Detailed empirical data on IT Security breaches is hard to come by despite laws like California SB1386. So there is much to be learned from Verizon Business’s April 2009 Data Breach Investigations Report.
The specific issue I would like to highlight now is the
section on methods by which the investigated breaches were discovered (Discovery
Methods, page 37). 83% were discovered by third parties or non-security employees
going about their normal business. Only 6% were found by event monitoring or
log analysis. Routine internal or external audit combined came in at a rousing
2%.
In addition, these numbers point to the difficulties in deploying viable detection controls, as there were a significant number of organizations that had purchased detection controls but had not put them into production. Again, I have seen this myself as most of the tools are too difficult to manage and it’s difficult to implement effective processes.

Comments