Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

3/18/2014
12:49 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Many Organizations Don't Go Public With Data Breaches Or Share Intel

Some 60 percent of organizations worldwide have an incident response team and plan in place to prepare for an attack, new report finds

There are likely many more breached retailers than Target, Neiman Marcus, Michaels, and Sally Beauty either unaware that they have been hit or not yet ready to go public. There also are many data breaches, even at retailers, that may never see the light of day: As a matter of fact, some 57 percent of organizations worldwide say they do not voluntarily report hacks that aren't bound by disclosure laws.

So says a new report published today by Arbor Networks and The Economist Intelligence Unit, which surveyed some 360 C-level or board-level business executives around the globe on their incident response posture. Some 77 percent of the respondents say their firms had been hit with a cyberattack in the past two years, but only about 35 percent say they share attack and threat information with other organizations in their industry, 32 percent say they do not share such intelligence, and 27 percent did not say one way or the other.

"Only a third of companies are willing to share information about incidents with other organizations ... But these days, the only way to defend is sharing," says Dan Holden, director of Arbor's ASERT.

Threat and attack intelligence-sharing is widely considered crucial to fight the bad guys and to give organizations information to prepare or defend against attack campaigns.

The U.S. is more active in intel-sharing than other nations, according to the report, with financial services, critical infrastructure and higher education as some of the most active in this practice. "Sharing information is one of the strengths of information security in the higher education industry, and we use multiple methods to share information and collaborate," says Brad Judy, director of information systems security at the University of Colorado, who was interviewed for the report.

[Breaches at Target and other retailers sound the alarm for retail industry to establish a cyber-threat Information-Sharing and Analysis Center. See Retail Industry Mulls Forming Its Own ISAC For Intel-Sharing .

Meanwhile, security incidents are becoming more common and frequent. While more than three-fourths say they have suffered an incident in the past two years, not all were not outsider-related: nearly 30 percent suffered major system outages and 27 percent, exposure of sensitive data by an employee.

Some 60 percent of organizations now have an incident response team and plan in place to prepare for an attack, with that rate on the rise, the report says. Some 80 percent of large organizations, and 70 percent of respondents overall, have third-party relationships in place with IR specialists. Those organizations hit with an attack in the past two years were more than twice as likely to have partnered with an IR specialist firm.

Execs see a well-orchestrated response to a security incident as a potential reputation-booster, the report found. Two-thirds of the respondents say that responding well to an incident can "enhance" the company's public reputation. "For Target, that's a big deal," Holden says, noting that the retailer suffered more customer fallout than TJX did. "Employee and customer awareness is different here [with Target] ... the saving face piece is big" today, he says.

The report also found that few execs are confident that their organization is prepared in the face of a security incident: Only 17 percent say they are fully prepared, and more than 40 percent say they would be better prepared if they had more knowledge about the threats out there. About half say they cannot predict how a breach would affect their business.

The execs surveyed for the report were spread across North America (31 percent), Europe (36 percent), and Asia-Pacific (29 percent).

The "Cyber incident response: Are business leaders ready?" report is available here (PDF) for download.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
A Startup With NSA Roots Wants Silently Disarming Cyberattacks on the Wire to Become the Norm
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/11/2021
Edge-DRsplash-10-edge-articles
Cybersecurity: What Is Truly Essential?
Joshua Goldfarb, Director of Product Management at F5,  5/12/2021
Commentary
3 Cybersecurity Myths to Bust
Etay Maor, Sr. Director Security Strategy at Cato Networks,  5/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32238
PUBLISHED: 2021-05-18
Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.
CVE-2020-23851
PUBLISHED: 2021-05-18
A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by submitting a malicious jpeg image.
CVE-2020-23852
PUBLISHED: 2021-05-18
A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial of service by submitting a malicious jpeg image.
CVE-2020-23856
PUBLISHED: 2021-05-18
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
CVE-2020-24026
PUBLISHED: 2021-05-18
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting...