285 million records breached, most attacks came from external sources, according to Verizon study 2008 was a banner year for security breaches, according to new research from Verizon. And while many security vendors have been banging the drum about the threat of malicious insiders, this report indicates organizations should be more wary of outside attacks (Read Senior Editor Bill Brenner’s take on the insider threat in Laid-off Workers as Data Thieves?)The “2009 Verizon Business Data Breach Investigations Report,” released this week finds that hackers continue to intensify and sharpen their efforts to steal sensitive data. In fact, more electronic records were breached in 2008 than the previous four years combined. The study’s authors said the upswing is fueled by a targeting of the financial services industry and a strong involvement of organized crime. Corporations fell victim to some of the largest cybercrimes ever during 2008, noted the report (Get tips on surviving a breach investigation in 5 Ways to Survive a Data Breach Investigation).The findings debunk the motion that insiders account for the biggest threat to security in most organizations and instead finds that 74 percent resulted from external sources. Only 20 percent were caused by insiders.“Outsiders are going to exceed insiders in number. There are more of them. It makes sense that that attack ratio would be there,” said Wade Baker, a Research and Intelligence Principal with Verizon. The study, the second annual conducted by Verizon, is based on data analyzed from Verizon Business’ actual caseload comprising 285 million compromised records from 90 confirmed breaches. The financial sector accounted for 93 percent of breaches, and a staggering 90 percent of these records involved groups identified by law enforcement as engaged in organized crime.“The world of cybercrime has definitely moved away from the teenage hacker in the basement motif to it’s a business now,” said Baker. “It really does have an effect. When you gather a group together and they all share this purpose of compromising data, then they leverage their collaborative resources and can do attacks one person would not have the time, resources or computing power to do.” Baker also noted that the investigation found most breaches were avoidable. Nearly nine out of 10, 87 percent, were considered avoidable through simple or intermediate controls.“If you look at the top three types of hacking, the ways criminals get in the door, it is default credentials, it is SQL injection and poor access control,” said Baker. “From that standpoint the method of entry into the corporate network, they aren’t using very sophisticated methods. If you did things well, you would be able to prevent that.”Additionally, 81 percent of victims were not Payment Card Industry (PCI) compliant. A statistic Baker said study authors interpreted as testimony to the effectiveness of PCI DSS.The study found that highly sophisticated attacks account for only 17 percent of breaches and 83 percent of attacks were considered to be what Verizon termed as “not highly difficult” to pull off. However, the study authors also note that while the percentage of sophisticated attacks was small, they accounted for 95 percent of the total records breached. The numbers, according to Baker, once again point to the sophistication and power of today’s organized cybercriminal networks. *Download a pdf copy of the report and check out the cover page. There is a reason why 0s and 1s were chosen. Can you figure it out? Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe