« Eliminating session hijacking... forever | Main | ComputerWeekly IT security blog award nomination »

June 19, 2008

Verizon's Data Breach Investigations Report is a pot of gold

Verizon's 2008 Data Breach Investigations Report is worth its weight in gold, even when you print it on the thickest paper available.

Data breaches. You’ve gleaned all you can from the headlines; now you have access to information directly from the investigator’s casebook. The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world.

This sort of detailed information has so far only been available to a selected few, while the rest of us have had to speculate. That is now over, and anyone can make decisions based on facts now.

I know different people are going to focus on different aspects but, for me, these stand out:

  1. In 62% of the cases errors contribute significantly to data breaches. This means that even if you erradicate insecurity in your applications the breaches are still going to continue.
  2. In 53% of the cases the attackers took days, weeks and months to compromise a system after making a successful entry.
  3. In 55% of the cases no skills or low skills were used to carry out the attacks.
  4. In 85% of the cases the attacks were entirely opportunistic.

I urge you to read the report in full, and a few times over.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e54fd889f2883400e553615b728833

Listed below are links to weblogs that reference Verizon's Data Breach Investigations Report is a pot of gold:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Maybe things will get better now that we have RatProxy web application security audit tool, generously donated to the Open Source Security Solution Providers pool by our great friend Google. :)

The comments to this entry are closed.

MY WORK

IronBee is the next generation web application firewall engine, and it's open source too.
ModSecurity Handbok cover
ModSecurity Handbook is the definitive guide to the world's most popular web application firewall.
Apache Security cover
Apache Security is the complete guide to securing your Apache web server.
SSL Labs offers a comprehensive SSL security assessment consisting of 250+ checks. To start, enter your domain name below:

ABOUT ME

Ivan Ristić is an open source advocate, entrepreneur, writer, programmer and web security specialist. He is the principal author of ModSecurity, the open source web application firewall, and the author of Apache Security, a concise yet comprehensive web security guide for the Apache web server.   [LinkedIn Profile]

My Photo

TWITTER

@ivanristic

    FEEDS