Report finds most data breaches are 'utterly preventable'

Powered by SC Magazine
 

SQL injection attacks still a major headache.

Most security breaches are caused by malware, an SQL injection attack or the exposure of remote access credentials such as a VPN password, according to a report by Verizon Business.

Verizon's 2009 Supplemental Data Breach Investigations Report, released today, said that malware such as keyloggers and spyware were responsible for the majority of data breaches.

Mark Goudie, managing principal at Verizon Business, told iTnews that the biggest surprise was that SQL injection attacks - which he described as "utterly preventable" - were still responsible for causing so much damage.

"This is an utterly preventable security flaw," he said. "You can get freeware scanners that will look for a SQL injection vulnerability."

But simply realising that a dangerous flaw existed wasn't enough to make organisations plug the security hole, he said.

"Over half of those cases had highlighted SQL injections in the scan reports as the only high risk vulnerability or exposure - and [yet] they had done nothing about it," said Goudie.

Shared or default remote access credentials also caused havoc, according to Goudie, who said "44 percent of the cases we investigated had a partner asset or connection involved in a data breach."

This means VPN credentials trusted to a third party were stolen or compromised and they were then used to remotely access the victim's network.

"Organisations were using common credentials across multiple organisations and certainly across multiple sites. They were breaking some of the basic rules of information security," said Goudie.

Preventing the majority of the security breaches described in the report would have been neither expensive or difficult, Goudie said.

"In 53 percent of cases we investigate, the [actions] that would have prevented the compromise, are simple or cheap. In only 13 percent of cases, victims would have needed difficult or expensive counter measures to prevent the breach," he said.


Report finds most data breaches are 'utterly preventable'
 
 
 
Top Stories
Qld Transport to replace core registration system
State's biggest citizen info repository set for overhaul.
 
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  21%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 897

Vote