2017美国网络犯罪现状报告(英文版)_24页_461kb
报告摘要
2017 U.S. State of Cybercrime Summary
Core Content Overview
The document provides a comprehensive overview of the state of cybersecurity in the U.S. in 2017, based on survey responses from 510 organizations. It highlights the challenges and trends in cybercrime, information sharing, board involvement, security budgets, and the effectiveness of security programs.
Key Statistics
- Total Respondents: 510
- Job Title Breakdown:
- Corporate Management: 35%
- Director / Manager: 23%
- EVP, Senior VP, VP: 10%
- Other: 30%
- Company Size:
- 500+ Employees: 41%
- <500 Employees: 59%
- Average IT Security Budget: $11.0M
- Average Number of Employees: 9,795
Main Points
1. Information Sharing Challenges
- Organizations rely on multiple information sharing groups, but overall, information sharing remains a challenge.
- A significant portion of respondents (6 in 10) still view cyber risks as an IT issue.
2. Board Involvement in Cybersecurity
- The board is playing a greater role in cybersecurity, though the reasons vary by organization.
- More frequent briefings by CISOs/C SOs to the board are reported.
- Full boards and risk committees are increasingly taking on cybersecurity risk management responsibilities.
3. Security Budgets and Investments
- IT security budgets continue to increase year-over-year.
- Investments are being made to address cyber-risks, with a focus on detecting and mitigating threats.
- The average time to discover an intrusion has increased by more than one month since 2015.
4. Impact of Cybersecurity Events
- Despite a decline in the number of security events, the impact remains significant.
- Financial losses have remained the same versus previous years.
- Phishing and ransomware are the most reported impacts, with phishing showing an uptick since 2015.
- Critical system disruptions due to insider threats are a concern, with 47% of incidents attributed to employee negligence.
5. Perception of Cyber Threats
- Outsiders are generally perceived as a bigger threat than insiders.
- 72% of security events in 2017 were targeted attacks aimed at the company, employees, resources, or customers.
- 61% of security events that caused financial loss were targeted attacks.
6. Insider Threat Management
- Most insider threats are handled internally without involving legal action.
- Only one-third of organizations have a way to interpret intent from user behavior monitoring.
- Common approaches to funding insider threat programs are placed in the hands of IT, legal, and HR departments.
7. Technology Usage and Effectiveness
- Organizations use a variety of technologies to detect and counter security events.
- The effectiveness of these technologies is rated on a scale from 1 to 5, with some showing higher ratings than others.
- Only 26% of companies use dedicated mobile security technologies to secure devices.
8. Cybersecurity Policies and Procedures
- Security policies and procedures are used to deter, detect, and respond to cyber events.
- Over 50% of organizations have a formalized plan for reporting and responding to cyber events.
- Less than one-third update their cyber response plans frequently.
Key Trends
- Increased Board Involvement: Boards are becoming more involved in cybersecurity, with a growing number of CISOs/C SOs briefing them more frequently.
- Rising Concern: There is a notable increase in concern about cybersecurity threats in 2017 compared to 2016.
- Growing Complexity: Cyber threats are becoming more difficult to detect, and the average time to discovery has increased.
- Targeted Attacks: Targeted attacks are becoming more prevalent and are seen as more damaging than non-specific ones.
- Insider Threats: Employee negligence is the leading cause of insider threats, emphasizing the need for better education and awareness programs.
Challenges and Gaps
- Information Sharing: Despite reliance on multiple groups, information sharing remains a challenge.
- Expertise and Training: While 76% of organizations feel they have the expertise to address new technologies, there is still a gap in how they interpret and respond to threats.
- Response Planning: Only 43% of organizations have a formalized plan for responding to cyber events, and less than one-third update these plans frequently.
- Funding and Responsibility: Funding for insider threats is often managed by IT, legal, or HR departments, rather than being a top-down initiative.
Conclusion
The 2017 U.S. State of Cybercrime report indicates a growing awareness and concern about cybersecurity threats, especially those involving insiders and targeted attacks. While security budgets and technologies are increasing, there is a clear need for better information sharing, more frequent updates to response plans, and a stronger, more unified approach to cybersecurity management across all organizational levels.
试读结束,高清完整版pdf/doc/ppt,请点下载