This week the 13th edition of the Verizon Data Breach Investigations Report (DBIR) was released, which is usually a hallmark event of the cybersecurity world. As we have been in previous years, Bitsight is proud to be a data contributor to the report. After taking some time to give it an initial read through, however, one thing stood out loud and clear to us: how little has changed after 13 years.
Going back to revisit the 2019 and 2018 reports, our suspicions were confirmed-- sure a few percentage points have changed here and there, but overall the state of the cybersecurity world is much the same.
Does this mean the DBIR is irrelevant? A relic of a bygone era that we cling to because we always have?
Hardly.
Our main takeaway is that Instead the 2020 DBIR is another excellent, very well-researched piece of work that illustrates the need for change in our industry. Security and risk leaders appear to be doing the same things, year in and year out, with the same predictable results. If those results reflected perfect performance, the lack of change would be comforting. But instead the report shows that while the attack methods evolve (see: the rise in ransomware), organizations of every size continue to be vulnerable to breach.
So we here at Bitsight would say that rather than dismissing the report as more of the same, it should serve as a clarion call to security pro’s everywhere that we need to rethink how we approach security, and a data-based demonstration that we need to break out of old habits and old thinking.
What Stood Out?
At 119 pages the DBIR is a lot to digest, however a few things already stood out to us as we dove into the report, and took a glance back at last year’s: