A survey conducted by
Websense
at this year's
e-Crime
Congress in London suggests that employees are the greatest risk to any
organisation's data and intellectual property.
Some 95 per cent of the 105 international security professionals surveyed
said that their company would not be confident of knowing about an information
leak, and 64 per cent believed that the board would be held responsible should a
leak occur.
One in seven respondents believe that data leaks are widespread, and 15 per
cent indicated that most companies have experienced some form of data leak in
the past 12 months.
Internal threats such as data leakage through malicious intent or by accident
continues to be the greatest concern, topping the poll at 59 per cent. This
represents a 15 per cent increase on last year's annual e-Crime Congress survey.
Furthermore, 79 per cent believe that legislation should be in place to curb
data leakage and to ensure greater transparency in the advent of an information
breach.
However, it seems that little improvement has been made concerning
organisations' approach to security. Only 10 per cent of respondents felt that
companies were truly attempting to tackle the problem.
"This survey shows that companies are so busy fire-fighting external security
threats that when it comes to information leakage they are failing to address
the larger problem," said Ross Paul, international product manager at Websense.
"A proactive approach ensuring the enforcement of well-defined policies to
protect sensitive information is a must in stopping it getting into the wrong
hands."
When data breaches do occur, there is a consensus among respondents that
legislation should support the need for disclosure, according to Paul.
"With only five per cent believing that all companies are aware of
information leakage incidents, it is time for companies to actively take
responsibility in detecting and protecting against this invisible threat," he
said.
The survey also revealed that information breaches can cost as much as five
per cent of a company's annual revenue.
But it seems that legislation is helping to drive budget increases, as 62 per
cent agreed that measures such as the
EU
Privacy Directive (PDF) and
Sarbanes
Oxley have helped to drive budgetary increases for information leak
prevention.
Comments
Have your say on this article