Study: More Than 84 Percent of North American Enterprises Suffered Security Breach in the Last Year

July 6, 2006
A new security study of 642 large North American organizations shows that more than 84 percent suffered some type of security incident over the past 12 months and that there was a 17 percent increase in incidents over the past 3 years.

The study, sponsored by CA, an information technology (IT) management software company, found that as a result of security breaches, 54 percent of organizations reported lost workforce productivity; 25 percent reported public embarrassment, loss of trust/confidence and damage to reputation; and 20 percent reported losses in revenue, customers or other tangible assets. Of the organizations that experienced a security breach, 38 percent suffered an internal breach of security.

In addition, the findings indicate that security isn't being taken seriously enough at all levels of an organization, especially in the financial service industry. Nearly 40 percent of respondents indicated that their organizations don't take IT security risk management seriously at all levels, while 37 percent believe their organization's security spending is too low. Only 1 percent believe it is too high.

Despite these findings, the survey revealed that organizations are taking steps to improve security. The three most important cited security steps were documenting security policies (88 percent), creating security education policies for employees (83 percent) and creating a chief information security officer position (68 percent) within the organization.

The survey also found that a lack of centralized security administration is affecting employee productivity. Only 6 percent of the organizations were able to provide new employees or contractors with access to all the applications or systems they require on their first day of work.

"These survey results demonstrate that even though organizations are investing in security technologies, they still aren't achieving the results they seek," said Toby Weiss, senior vice president and general manager of CA's Security Management Business Unit. "Clearly, more work needs to be done in terms of both improved security management itself and better education of business users about the importance of IT security best practices."

The survey also found that organizations are turning towards identity and access management (IAM) technology to improve security, enable regulatory compliance and reduce costs. More than 75 percent of the organizations surveyed have implemented some form of IAM functionality and are continuing with IAM investments, with an additional 18 percent planning to begin rolling out an IAM solution or extend their IAM deployments over the next 12-18 months.

Sponsored Recommendations

ISO 45001: Occupational Health and Safety Management Systems (OHSMS)

March 28, 2024
ISO 45001 certification – reduce your organizational risk and promote occupational health and safety (OHS) by working with SGS to achieve certification or migrate to the new standard...

Want to Verify your GHG Emissions Inventory?

March 28, 2024
With the increased focus on climate change, measuring your organization’s carbon footprint is an important first action step. Our Green House Gas (GHG) verification services provide...

Download Free ESG White Paper

March 28, 2024
The Rise and Challenges of ESG – Your Journey to Enhanced Sustainability, Brand and Investor Potential

Free Webinar: Mining & ESG: The Sustainability Mandate

March 28, 2024
Participants in this webinar will understand the business drivers and challenges of ESG and sustainability performance, the 5 steps of the ESG and sustainability cycle, and prioritized...

Voice your opinion!

To join the conversation, and become an exclusive member of EHS Today, create an account today!