| | |

Verizon – DBIR2015 Breach Panel

April 2015 – The annual Verizon briefing to overview their Data Breach Incident Report (DBIR) [http://www.verizonenterprise.com/DBIR/2015/ ]took place at the RSA conference in San Francisco. The report once again showed a rise in both the number of data breaches reported, and a cost per incident for remediation. The Panel this year was introduced by Janet Brumfield Director of Corporate Communications for Verizon. The panel itself was moderated by Mike Denning, VP of Global Security for Verizon, and the panelists were Brian Sartin – Director of RISK team, Verizon; Paul Nikhinson – Privacy Breach Response, Beazley Group; Emily Mossburg – Leader Cyber Risk Services Resilieant Practics, Deloitte & Touche; Sherry Ryan – VP, CISO, Juniper Networks; and Scott Swantner- Agent, US Secret Service.


Verizon 2015 RSA Data Breach Panel

 

The issues covered included crime scene integrity, costs of cyber insurance, accidental covering the tracks of the intrusion in the course of the investigation, proactive reporting and working with law enforcement. One of the big areas determining the extent of the breach and what data was taken. This has been made more complicated with the combination of ransomware and data theft, as the resulting data and the trail are rencrypted and held hostage, thus reducing the ability to determine what has left the premises and may have been taken. In these cases, the reported breach must still inform all the potential individuals in the affected databases that a breach has occurred, even if their record may not have been affected. As a result, the cost of the investigation and reporting has significantly increased of the cost of a databreach at most companies.

For 2014, the estimated financial loss from the 700 million compromised records was $400Million USD. Once again over 80% of the attacks were from external sources. One of the most interesting changes in the threat actor category came to light with the addition of motive to the Vocabulary for Event Recording and Incident Sharing (VERIS). The new category called “secondary” was added to better track these attacks that took place in combination with a primary motive, to indicate that the victim
was targeted as a way to advance a different attack against another victim.

The finding indicated that Strategic web compromises are a good example. In these campaigns, a website is hacked to serve up malware to visitors in hopes that the actor’s true target will become infected. Verizon found that in the 2014 data set that nearly 70% of the attacks where a motive for the attack is known include a secondary victim. This creates an additional level of complexity in incident tracking and breach detection as the data loss may not be at the original infected site.
 

Similar Posts