Networking: Human error largely to blame
April 17, 2006What's the most grave IT security threat today? Hackers? Overly complicated corporate networks? None of the above, experts are telling United Press International's Networking column. Good, old-fashioned human error -- not nefarious, new technologies or super-sophisticated computer geeks, holed up in a shack near the Caspian Sea by the Russian mafia -- are to blame for about 60 percent of IT security breaches.
A new survey, a copy of which was provided to Networking, by the Computing Technology Industry Association (CompTIA), said human error is increasing as an IT problem. Last year, only 47 percent of security breaches were blamed on human error alone.
Though miscues by staffers are largely to blame, only 29 percent of the 574 organizations that participated in the CompTIA survey indicated that security training is a requirement at their company. Only 36 percent of organizations offer end-user security training.
"The person behind the PC continues to be the primary area where weaknesses are exposed," said Brian McCarthy, chief operating officer, CompTIA. "The primary cause of security breaches is not being adequately addressed."
That's because the primary focus of most IT vendors is, simply put, selling hardware or software solutions to their customers. "Where does your e-mail message travel after you hit send?" a spokesman for vendor Echoworx Secure Mail, asked Networking, rhetorically. "Who might be scanning your message? Is it a good guy just doing his job? Or is it a bad guy with malicious intent? When it comes to e-mail and protecting your identity, these are questions that everyone should consider, but most people never think about."
This week, Echoworx is introducing a new desktop-to-desktop e-mail encryption tool to secure the confidentiality of communications.
Other sophisticated security infrastructure, similar to that technology, has emerged over recent years and enables IT departments to more effectively detect and prevent attacks. For example, the CompTIA study demonstrated that anti-virus software is "nearly universal" with nearly 96 percent penetration. The vast majority or organizations utilize firewalls and proxy servers, at 91 percent. What is more, disaster recovery plans, intrusion detection systems and written information security policies are also popular measures, the survey showed.
"As we get better from a technology standpoint, many organizations seem to believe that technology solutions alone are sufficient to turn back all attacks, and a level of complacency may be setting in," McCarthy said.
But, McCarthy stressed, the fact is that no technology "on its own" can be completely successful without a strong commitment to information security awareness and training throughout every level of the organization.
To be sure, hackers are still on the attack - whether they be employed by the Russian mob or not. Virus and worm attacks were the "most commonly mentioned" security problem in the CompTIA study, which was completed by TNS Prognostics, a leading market research firm.
Approximately 40 percent of organizations participating in the survey said they had experienced at least one security attack in the past year. The most severe security breaches were reported by large organizations -- with 7,000 or more employees -- and educational institutions, like colleges and high schools. The mean value for each security breach is $11,000, according to the survey by the Oakbrook Terrace, Ill.-based trade association.
Experts tell Networking that there is no way to completely prevent IT security problems from happening. "Executive summary -- nothing is 100 percent secure," Ted Demopolous, an IT consultant, based in Durham, N.H., and business book author, told Networking.
Copyright 2006 by United Press International
-
Spy software can see smartphone texting realtime (w/ Video)
Nov 04, 2011 |
3.5 / 5 (6) |
1
-
Integrated bioinformatics gateways portal and interface
Sep 22, 2011 |
not rated yet |
0
-
SDSC announces scalable, high-performance data storage cloud
Sep 22, 2011 |
5 / 5 (1) |
0
-
Silicon Valley on Apple post-Jobs: success for now
Aug 26, 2011 |
not rated yet |
0
-
Security needs drive cyberforensics
Nov 23, 2010 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
More news stories
Walney offshore wind farm is world's biggest (for now)
(PhysOrg.com) -- The Walney wind farm on the Irish Sea--characterized by high tides, waves and windy weather--officially opened this week. The farm is treated in the press as a very big deal as the Walney ...
GPS court ruling leaves US phone tracking unclear
A US Supreme Court decision requiring a warrant to place a GPS device on the car of a criminal suspect leaves unresolved the bigger issue of police tracking using mobile phones, legal experts say.
15 hours ago |
4 / 5 (2) |
0
Europeans protest controversial Internet pact
Tens of thousands of people marched in protests in more than a dozen European cities Saturday against a controversial anti-online piracy pact that critics say could curtail Internet freedom.
11 hours ago |
5 / 5 (6) |
0
Netflix settlement trims 14 pct off 4Q earnings
(AP) -- Netflix pressed the rewind button on its fourth-quarter earnings after settling allegations that the video subscription service violated a consumer-privacy law.
15 hours ago |
not rated yet |
0
Navy to begin tests on electromagnetic railgun prototype launcher
The Office of Naval Research (ONR)'s Electromagnetic (EM) Railgun program will take an important step forward in the coming weeks when the first industry railgun prototype launcher is tested at a facility ...
Feb 06, 2012 |
4.7 / 5 (15) |
91
|
Europe stakes billion-dollar bet on new rocket
A pencil-slim rocket is scheduled to lift into space from South America on Monday, carrying a billion-dollar bet that Europe can grab a juicy slice of the market to place satellites in low orbit.
Study finds that anti-diabetic medication can prevent the long-term effects of maternal obesity
In a study to be presented today at the Society for Maternal-Fetal Medicine's annual meeting, The Pregnancy Meeting, in Dallas, Texas, researchers will report findings that show that short therapy with the anti-diabetic medication ...
Steroid injections prove effective in treatment of lumbar disc herniations
The use of epidural steroid injections may be a more efficient treatment option for lumbar disc herniations, according to research presented today at the American Orthopaedic Society for Sports Medicine's Specialty Day in ...
Amateur football players not always keen on returning to play after ACL injuries
Despite the known success rates of reconstructive Anterior Cruciate Ligament (ACL) surgery, the number of high school and collegiate football players returning to play may not be as high as anticipated, say researchers presenting ...
Explained: Sigma
It's a question that arises with virtually every major new finding in science or medicine: What makes a result reliable enough to be taken seriously? The answer has to do with statistical significance -- but ...
Political leaders play key role in how worried Americans are by climate change: study
More than extreme weather events and the work of scientists, it is national political leaders who influence how much Americans worry about the threat of climate change, new research finds.