IDG-2017美国网络犯罪现状报告(英文版)-2017-26页
报告摘要
2017 U.S. State of Cybercrime Summary
Core Content
The 2017 U.S. State of Cybercrime survey, conducted by IDG and in partnership with Forcepoint, CSO, U.S. Secret Service, and CERT Division of Software Engineering Institute at Carnegie Mellon University, provides insights into the evolving landscape of cybercrime in the United States. It includes responses from 510 executives across businesses, law enforcement, and government agencies, with a margin of error of +/- 4.3%.
Main Findings
Cybersecurity Trends
- Board Involvement: The board of directors is increasingly involved in cybersecurity discussions, with CSOs/CISOs briefing the board more frequently. However, 60% of boards still view cyber risks as an IT issue, not a strategic concern.
- Security Events: The number of security events has declined since 2015, but monetary losses have remained the same.
- Severity of Impacts: The severity of cybercrime impacts has increased, with phishing and ransomware becoming more prevalent. Business Email Compromise has seen a sharp rise, and critical system disruptions are a growing concern.
- Concern Levels: Concern about cybersecurity threats has increased significantly in 2017 compared to 2016.
Cybercrime Sources
- Outsiders are perceived as the greater threat, with 39% of respondents identifying them as the most dangerous group.
- Insiders (employees, contractors, etc.) are also a significant threat, often due to negligence or accidental actions (47%), carelessness (23%), or disgruntlement (8%).
Security Spending and Effectiveness
- IT Security Budgets: Budgets continue to increase year-over-year, with an average of $11.0M.
- Investment Impact: Spending is focused on addressing cyber risks, but only 38% of organizations evaluate third-party security before engaging with them.
- Effectiveness of Security Technologies: Logging & Monitoring and Encryption are seen as highly effective in countering cybercrime, but only 26% use dedicated mobile security technologies.
Insider Threats
- Insider Threats: 47% of insider incidents are due to unintentional/accidental actions, highlighting the need for better education and awareness programs.
- Insider Handling: Most insider threats are handled internally, with only 14% reported to law enforcement.
- Insider Threat Funding: IT departments are the primary source of funding for insider threat initiatives, with limited top-down support.
Cybersecurity Practices
- Incident Response: Only 43% of organizations have formalized cyber response plans, and less than one-third update them frequently.
- Threat Intelligence: Organizations monitor a variety of threat sources, but less than one-third update their cyber response plans frequently.
- Measuring Effectiveness: Only 35% of organizations measure the effectiveness of their security programs annually or more often.
Key Insights
- Information Sharing: While organizations use multiple information sharing platforms, sharing remains a challenge.
- Threat Detection: Cyber threats are becoming more difficult to detect, with the average time to intrusion discovery increasing by over a month since 2015.
- Third-Party Risks: Most organizations do not conduct due diligence on third-party partners, leading to gaps in the digital business ecosystem.
- Legal and Compliance Actions: Only 21% of organizations involve legal or compliance actions for insider threats, with many handling them internally.
- Training and Awareness: Security awareness training is critical, as insiders often fall victim to phishing and careless behavior contributes to security breaches.
Conclusion
The survey highlights the complex and evolving nature of cybercrime, emphasizing the need for improved information sharing, better security training, and more robust internal and external cybersecurity strategies. While IT security budgets are increasing, monetary losses remain unchanged, indicating that current measures are not fully effective. Outsiders are seen as a greater threat, and targeted attacks are on the rise, requiring a multi-layered and proactive approach to cybersecurity.
试读结束,高清完整版pdf/doc/ppt,请点下载