Risk

7/19/2007
01:27 PM
50%
50%

China's Security Syndrome

InformationWeek Research's 10th annual Global Information Security Survey highlights some very different security concerns facing Chinese businesses as compared with their U.S. counterparts.

InformationWeek Research's 10th annual Global Information Security Survey highlights some very different security concerns facing Chinese businesses as compared with their U.S. counterparts.While U.S. businesses are generally considered to have a mature and stable corporate environment that's been grappling with IT security issues for years, China's more recent movement to the global business arena means the country is just beginning to pay attention to a lot of IT security concerns.

Chinese companies are generally three to five years behind North American and U.K. companies in terms of IT security, Alastair MacWillson, global managing director of Accenture's security practice, told me. Accenture helped InformationWeek Research put together the survey, and MacWillson shares his expertise in a story entitled, "China's Evolutionary Leap." "Security hasn't typically been fantastically high on their priority list."

Chinese businesses have a lot of catching up to do, which might explain why the average percentage of IT budget spent on information security is a whopping 19% in China, as compared with 12% in the United States. "That's quite an astonishing figure," MacWillson says, adding that the Chinese companies who responded to the survey clearly understand that China is far behind in terms of IT security and are spending to catch up to where they need to be.

This is likely to continue to change as the country's companies seek to do more business internationally. Bank of China, for example, "wants to adopt international standards across everything they do, so they need to adopt the control features of a Western bank," MacWillson says. Chinese businesses already are seeing the effects of this move into mainstream global markets, as 32% of Chinese respondents report having been the victim of a publicized data breach or data loss within the past 12 months, as compared with 6% of U.S. respondents.

Chinese respondents have been struck by fewer phishing attacks than U.S. respondents, 17% as compared with 31%, and this speaks to the smaller number of people in China who have access to online bank accounts, as compared to bankers in the United States, MacWillson says. If phishing attacks continue at the current pace, they're likely to become more of a problem for the country as more and more Chinese bank online.

China also has a notorious reputation for using counterfeit software, which can't easily be patched. While a sizable percentage of both U.S. and Chinese survey respondents were compromised as the result of a known operating-system vulnerability being exploited, this attack method was used against nearly two-thirds of all Chinese respondents, compared with 43% of U.S. respondents. Likewise, 41% of Chinese respondents were compromised through an exploit that took advantage of a known application vulnerability, as compared with less than a quarter of U.S. respondents. MacWillson notes that this could be the result of the large amount of pirated software being used in China. "They don't have access to the patches, so that may be why they're concerned about known exploits to operating systems," he says.

China is recognizing that it's got problems in these areas of security and they're being challenged to address them. "Multinationals are nervous about doing business in China because of the country's reputation for security," MacWillson says, adding that perhaps the high level of IT security spending indicated in the survey could be an attempt by Chinese companies to address these concerns.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
121 Pieces of Malware Flagged on NSA Employee's Home Computer
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/16/2017
Mobile Malware Incidents Hit 100% of Businesses
Dawn Kawamoto, Associate Editor, Dark Reading,  11/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.