Showing posts with label DBIR. Show all posts
Showing posts with label DBIR. Show all posts

22 April 2014

WHY DO DATA BREACHES HAPPEN? Clues from the Verizon DBIR 2014...

The always eagerly awaited Verizon DBIR 2014 was released earlier this year. As always, with a nice cup of coffee and some smooth jazz playing in the background, I will endeavour to distil the essence of this always excellent publication... Well, this year, the DBIR departs from just analysing data breaches to looking at 63,347 confirmed security incidents, of which 1,367 were confirmed data breaches (compared to 621 for 2012) across 95 countries (compared to 27 in 2012). This gives far greater richness to the data set and the insights that can be derived from it (rightly so, the DBIR team notes that incidents need not necessarily result on data loss to have a significant impact on an organisation – I couldn’t agree more!). Also don’t miss the month by month review of the major incidents of 2013 on pages 3 & 4, that’ll get you in the mood...


28 January 2013

GAZING AT 2013: THE RIGHT FOCUS AND THE RIGHT LANGUAGE...

Google
Well, it’s the New Year, and I wish you all the best for a fantastic 2013! I can’t believe my last post was in November! And it’s already the end of January! So I thought I’d get in quickly with my two pennies worth of crystal ball gazing before it becomes unfashionable... What did we learn from 2012? Are there any interesting market trends? How does it affect security? What is the current state of information security and how is it shaping up? Are we getting any better? If any of these questions spark your interest of if you’d just like to see if my Nostradamus impression has something in it, read on...

9 May 2012

CLOSE ENCOUNTERS OF THE THIRD (PARTY) KIND...

Google
Phew... The last month was absolutely hectic, with all those conferences falling within the same short period of time! With all that, I was privileged enough to have been asked to speak at both Internet World and Infosecurity Europe. Two very different experiences... Whilst it is expected to be talking about security at an infosec conference, it is always welcome to be asked to present about security matters at an event with a different focus - in this instance, everything digital... (see my previous post on the subject). It was nevertheless surprising, walking the show floor at Internet World, talking to vendors and poring over the agendas in the various theatres, how little security featured. With everything about the show related to "cyber", not many had made the obvious leap to "cybercrime"... So, on the way to our Devil's Tower, our quest is still to find our curwen hand signs to communicate with the third (party) kind...

26 March 2012

VERIZON DBIR 2012 - some context...

Google
The Verizon DBIR 2012 was released last week and I am sure you have seen a lot of blog posts, articles and tweets on the subject... So let me try and put a different perspective on it: many of you will have heard me say that the DBIR is the “gift that keeps on giving”, and yes, it is! But as with every report, statistics and opinions always have to be put into the right context... The conclusions are not surprising, but there are quite a few little nuggets in the report that are worth examining...
To start with, I am glad to see that the analysis now offers some separate insights in relation to SMEs and larger organisations, as some of the issues can be different depending on size. The case load is also bigger this year (855 incidents compared to 761 in 2010) and known compromised records studied were also greater (3.8 million in 2010 compared to 174 million in 2011 - mostly due to the return of the “mega breaches” in 2011 after a relatively quiet 2010).