
    Palladium  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    Focused on Channel Security?
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts