Almost half of the breached organizations classified the situation as "serious" -- meaning there was a financial threat, potential damage to the organization's reputation, or other business-critical problem, according to the Computing Technology Industry Association's (CompTIA's) 8th Annual Global Security Trends Study.
Human error is the perceived cause for 59 percent of security incidents, according to the study. Forty-one percent are perceived as technology errors. The element of human error that most contributes to security breaches? Failure of end users to comply with security policies, which was cited by 49 percent of respondents.
Almost half of those surveyed rate security as an upper level IT priority, compared to 35 percent in 2008.
The study suggests organizations continue to face traditional IT security threats: viruses, email and browser-based attacks, and user abuse. But organizations also cited many emerging challenges, including social media-based attacks, phishing, cloud computing security, and security in a mobile environment.
Factors that make the security landscape riskier today include the rapid rise of social networking, cited by 52 percent of respondents; more reliance on Internet-based applications (50 percent); and the growing sophistication, criminalization and organization of hackers motivated by financial gain (48 percent).
The economic recession continues to affect the security environment, according to the survey. Thirty-four percent of respondents believe their internal security threat level has increased as a result of the recession. They expressed concerns about departing employees who might have knowledge of logins, access points and other potential vulnerabilities.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.