About
Subscribe

Companies underestimate internal threat, says KPMG

Johannesburg, 29 Mar 2001

A global e.fr@ud.survey conducted by KPMG reveals that South African company executives, like their global counterparts, are ill-prepared to counter threats to their network systems.

Some 43% of CEOs, CIOs and other senior management from 102 public and private companies in SA said that the greatest e-commerce threat to their organisation would arise from a lack of employee awareness, 38% said it would arise from poor implementation of security policies, while 37% said hackers presented the greatest threat.

Globally, 79% of participants in 12 countries said that a breach in their e-commerce system would most likely be perpetrated through the Internet or other external access. It is well documented, however, that the greatest risk is from internal perpetrators - such as disgruntled or former employees or external service providers who have an established relationship with the company - who may commit the breach, or may supply the information necessary to do so to someone else.

"Most security breaches are committed by individuals who possess intimate knowledge of the systems they are attacking," says Tony Wright, partner of KPMG Forensic and Investigative Accounting Group. "If senior management understood that, they might handle their security issues very differently."

The survey also found that companies are failing to put in place policies that could prevent and help prosecute e-commerce fraud. Fewer than 35% of executives surveyed said that security audits are performed on their e-commerce systems (compared to 44% in SA), and only half have incident response procedures in place for when they do discover a breach (compared to 43% in SA).

"The first thing most companies do when there is a security breach is fix it right away so they can get their e-system back up for business," says Wright. "But they don`t realise they are destroying evidence and making it almost impossible to recover assets or pursue legal action. It`s like cleaning a crime scene before dusting for fingerprints."

According to the survey:

  • 86% of respondents consider themselves somewhat to very knowledgeable about e-commerce (compared to 30% in SA).

  • Only 22% of companies have computer forensic response guidelines (21% in South Africa).

  • Only 62% perform background checks on the entities that assist them with the development, maintenance and/or administration of their e-commerce system (50% in SA).

  • 9% (6% in SA) have had a security breach in the last 12 months. Of those, an astonishing 83% said legal action was not pursued (50% in SA).

  • 72% said their greatest concern was the risk of damage that may be caused to their company`s reputation as a result of a security breach (this was also the greatest risk in SA).

  • Respondents said that security of credit card numbers and personal information were by far the most important concerns to their customers (also the primary concerns in SA).

KPMG believes the number of reported breaches is understated. There may be a variety of explanations for this, including an understandable reluctance to report breaches to protect the company`s reputation.

In addition, respondents may not have been made aware of security breaches within their organisation, or attacks or intrusions have gone undetected by the organisation. The survey also acknowledges that participants sustaining a security breach may have chosen not to respond to this question.

The survey results were similar among companies throughout the world, in both developed and developing countries, indicating that national and geographic boundaries matter little when it comes to fraud in the global electronic marketplace.

To prevent and detect e-fraud, KPMG recommends companies implement a comprehensive security programme often referred to as the "onion" model, because of its many layers. The model includes the use of encryption, firewalls, intrusion detection systems, incident response procedures, including computer forensic response guidelines, monitoring and external audits.

Results of KPMG`s 2001 Global e.fr@ud.survey are based on 1 253 responses from the largest public and private companies in Australia, Belgium, Canada, Denmark, Germany, Hong Kong, India, Italy, SA, Switzerland, UK and US.

Share

Editorial contacts