Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Annual CSI Study: Cost of Cybercrime Is Skyrocketing

Average annual loss per company has more than doubled since last year, according to bellwether study

Sep 11, 2007 | 09:55 AM

By Tim Wilson
DarkReading

If your organization was hit hard in the wallet by cybercriminals in the past 12 months, you're not alone.

According to the Computer Security Institute's annual Computer Crime and Security Survey, which is scheduled for release later this week, companies reported average annual losses of $350,424 in the past year, up sharply from the $168,000 they reported the previous year. (See CSI/FBI: Violations, Losses Down and 10th Annual CSI/FBI Survey .)

This is the first year since 2002 that CSI -- which has developed the survey jointly with the FBI for 11 years -- has reported an increase in average annual losses. "Not since 2004 have average losses been this high," the CSI says in a sneak peek of its report.

For the first time, financial fraud overtook virus attacks as the source of the greatest financial losses, according to CSI. Virus losses, which had been the top cost for seven years straight, fell to second place. "But if separate categories concerned with the loss of customer and proprietary data are lumped together, however, then that combined category would be the second-worst cause of financial loss," the report says.

Insider abuse of network access or email surpassed virus incidents as the most prevalent security problem in the past year, with 59 and 52 percent of respondents reporting each, respectively.

Almost one fifth (18 percent) of respondents who suffered one or more types of security incidents in the past year also said they'd suffered at least one targeted attack -- a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.

The percentage of organizations reporting computer intrusions to law enforcement continued upward, reversing a decline over the past two years. Twenty-nine percent of respondents that experienced a security incident in the past 12 months reported it to the police; only 25 percent did so last year.

More details on the study, as well as a copy of the study itself, will be available on Dark Reading in the next few days.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)