September marked a month of heated discussion concerning data privacy issues, with continuing coverage in the media regarding breaches at major, global institutions. Bitsight looked into the types of breaches experienced by the finance sector over three years of data to determine whether web application compromise is on the rise as well as the impact of these events.
Figure 1
Figure 1 displays the proportion of breaches within each industry sector collected by Bitsight since 2015 with darker colors correspond to a greater prevalence of a certain breach type. Only 11% of the finance sector breaches in the past 3 years list web application compromise as their primary cause. In contrast, 38% of incidents were caused by employee error and another 11% resulted from privilege abuse.
By itself, this finding would suggest that financial organizations should focus on implementing trainings and controls that limit the damage that can be done by poorly equipped or disgruntled workers. By doing so they might expect to reduce their risk of all breaches by almost half. However, we know that the data breach landscape is not static, and that the relative frequency of these event types has changed over time.
Figure 2
When we include a temporal aspect, it becomes clear that there has been a fundamental shift in the types of events experienced by the finance sector. In 2015, web application compromise made up only 8% of the breaches observed by Bitsight at financial organizations.
Figure 3
By 2016, web application compromise rose to 11% (Figure 3).
Figure 4