Vulnerabilities / Threats
2/19/2013
06:55 AM
Tim Wilson
Tim Wilson
Quick Hits
50%
50%

Most Americans Believe U.S. Businesses Are Vulnerable To Cyberattack, Study Says

Ninety-three percent believe U.S. corporations are at least somewhat vulnerable to state-sponsored online attacks, Tenable report says

Americans believe that their corporations are vulnerable to state-sponsored cyberattacks, and they fear that the country is not ready to repel those attacks, according to a study released last week.

According to a study of more than 1,000 U.S. adults, 93 percent of Americans believe their businesses are at least somewhat vulnerable to state-sponsored attacks. Ninety-five percent believe U.S. government agencies are vulnerable to such attacks.

If the U.S. were to undergo a cyberattack, Americans are most concerned about disruption to utilities, such as water, electric, and gas (37 percent), the study says.

More people are concerned about disruption to communication infrastructure, such as phone and Internet (21 percent), than they are about disruption to transportation infrastructure (7 percent), the study says. Thirty percent are concerned about disruption to financial services.

Americans age 65 or over believe the U.S.’s engagement in cyberwarfare to be more likely, with 26 percent saying they considered the U.S. "very likely" to engage in such attacks in the next 10 years; only 9 percent of Americans ages 25 to 34 believe it "very likely."

Sixty percent of Americans support increasing government spending to train and equip "cyberwarriors" to defend the U.S. against outside attacks, the survey says. Only 10 percent of respondents are opposed to this increase in spending.

Sixty-six percent of respondents in the survey believe corporations should be held responsible for cyberbreaches when they occur, according to the study. But an almost equal number of Americans, 62 percent, says government should be responsible for protecting U.S. businesses and corporations from cyberattacks.

"I think these rather conflicting results on who should be held accountable reveal that Americans want both the public and private sector working closely together on cybersecurity," says Ron Gula, a former cybersecurity expert with the NSA, and now CEO and CTO of Tenable Network Security.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0543
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-0544
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

CVE-2015-2721
Published: 2015-07-05
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attacke...

CVE-2015-2722
Published: 2015-07-05
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

CVE-2015-2724
Published: 2015-07-05
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report