Crowd-2018年网络内部安全威胁报告(英文)-2018.8-41页-7mb
报告摘要
Insider Threat Report Summary (2018)
Core Content
This report provides an in-depth analysis of insider threats, focusing on the current trends, challenges, and strategies used by IT and security professionals to manage and mitigate these risks. It highlights the growing concern around both malicious and accidental insider threats, and outlines the key technologies and practices being adopted to detect and respond to them.
Main Points
1. Insider Threats are a Major Concern
- 90% of organizations feel vulnerable to insider attacks.
- 53% of organizations reported insider attacks in the previous 12 months, with 27% noting increased frequency.
- Malicious insider attacks and accidental breaches are equally concerning, with 47% and 51% respectively.
2. Types of Insiders
- Regular employees (56%) and privileged IT users/admins (55%) are the biggest security risks.
- Contractors/service providers (42%) and executives/business users (25%) also pose significant risks.
- Customers/clients and none are less commonly cited as threats.
3. Most Vulnerable Data Types
- Confidential business information (57%) is the most vulnerable.
- Followed by privileged account information (52%) and sensitive personal information (49%).
- Intellectual property (32%) and operational/infrastructure data (27%) are also at risk.
4. IT Assets at Risk
- Databases (50%) and corporate file servers (46%) are the most targeted IT assets.
- Mobile devices (25%) are seen as a lesser target.
5. Enabling Risk Factors
- Too many users with excessive access privileges (37%) is the top risk factor.
- Increasing number of devices accessing sensitive data (36%) and increasing complexity of IT systems (35%) are also major concerns.
- Other factors include increasing amount of sensitive data (34%) and lack of employee training/awareness (31%).
6. Insider Threat Detection and Prevention
- Detection (64%) is the primary focus, followed by deterrence (58%) and analysis/post-breach forensics (49%).
- User behavior monitoring is widely used, with 94% of organizations deploying some method and 93% monitoring access to sensitive data.
- DLP (60%), encryption (60%), IAM (56%), and endpoint/mobility security (50%) are the most commonly used technologies.
7. Insider Threat Program Maturity
- 86% of organizations have or are building an insider threat program.
- 36% have a formal program, while 50% are in the process of developing one.
- 81% believe their insider threat prevention and detection methods are moderately to very effective.
8. Barriers to Insider Threat Management
- Lack of training and expertise (52%) is the biggest barrier.
- Other barriers include lack of suitable technology (43%), lack of collaboration (34%), and lack of budget (34%).
9. Speed of Detection and Mitigation
- 22% of organizations detect insider threats within minutes.
- 28% detect them within hours.
- 89% believe they can recover from an insider attack within a week.
- Only 2% believe they would never fully recover.
10. Budget Trends
- 49% of organizations expect an increase in their security budget.
- 43% expect it to remain flat.
- Over 8% of IT security budgets are allocated to insider threat prevention, detection, and mitigation.
11. Insider Threat Training and Policies
- 68% of organizations use policies and training.
- 63% conduct internal audits.
- 56% perform background checks.
- 82% have implemented insider security programs.
Key Technologies and Tools
- Intrusion Detection and Prevention (IDS/IPS) (63%)
- Log Management (62%)
- Security Information and Event Management (SIEM) (51%)
- Predictive analytics (40%)
- User and Entity Behavior Analytics (UEBA) (39%)
Summary of Actions
- Organizations are increasingly focused on detection and monitoring.
- User behavior analytics and monitoring tools are being widely adopted.
- There is a growing recognition of the need for formal insider threat programs and comprehensive training.
Sponsors
- CA Technologies
- Dashlane
- Haystax Technology
- HoloNet Security
- Interset
- Quest
- Raytheon
- RSA
- Securonix
- Veriato
This report underscores the critical need for proactive measures and continuous monitoring to address insider threats, which are increasingly seen as a significant risk to organizational security.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载