As the number and costs of cyber-attacks and data breaches continue to rise, more money is being thrown at the problem. IDC projects that by 2022, organizations will spend $133.8 billion to protect their IT infrastructures against cybersecurity threats.
With this much money being spent, organizations may want to target their efforts as efficiently as possible. Here are three critical areas that represent the most frequent and emerging causes of data breaches, with suggestions on steps you can take to prevent them--without breaking the bank.
1. Flawed cloud configurations
As more data is moved to the cloud, hardly a day goes by when a security incident involving misconfigured cloud storage configurations doesn’t make the headlines. Indeed, the cloud systems of Verizon, GoDaddy, the U.S. Department of Defense, and Capital One have all been compromised in recent years, leading to the breach of millions of customer records
But as we wrote previously, when discussing lessons learned from the Capital One data breach, such incidents are entirely preventable – if cloud users observe the cloud shared responsibility model. That model, stipulated in all cloud service agreements, makes it clear that cloud service providers (CSPs) are responsible for the security of their cloud infrastructure, while customers are responsible for security in the cloud – such as patches and updates, configuration and management tasks, and managing data.
Yet, only 10% of CISOs report that they fully understand the shared responsibility model, and 82% have experienced security incidents due to confusion over who has responsibility for what in the cloud. This can lead to misconfigurations or the mistaken belief that executives aren’t liable for losses as a result of a cloud breach.
Read more about how you can ensure your cloud data is protected, without overwhelming security teams with alerts and actions.
2. Vulnerable third parties
A study by Opus and Ponemon Institute found that third parties are one of the fastest growing risks to an organization’s sensitive data. Indeed, 59% of companies having experienced a third-party data breach.
Third-party risk management, however, can be extraordinarily challenging, since our vendor networks are growing at an exponential pace. Today, 60% of organizations work with more than 1,000 third parties. Unsurprisingly, only 16% say they take steps to effectively mitigate risk in their vendor ecosystems.