Data breaches begin close to home

Opinion
Aug 31, 20102 mins

* Compromises of database servers comprise 25% of breaches, but 98% of total records.

Last issue I pointed you to a story that Oracle’s Mark Dixon had sent me about a manager who kept using the accounts of departed subordinates to co-sign authorizations that helped her steal $11 million dollars from her organization. Mark had more to say on data breaches, though.

He also mentioned a Webcast presentation by Andrew Jaquith, (senior analyst, Forrester Research). Using source data from DatalossDB.org, Andrew reported that in 2009, 138 million data records were breached. By any measure, that’s a lot of data, resulting in large financial losses to corporations and lots of consternation to individuals whose identities may be included in those data breaches.

Surprisingly, of the 138 million breached records, a full 133 million breached records occurred at the server level. That’s right, it wasn’t stolen or misplaced laptops and thumb drives that were breached. Dixon also mentioned the Verizon 2010 Data Breach Investigations Report, which stated that compromises of database servers comprised 25% of breaches, but 98% of total records.

So, while we may hear about more case of data breaches occurring from edge devices, Mark thinks that the real challenge is protecting the core database from threats.

Some other interesting stats from the report were that while 70% of data breaches involved outsiders (down 9% from 2009), insiders were involved in 48% of breaches — an increase of 26% from the preceding year. (Twelve percent of breaches were traced to multiple parties, so the percentage of insiders and outsiders adds to more than 100%).

While the number of breaches attributable to hacking dropped 24%, those involving abuse of privileged accounts increased 26% to 48% of all breaches.

I hope I’m getting through to you that access governance, data governance, policy management and all the other aspects of IdM in the workplace need to be done right, now more than ever. It wouldn’t be a bad time to do a full-scale policy audit to see if you’re in compliance with industry best practices. There’s no better time to start than today.