The Verizon
DBIR 2012 was released last week and I am sure you have seen a lot of blog
posts, articles and tweets on the subject... So let me try and put a different
perspective on it: many of you will have heard me say that the DBIR is the
“gift that keeps on giving”, and yes, it is! But as with every report,
statistics and opinions always have to be put into the right context... The conclusions are not surprising, but there are quite a few little
nuggets in the report that are worth examining...
To start with, I am glad to see that the analysis now offers
some separate insights in relation to SMEs and larger organisations, as some of
the issues can be different depending on size. The case load is also bigger
this year (855 incidents compared to 761 in 2010) and known compromised records
studied were also greater (3.8 million in 2010 compared to 174 million in 2011
- mostly due to the return of the “mega breaches” in 2011 after a relatively
quiet 2010).