The distinction between insiders and outsiders isn't very useful. Security pros just shouldn't trust anyone. Proper controls must be in place to protect data from both internal and external attack vectors. Whether the right number is 73% or 27% doesn't matter if an insider has created a breach. Or an outsider, for that matter.
Reading deeper into the Verizon report (pdf), it's clear that many of the breaches could have been avoided by updating devices on a timely basis and making sure configurations were locked down. Again, both of these issues are pretty simple security practices. People should focus on protecting important data rather than making artificial delineations between insiders and outsiders.
The last point is that Verizon's data set is skewed toward outsiders. Many insider attacks are never reported, nor do they bring in fancy forensic investigators (like Verizon) to clean up the mess. Yet, when the breach happens from outside, organizations usually have to disclose and tend to bring in outside experts.
Verizon's study definitely has value; it's opened up the eyes of a lot of people. But it's important to put it in the proper frame of reference and make sure to draw the right conclusions.
Dig Deeper on Data security breaches
Related Q&A from Mike Rothman
Pirated software is still a major concern nowadays. Uncover how to prevent software piracy and protect your organization's intellectual property. Continue Reading
While liaison officer responsibilities vary depending on the company they work for, their strong organizational and communications skills make them ... Continue Reading
The CISSP certification can be a challenge to obtain. Mike Rothman unveils how to get on the right education and career tracks in order to get CISSP ... Continue Reading