Survey: Security efforts paying off

Companies working to harden their security have found that the efforts have resulted in fewer incidents of unauthorised computer use and a decline in damages from security incidents, a computer security group said in a report released Thursday.

The Computer Security Institute's survey of security professionals at nearly 500 companies found that damages related to cyberattacks declined, reaching about US$290,000 per company versus US$400,000 per company a year ago. The report, conducted in cooperation with the FBI, also said respondents thought denial-of-service attacks outpaced intellectual property theft as the most costly type of information threat. Such a shift may indicate that companies are shoring up internal-network defenses, said Robert Richardson, editorial director for CSI and an author of the report.

"If you get more effective in protecting what is inside your networks, then (attackers) have to resort to other things," he said. "One thing you can resort to is denial-of-service attacks."

Unlike thefts, which require an attacker to break into a system, DoS attacks typically involve an online miscreant sending a flood of data to a Web site to prevent others from accessing the site. This is the first time DoS attacks have topped the list of threats.

The survey, which measures responses mainly from information technology managers who work for companies that are CSI members, is considered an indicator of general trends but not a reliable measure of specific detail, said Richardson.

"You have to be careful in general of results of this kind," he said. "It highlights a lot of interesting things, but it also raises questions that can't be answered by the data."

Most companies kept security functions inside the company, with only 12 percent of those surveyed indicating they outsourced more than 20 percent of security procedures.

Larger companies typically benefited from economies of scale and paid less per employee for security, the survey found.

Companies with annual sales of more than US$1 billion typically paid a little more than US$100 per worker on security, while companies with revenue of less than US$10 million spent an average of US$500 per worker.

The survey also indicated that more companies are interested in computer security because of new government regulations. The financial, utility and telecommunications sectors believe that the Sarbanes-Oxley Act, which requires a company's executives to be accountable for their financial statements, has resulted in management focusing on information security, Richardson said.

This is the first year that the survey asked companies about the effect of the law.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue All I want for Xmas is Telstra pricing
    Five consecutive days without broadband has led me to what seemed at the time to be an act of desperation: contemplating signing up for Telstra's 100Mbps cable modem service.
  • Array Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • More blogs »

Tags

Back to top

Featured