2017美国网络犯罪现状报告(英文版)_26页
报告摘要
2017 U.S. State of Cybercrime Summary
Core Content
The 2017 U.S. State of Cybercrime survey, conducted by CSOonline.com in partnership with Forcepoint, U.S. Secret Service, and CERT Division of Software Engineering Institute at Carnegie Mellon University, provides insights into the frequency, impact, and management of cybercrime in U.S. organizations. The survey included 510 executives from businesses, law enforcement, and government agencies, with a margin of error of ±4.3%.
Key Findings
Cybercrime Trends
- Security Events: The number of known security events has declined since 2015, but monetary losses have remained relatively constant.
- Threat Severity: Cybercrime impacts have become more severe, with phishing, ransomware, and financial fraud increasing significantly.
- Business Email Compromise (BEC): There has been a sharp rise in BEC incidents, indicating a growing threat from targeted attacks.
Cybersecurity Awareness and Training
- Insider Threats: Most insider security events are due to employee negligence or carelessness, highlighting the need for better security awareness training.
- Phishing Vulnerability: A large portion of insider attacks are attributed to phishing scams, reinforcing the importance of user education.
Cybersecurity Budgets and Spending
- IT Security Budgets: IT security budgets continue to increase year over year, but only 35% of organizations have a formalized plan for responding to cyber events.
- Investment Impact: Despite increased spending, the effectiveness of security programs is not consistently measured, with only one-third of organizations evaluating their programs annually or more often.
Board Involvement
- Board Engagement: The board of directors is becoming more involved in cybersecurity discussions, with CSOs/CISOs reporting to the board more frequently.
- Perception of Cyber Risks: While 6 in 10 boards still view cyber risks as an IT issue, full boards and risk committees are taking on increasing responsibility for cybersecurity management.
Threat Sources
- Outsiders as Major Threats: 39% of organizations perceive outsiders as the greater cyber threat, while insiders are also a concern.
- Unknown Sources: A significant number of incidents are attributed to unknown sources, indicating a lack of visibility and detection capabilities.
Incident Response and Legal Actions
- Internal Handling of Incidents: Most insider cybercrimes are handled internally, with legal action rarely taken.
- Legal and Compliance Initiatives: Some organizations use legal and compliance initiatives to manage insider threats, while IT departments often bear the responsibility for funding and implementing security measures.
Technology Effectiveness
- Top-Ranked Technologies: Logging & Monitoring, Encryption, and Endpoint Detection and Response (EDR) are seen as highly effective in addressing cybercrime concerns.
- Mobile Security: 26% of organizations use dedicated mobile security technologies to secure devices.
Cybersecurity Policies and Procedures
- Security Policies: Many organizations use security policies and procedures to deter, detect, and respond to cyber threats.
- Threat Monitoring: Companies monitor a variety of sources to stay updated on threats, but less than one-third update cyber response plans frequently.
Conclusion
Despite growing IT security budgets and increased board involvement, the U.S. organizations still face significant challenges in information sharing, threat detection, and measuring the effectiveness of their security programs. Phishing and ransomware remain prevalent, and insider threats are often linked to employee negligence and carelessness. Outsiders are perceived as a greater threat, and targeted attacks are on the rise. There is a need for improved security awareness training, better incident response planning, and more robust cybersecurity frameworks to address these ongoing challenges.
试读结束,高清完整版pdf/doc/ppt,请点下载