2010 Verizon Data Breach Report
The 2010 Verizon and U.S. Secret Service breach report is full of enlightening facts, figures and statistics. I highly recommend you read it cover to cover. It breaks down the breaches by demographic, threat agents, threat actions, attack difficulty and targeting, vertical, and time span. It also compares how PCI compliance affected the number and severity of breaches. This is the first year that Verizon has teamed up with the Secret Service to expand reporting on breach incidents. This reporting is highly regarded as a source for intrusions into the customers of Verizon’s widely adopted communications services. DBIR series now spans six years, 900+ breaches, and over 900 million compromised records.
http://www.verizonbusiness.com/resources/reports/rp_2010-data-breach-report_en_xg.pdf
Highlights:
- Who is behind Data Breaches?
70% resulted from external agents (-9%)
48% were caused by insiders (+26%)
11% implicated business partners (-23%)
27% involved multiple parties (-12%)
- How Do Breaches Occur?
48% involved privilege misuse (+26%)
40% resulted from hacking (-24%)
38% utilized malware (<>)
28% employed social tactics (+16%)
15% comprised physical attacks (+6%)
- What commonalities exist?
- 98% of all data breached came from servers (-1%)
85% of attacks were not considered highly difficult (+2%)
61% were discovered by a third party (-8%)
86% of victims had evidence of the breach in their log files
96% of breaches were avoidable through simple or intermediate controls (+9%)
79% of victims subject to PCI DSS had not achieved compliance
Older Reports:
2009:http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf
2008: http://www.verizonbusiness.com/resources/security/databreachreport.pdf
Tags: breaches, compliance, data breach report, malicious software, security, social engineering, statistics, verizon
Search:
Translate







Random Quote
The problem of viruses is temporary and will be solved in two years.
— John McAfee, 1988Handpicked News:
- NASA Is Considering Fuel Depots in the Skies - New York Times (Sci/Tech - Google News)
- Boston Police website hacked - msnbc.com (Sci/Tech - Google News)
- Google Serves Up Ice Cream Sandwich With a Nexus on the Side (LinuxInsider)
- Get Your External IP Address with a Quick Search for "IP" [Google School] (Lifehacker)
- Another Massachusetts Health Services breach – at least they HAVE to report it (ESET ThreatBlog)
- Flowchart Guides Readers Through the 100 Best SF Books (Slashdot)
- Analysis of compromised websites - hacked PHP scripts (Naked Security - Sophos)
- Alleged Celeb Hacker Glad He Got Caught; Was Addicted to Hacking (Threat Level)
- Shady Reshipping Centers Exposed (Slashdot)
- Dutch ISP Files Police Complaint Against Spamhaus (Slashdot)
Blogroll
- Rober Siciliano Identity Theft Expert
- Secureworks Research Threat Intelligence from Dell Secureworks. Colonel Barry R. Hensley, Vice President of the Counter Threat Unit (CTU)., Is the former Director of the Army’s Global Network Operations and Security Center (AGNOSC).
- SourceFire Blog Vulnerability Research Team
- Tippingpoint Blog Digital Vaccine Laboratories
Malware
- Anubis Submit your Windows executable and receive an analysis report telling you what it does. Alternatively, submit a suspicious URL and receive a report that shows you all the activities of the Internet Explorer process when visiting this URL.
- Virus Total the ISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers.
Security Links
- Data Loss DB Reports and maintains a searchable database of Data Loss incidents.
- DShield The ISC was created in 2001 following the successful detection, analysis, and widespread warning of the Li0n worm. Today, the ISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with I
- Internet Storm Center The ISC provides a free analysis and warning service to thousands of Internet users and organizations, and is actively working with Internet Service Providers to fight back against the most malicious attackers.
- Router Alley CCNA/CCNP Study Guides
- Sans Reading Room 1,895 original computer security white papers in 77 different categories.
Vendor Security Advisories
Who's Online
6 visitors online now2 guests, 4 botsPowered by Visitor Maps




1 Comment
i like it