iTnews
  • Home
  • News
  • Technology
  • Security

Verizon boosts Australian data-breach team

By Liz Tay
Jul 28 2010 2:18PM
Follow google news

US hacker conviction blamed for Asia-Pacific cybercrime upswing.

Verizon Business has tripled the size of its Australian data-breach investigations team to handle a growing number of breaches in Asia-Pacific.

Verizon boosts Australian data-breach team

Today it launched its Data Breach Investigations report based on global customer data and information last year from the US Secret Service, the arm of government that dealt with protecting that nation's financial systems from fraud and cybercrime.

More than half of the 100 cases investigated by Verizon last year were outside the US; 57 were data breaches.

Including 84 of Secret Service's data-breach cases last year, the report covered more than 143 million compromiseed data records.

Verizon noted that details of about two-thirds of cases in its report would never be disclosed because disclosure was not mandatory in many countries.

Although data breaches had declined, Verizon found its investigations last year were "quite large and complex", involving many parties, countries, related incidents and assets.

Its Asia-Pacific managing principal of Investigative Response, Mark Goudie, told iTnews that its Australian team grew 300 percent between 2008 and 2009.

Declining to disclose figures for competitive reasons, Goudie said Verizon relocated staff from other regions to Australia, making this the biggest team in the region.

He blamed the arrest and conviction of US hacker Albert Gonzalez for driving some cybercrime away from the US towards Asia-Pacific about last September.

"Almost straight away, computer crime in the US seemed to stop," Goudie said. "There was a significant uprising in computer crime and attacks in the APAC region at that time."

Hackers sought "anything they can convert into currency or can help with organized crime" - including personally identifiable information and payment card data, he said.

Australia's small, online retailers with up to 100 employees were found to be especially susceptible because hackers targeted "low-hanging fruit", with limited security capabilities, he said.

But even big, data-rich organisations in financial services, hospitality and retail industries fell folly to attacks that Verizon considered avoidable "if security basics had been followed".

iTnews has reported data breaches at Atlassian and StGeorge Bank during the past year. According to an August 2009 survey by the Ponemon Institute, two in three Australian organisations experienced a serious data breach that year.

"In most cases, it's the little things - a web server or system being out of date - the attackers are just looking for the one weak link," Goudie said.

Although 87 percent of data breach victims had evidence of the breach in their log files, 61 percent relied on a third party to discover the breach.

Malicious insiders, privilege misuse and social engineering tactics were blamed for 49, 48 and 28 percent of breaches, respectively, although Verizon noted that results could be skewed by the types of cases studied by the Secret Service.

Patchable vulnerabilities ceased to be an issue but SQL injection, stolen credentials, backdoors and customised malware were on the rise.

An otherwise secure company was caught out by sharing payment infrastructure with another, less secure company on the same web server, Goudie said.

Verizon had not detected increased risks in cloud computing or virtualisation although Goudie said it was "looking quite closely" at these areas.

"There are walls in between virtualised machines," he said. "We have not seen any links [between the technologies and increased data breach occurrences]."

Verizon's top data breach preparation tips for Australian organisations

1)  Use a firewall to filter outbound and inbound data.

2)  Ensure that servers never prompt an internet connection.

3)  Improve discovery-response times with usage logs.

4)  Ensure systems are current and there were no weak links.

5)  Prepare to handle compromised systems.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
data breachsecuritystrategyverizon

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
AI is delivering business value today
Partner Content AI is delivering business value today
You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.