Companies found malware faster, but most of them needed the help Trustwave says Companies have shortened the amount of time between malware infection and discovery, but too few organizations detect the breach on their own, a security report found.The median number between intrusion and detection was 87 days, while the median from detection to containment was seven days, Trustwave found in its 2014 report released Wednesday. The findings were based on 691 data breach investigations conducted over the last year.Until the latest report, data-protection vendor Trustwave had used average times between infection, detection and containment. On that basis, the time between intrusion and detection was 134 days, a reduction of two-and-a-half months from 2013.Nevertheless, self-detection of malware remained low at 29 percent, the study found. The majority of organizations were notified of a possible infection by third parties, such as a regulatory body, bank, credit-card company, law enforcement, customer or partner. “That’s just a horrible statistic in general,” Karl Sigler, manager of threat intelligence for Trustwave, said.Once aware of the breach, companies worked quickly to contain it, as the seven-day median shows, Sigler said. Two-thirds of the organizations in the study contained the malware in less than 10 days. “That’s a phenomenal statistic compared to in the past,” Sigler said. “Sometimes breaches would take months to actually contain.”Companies’ failure to detect breaches on their own is typically due to poor configuration of intrusion detection systems, Sigler said. Organizations also fail to make good use of logs from security systems, servers and other network components to detect anomalies that could indicate an infection.A lot of companies have the products, but lack the expertise for monitoring network traffic and logs.“A lot of companies still seem to be under the impression that they can purchase a product and they’re secure in some fashion,” Sigler said. “Obviously, no product is magic and no product is going to be a silver bullet.”Security appliance vendor Check Point Software Technologies released a report this month that drew similar conclusions. The vendor found that 84 percent of the organizations studied have systems infected with malware and nearly three quarters had at least one bot on their network.While it’s true some malware do not present a threat, detection is the only way to make that determination, experts say. Trustwave found an increase in the number of companies using third parties to manage security and perform code auditing and penetration testing, Sigler said. The study found that the number of breached organizations with outsourced IT functions fell to 46 percent, a decrease of 17 percent from 2012.More than half of data-theft incidents involved payment card data, either from e-commerce sites or electronic cash registers, Trustwave found. However, the number of cases that resulted in the loss of sensitive information, such as financial credentials, internal communications and other personally identifiable information, rose 33 percent.“If this data set speaks to broader trends, it appears that attackers are more aggressively setting their sights on other types of confidential data, and businesses that don’t process payment cards should prepare to take action,” the report said. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe