Vulnerabilities / Threats
11/14/2012
09:50 AM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

Employee-Empowering Technologies Raise Security Stakes For Organizations, New CompTIA Study Reveals

Majority of companies attribute human error as a contributing cause of security breaches

DOWNERS GROVE, Ill., Nov. 14, 2012 /PRNewswire-USNewswire/ -- Cloud computing, mobility, social tools and other technologies that put more power in the hands of individual users pose new challenges for organizations seeking to secure data, devices and networks, new research released today by CompTIA, the non-profit association for the information technology (IT) industry, reveals.

The majority of companies in CompTIA's 10th Annual Information Security Trends study attribute human error as a contributing cause of security breaches, just as they have in the previous nine years of the study. What's changing, however, is that the human element is no longer confined to malware, phishing and viruses.

Cloud computing options force end users to consider how data is handled outside of their organization. Unauthorized mobile applications and mobile malware strains are becoming more prevalent. Social networking is a growing factor affecting organizational security.

"As users gain more responsibility for their own technology, the human element becomes more and more important," said Seth Robinson, director, technology analysis, CompTIA.

"But many organizations are not sure what to do about it," Robinson continued.

"The way they've thought about security in the past is to purchase a firewall or antivirus software or other product. But there's not a product that can help with end-user awareness. It really requires a commitment to training and education."

Four out of five companies expect to keep security as a high priority over the next two years, with large companies more likely to do so than their small and medium counterparts.

"Spending on security products shows no signs of abating, but a comprehensive security solution also must focus on the end users," Robinson said. "It boils down to policies, processes and people; making every user aware of their responsibilities for security."

Along with growing concern over increasingly sophisticated and targeted cyber-attacks, changes in IT operations have also prompted new security approaches. For example, 51% of firms said that their move to cloud solutions or new mobility strategies was responsible for the implementation of new security tactics.

In dealing with these changes, 41% of organizations report a need to help their security staff close moderate or significant gaps in security expertise, with the deficit most pronounced in areas such as cloud security, mobile security and data loss prevention. The impact of these deficiencies is felt in several ways, including being unaware of where the company is exposed (44 percent of responding firms); loss of business as a result of security issues with customer data (39 percent); and costs incurred for training the current workforce (38 percent).

A net 49% of companies say they intend to hire security specialists, including those that also plan on training current staff. Executives have a strong preference for security professionals with industry certifications. A full 84% said they experienced a positive return on investment in security certifications, with certified staff viewed as more valuable because of their proven expertise and ability to perform at a high level than non-certified staff.

CompTIA's 10th Annual Information Security Trends study is based on surveys of

508 U.S. business and IT executives involved in setting or executing information security policies and processes for their organizations; and 368 executives at U.S. IT firms. Surveys were conducted in late September and early October 2012.

About CompTIA

CompTIA is the voice of the world's information technology (IT) industry. Its members are the companies at the forefront of innovation; and the professionals responsible for maximizing the benefits organizations receive from their investments in technology. CompTIA is dedicated to advancing industry growth through its educational programs, market research, networking events, professional certifications, and public policy advocacy. Visit http://www.comptia.org/home.aspx or follow CompTIA at http://www.facebook.com/CompTIA and twitter.com/comptia.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4907
Published: 2014-07-11
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.

CVE-2014-4908
Published: 2014-07-11
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper hand...

CVE-2014-2963
Published: 2014-07-10
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.

CVE-2014-3310
Published: 2014-07-10
The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.

CVE-2014-3311
Published: 2014-07-10
Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center allows remote attackers to execute arbitrary code via crafted data, aka Bug IDs CSCup62463 and CSCup58467.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.