Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


August 31, 2004

Computer Crime Survey Findings

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

A couple months ago, the Computer Security Institute released its annual CSI/FBI Computer Crime and Security Survey. Some of the survey's findings might surprise you. First, the total financial losses resulting from unauthorized use of computer systems dropped from $201.8 million last year to $141.5 million this year. Likewise, the percentage of respondents reporting unauthorized use of computer systems dropped from 58 percent 12 months earlier to 53 percent. How could financial losses and unauthorized use have dropped when all we hear and read about is security vulnerabilities and breaches? Does this desirable downward trend in the survey correspond to IT security incidents in general among companies and organizations? It's hard to tell from this survey because CSI doesn't explain how it selected the respondents. The press release announcing the survey suggests that the respondents were CSI member organizations. The press release quotes CSI Director Chris Keating as saying, "Although the CSI/FBI survey clearly shows that cybercrime continues to be a significant threat to American organizations, our survey respondents appear to be getting real results from their focus on information security. ... We don't believe that all organizations maintain the same defenses as our members--financial damages for less protected organizations are almost certainly worse." If the respondents were CSI members, it supports Keating's assessment that the survey "suggests that organizations that raise their level of security awareness have reason to hope for measurable returns on their investments."

Indeed, the survey could provide some ammunition to help you make your business case to management that investing in security pays off. But you can claim ROI only if you collect the right information over a sufficient period of time and analyze it properly. The survey shows that most of the organizations that experienced an overall decline in security incidents and losses also use one or more financial metrics to quantify the cost/benefit aspect of their security expenditures. Fifty-five percent of the total respondents reported using ROI, and about 25 percent used Net Present Value or Internal Rate of Return. What about you? Have you experienced a decline in security incidents or financial losses as the respondents in this survey have? Does your organization use a financial metric such as ROI, Net Present Value, or Internal Rate of Return to measure security problems in dollars and cents?

Another interesting statistic re-affirms what I've long held to be the case. Security incidents were fairly evenly split between insiders and outsiders, but insider incidents still led, especially in organizations with more than five incidents during the year. The lesson to learn here is that you need to spend just as much or more time thinking about security threats behind the firewall and designing countermeasures against internal threats as you do working against outsider threats.

As you might expect in this era of increased scrutiny on public organizations and accountability, companies aren't always anxious to make their security incidents public. In fact, the percentage of respondents reporting intrusions to the authorities declined from the previous year. This lack of "information sharing" makes it difficult for any of us to know the real story about IT security. It also highlights the fact that your incident response procedures should address more than just the technical risks of an incident--they should also spell out the public relations steps employees should take.

The survey has lots of other good information. Take a look, and tell me what you think. Are the results representative of the state of IT security at large? What other facts or trends did you find notable?

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Windows 7 Sets Sales Record

Microsoft CEO Steve Ballmer described Windows 7's first ten days of sales as "fantastic" while in Japan yesterday. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement