|
Latest
Ponemon Institute Study Ties Lack of
Awareness in Corner Office
to Insider Threat Challenges
New Study Links Inadequate
Resources and Leadership to Increased
Insider Threats
Elk Rapids, Mich. and Cupertino,
Calif. – September 12, 2006 –
Privacy and information management
research firm the Ponemon Institute
and ArcSight, Inc., a global leader in
Enterprise Security Management (ESM)
software, today released a new study
showing that IT security professionals
believe poor leadership at the
executive level, coupled with a lack
of accountability, is a major
contributor to the breakdown in
corporate data integrity. The study,
National Survey on Managing the
Insider Threats, is drawn from the
responses of more than 450 U.S.-based
IT security professionals, and points
to resource and leadership failures as
a primary cause of employee
complacency, negligence and malicious
behavior resulting in both intentional
and inadvertent compromise of business
and personal information.
The study, sponsored by ArcSight,
examines experienced IT security
professionals’ opinions related to the
causes, responses and solutions to the
insider threat to data integrity. For
the purposes of the study, "insider
threat" is defined as the misuse or
destruction of sensitive or
confidential information, as well as
IT infrastructure that houses this
data, by employees, contractors and
others with access to sensitive or
confidential information. The National
Survey on Managing the Insider Threats
found that:
- More than 78% of respondents
reported one or more unreported
insider-related security breaches
within their company.
- 93% of respondents attributed
lack of resources and 81% of
respondents cited lack of
accountability as two primary
contributing factors to poor data
security.
- Respondents ranked the top three
threats to data integrity as:
- Missed or failed security
patches on critical applications
- Accidental or malicious
insider misuse of sensitive or
confidential data
- Virus, malware, and spyware
infections
- 89% view insider threats as
serious, yet only 49% think CEOs
have the same perception.
Furthermore, the National Survey on
Managing the Insider Threats
calculated the average annual cost of
insider data breaches at $3.4 million,
and found that spending on
technologies and programs aimed at
addressing the insider threat seemed
insufficient.
"Whether through neglectful or
malicious activity, insiders pose a
constant and serious threat to data
integrity, and our study helps to
identify the primary causes for this
serious challenge to corporate
security," said Dr. Larry Ponemon,
founder and chairman of the Ponemon
Institute. "By identifying causes, we
believe our efforts can also help IT
security professionals develop winning
strategies for addressing the insider
threat."
"While addressing insider threats
has become a top priority for many of
the commercial and government
organizations we work with, this study
is evidence that more education is
necessary beyond the IT security
department on the potential threat,
whether it’s losing control over
confidential information or insider
activity related to IT sabotage and
fraud," said Steve Sommer, senior vice
president of marketing and business
development at ArcSight. "While many
IT security professionals use a
combination of manual controls and
technologies to address insider
threats, they require a combination of
incident prevention, detection and
response. We’re helping organizations
gain a comprehensive view into their
security postures for early insight
into suspicious activity."
Copies of Survey on Managing the
Insider Threat are available through
the Ponemon Institute and through
ArcSight.
About the Ponemon Institute
The Ponemon Institute is dedicated
to advancing responsible information
and privacy management practices in
business and government. To achieve
this objective, the Institute conducts
independent research, educates leaders
from the private and public sectors
and verifies the privacy and data
protection practices of organizations
in a variety of industries.
About ArcSight
ArcSight, a leader in Enterprise
Security Management, provides
solutions that serve as the mission
control center for real-time threat
management, compliance reporting and
automated network response. By
comprehensively collecting, analyzing
and managing security data, ArcSight
solutions centrally manage and
mitigate information risk for
security, insider threat and
compliance. ArcSight's customer base
includes leading global enterprises,
government agencies and MSSPs.
ArcSight and the ArcSight logo are
trademarks of ArcSight, Inc.
# # #
Press Contacts:
Mike Spinney
Ponemon Institute
978-597-0342
mspinney@ponemon.org
Erin O’Keeffe
Horn Group for ArcSight
415-905-4005
eokeeffe@horngroup.com
For more information on ArcSight
news, please contact: pr@arcsight.com
|