About
Subscribe
  • Home
  • /
  • Computing
  • /
  • CSI/FBI Computer Crime and Security Survey reveals interesting statistics

CSI/FBI Computer Crime and Security Survey reveals interesting statistics

By Namitech
Johannesburg, 22 Jul 2003

Awareness of network management and security is growing continually, driven strongly by legislation, the need to protect mission-critical information assets and often, by simple common sense. But the costs of a comprehensive e-security programme can be high for large corporates; exorbitant, even, for smaller organisations. Is the investment always necessary? According to the 2003 CSI/FBI Computer Crime and Security Survey, most definitely.

The most important result from the survey was evidence that the risk of cyber attacks remains high, and that despite deploying an enviable range of security technologies, some organisations still fell victim to attacks that resulted in significant financial loss. However, while there is no shortage of malicious hacking activities, one positive may be that the severity of the resultant financial losses indicates a downward trend - the first time since 1999.

Some 530 computer security practitioners participated in the survey, coming from diverse industries such as corporations, governmental agencies, medical institutions and universities. Of these, 56% reported unauthorised use of their systems, with a total annual loss of $201 797 340, down 56% from last year`s survey.

According to Chris Davis, executive at NamITrust, the enterprise security division within NamITech, an important point to note is that this fairly high incident rate continues to be reported by organisations that actually do have security technologies in place.

"The CSI/FBI survey established that 99% of organisations are using anti-virus software, 98% have firewalls in place and 91% use some form of physical security to protect their computer and information assets. In addition, 92% have access control measures in place and 73% have deployed intrusion detection systems (IDS) across their networks.

"What is disturbing is that even with these security measures in place, 15% of the respondents admitted not knowing whether there had been any unauthorised use of their systems within the past 12 months," continued Davis. "In such situations, organisations need to consider the value that an outsourced security provider could hold for them."

Outsourcing involves entrusting an organisation`s system security to a specialised managed security services provider (MSSP) who then manages and monitors this round the clock, either on-site or remotely. They provide vulnerability assessments, real-time monitoring, intrusion detection services including incident reporting and overall security consulting.

"Security consultancies have trained and dedicated professionals on their staff, a resource that is scarce and often eludes non-specialist organisations. They are therefore far better placed to objectively assess the situation and to come up with workable suggestions. They also provide constant monitoring of safety levels and possible weaknesses, thereby avoiding this startling ignorance of unauthorised use or malicious attacks on the part of the organisation," concludes Davis.

Share

Editorial contacts

Victoria Sayers
Brand New Communications
(011) 458 0052