On TV.com: Why Is Everyone in TV High School SO OLD
BNET Business Network:
BNET
TechRepublic
ZDNet

November 9th, 2007

Most security breaches caused by careless human error

Posted by Michael Krigsman @ 2:04 pm

Categories: CIO issues, Security and privacy

Tags: Breach, Data, Productivity, Web Servers, Search, Security, Internet, Michael Krigsman

Security expert David Litchfield analyzed data breaches during 2007 and came up with interesting results:

Word documents and spreadsheets mistakenly left on a web server or indexed by a search engine account for 20.6% of the 276 breaches, both physical and digital, recorded up to the 23rd of October. This means that a fifth of the breach problem could be solved if companies actively and regularly hunted out such relict documents themselves.

David points out that these numbers are certainly low, since most criminals don’t report their activities.

In a related announcement, Chris Walsh reports on two studies that showed:

60-65% of breaches [are] due to lost or stolen media and 15-25% [of breaches are due to data] exposed online.

Here’s a table showing this data:

Most security breaches caused by careless human error

Based on these reports, it’s clear the vast majority of data breaches are caused by human error: data custodians inadvertently leaving files exposed to search engines, or else losing storage media (and laptops) containing secure data.

It’s tempting to believe that security data breaches result from the hands of evil hackers, secretly using advanced techniques to pry into sensitive and well-guarded computers. Unfortunately, the reality is that most breaches are caused by plain old carelessness.

Michael KrigsmanMichael Krigsman is CEO of Asuret, Inc., a software and consulting company dedicated to reducing software implementation failures. Click here to discuss this post with him on Twitter. See his full profile and disclosure of his industry affiliations.

Email Michael Krigsman

Subscribe to IT Project Failures via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
Workers don't follow IT policies
Many organizations have proper IT policies in place. However, it's difficult to impossible to enforce those policies all the time.... (Read the rest)
Posted by: mkrigsman@... Posted on: 11/09/07 You are currently: a Guest | | Terms of Use
How about...  dahowlett@...ZDNet Moderator | 11/09/07
The executives prefer to focus on the bottom line...  merlin747 | 11/09/07
Workers don't follow IT policies  mkrigsman@...ZDNet Moderator | 11/09/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads