Security breaches hit highest ever level
Pricewaterhouse Coopers' annual survey has shown more security breaches than ever before.


Security breaches within organisations have reached their highest ever level, according to new research.
The annual security survey, presented by Pricewaterhouse Coopers LLP at InfoSecurity 2010, showed more breaches than in the survey's 10-year history, even topping the massive influx of worms back in 2004.
The report claimed 83 per cent of small businesses had suffered from breaches in the past year whilst both small and large organisations saw triple the amount of malware infecting their systems.
"You are seeing similar patterns in the rise of theft and fraud," said Chris Potter, information security assurance partner at Pricewaterhouse Coopers LLP.
"Unfortunately it is not just the number of organisations affected which has gone up. If you take large respondents those with more than 250 employees the median number of breaches... has gone up from 15 to 45 per year."
Potter also revealed the cost to the business per breach has risen by threefold, with the total for all businesses rising to an estimated 10 billion.
But is causing this huge rise? Andrew Beard, information security advisory director at Pricewaterhouse Coopers LLP, believes it is down to the speed in which technology is being embraced in 2010.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Technology is evolving quite rapidly," he said. "Now you may look at this and think the likes of VoIP and wireless networks aren't new technologies [but] what is significant here is the rapid adoption of that technology, especially in small organisations where [the use of] wireless networks has doubled, VoIP has trebled and all companies, big and small, have improved their remote access."
He added: "Typically though we have seen in the past that rapid adoption of technology does not lead to rapid adoption of controls to make sure it is used in a safe way."
Beard also believes the use of third party external services, such as software as a service (SaaS), without thorough checks and the embracing of social networking has helped the rise.
However, despite positive signs in the report that knowledge around the areas was increasing and good investment was being put into information security, the future outlook was still "gloomy."
"Most [survey] respondents don't think it is going to get any better," concluded Potter.
"Security professionals tend to be pessimistic at the best of times... but on balance four times as many people think there will be more security incidents next year than think will be fewer."
Jennifer Scott is a former freelance journalist and currently political reporter for Sky News. She has a varied writing history, having started her career at Dennis Publishing, working in various roles across its business technology titles, including ITPro. Jennifer has specialised in a number of areas over the years and has produced a wealth of content for ITPro, focusing largely on data storage, networking, cloud computing, and telecommunications.
Most recently Jennifer has turned her skills to the political sphere and broadcast journalism, where she has worked for the BBC as a political reporter, before moving to Sky News.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
PyPI attack: Targeting of repository 'shows no sign of stopping'
News Greater collaboration and understanding of attackers’ tactics is key to mitigating open source security threats
By Ross Kelly Published
-
Capita's handling of cyber attack shows companies still fail at breach reporting
Analysis Capita initially told customers there was “no evidence” of data having been compromised in the March cyber attack
By Ross Kelly Published
-
Malware being pushed to businesses by search engines remains a pervasive threat
News High-profile malvertising campaigns in recent months have surged
By Ross Kelly Published
-
There's only one way to avoid credential stuffing attacks
Opinion PayPal accounts were breached last year due to a credential stuffing attack, but can PayPal avoid taking responsibility?
By Davey Winder Published
-
Five things to consider before choosing an MFA solution
In-depth Because we all should move on from using “password” as a password
By Rene Millman Published
-
Cyber security suffers from a communication problem
News Negative language around ‘human failures’ is eroding trust between security teams and broader business functions - it has to stop
By Ross Kelly Published
-
Does LastPass really deserve a last chance?
Opinion After several disastrous security incidents and a communications breakdown, it’s time to leave LastPass for pastures new
By Ross Kelly Published
-
What is the spell-jacking vulnerability and how can your business avoid exposing data?
In-depth Spell-jacking vulnerabilities are threatening to unwittingly leak data to third parties, undermining any drive to protect privacy
By Davey Winder Published