|
Does Verizon's Voyager stack up to the iPhone? |
|
|
5 IT skills that won't boost your salary
[1,407]
Women 4 times more likely than men to cough up personal info
[589]
Japan's 10 funniest tech-related commercials [Videos]
[407]
Throwing away a promo CD is "unauthorized distribution"?
[1,265]
Adults too quick to dismiss educational video games
[682]
Attack of the iPhone clones [Slideshow]
[578]
10 things IT needs to know about AJAX
[1,258]
This Year's 25 Geekiest 25th Anniversaries [Slideshow]
[409]
|
|
The key word here is "detected"
With many companies still looking outward and only deploying protection at the perimeter, it's possible that many internal issues, between local domains, may not even have been picked up. If they were picked up then it may have been by a manual process inside the company (audit?) and not made known to the Verizon technologies deployed. Internal threats and issues tend to carry a greater possibility of reputaitonal damage, so if discovered internally they may have been hushed up?
verison study.
which came first the chicken or the egg? common sense dictates that external breachs are many times the work of internal persons. after all it only makes sense to learn the system and then hack from the outside rather than internally. particularly if you have insiude info.
<img src="http://browseblogs...
"I am going to have to rethink my long-held stance – originating in the 1980s – claiming that the bulk of the threats to information systems are internal."
I have worked in the industry for 15 years and let me tell you the internal sources are few but result in way more damage than the external ones.
Correct..
I have worked in industry 30+ years and can tell that you are absolutely correct. Now, of course, the public very seldom sees the damage when and if it can be kept quiet. There are many problems if the "information" security is seen IT only - the data may mostly be in computer systems but the misuse often goes well beyond what one or even an IT group can manage.
Question Authority
Well don't you also want to focus the scientific lense of doubt on the Verizon study as well? In another section of the report regarding compromised data they state that the kind of forensics work they do skews the results. Internal investigations probably find the "evil insider" easier so no recourse to folks like Verizon.
Labeling?
Consider too the possibility that insider data breaches may be labeled as something else: theft, misuse of authority, data corruption, data destruction etc. "When an outsider attacks, it's a security incident; when a insider attacks, it's bad behavior."
Post new comment