Skip the navigation

Security Statistics

July 9, 2001 12:00 PM ET

Computerworld - Security Statistics you'll find on this page:

Risks of Doing E-Business

Who does the best job of protecting data on computers?

Virus Alert

Top Security Job Markets





RISKS OF DOING E-BUSINESS

The threat from computer crimes and other online security breaches has barely slowed, never mind stopped, according to a recent survey of 538 security professionals in U.S. corporations that was conducted by the Computer Security Institute and the FBI's Computer Intrusion Squad.
Reported breaches in the past six months 85%
Reported financial losses in the past six months 64%
Could quantify financial losses 35%

TOTAL QUANTIFIABLE LOSSES

Year 2000 (265,589,940)

Year 2001 (projected) (377,828,700)



TYPES OF QUANIFIABLE LOSS

Theft of proprietary information $151.2M

Fraud $92.9M


ATTACKS REPORTED TO LAW ENFORCEMENT

Year 2000 25%

Year 2001 (projected) 36%


ATTACKS ON THE RISE
Source: Computer Security Institute/FBI Computer Intrusion Squad, Washington; survey of 538 IT security professionals


NET INTRUSIONS COST BILLIONS


Though the cost of intrusions is high, many companies still haven't devoted many resources to protecting themselves.

Total annual cost of online security breaches to corporations

$15B
Percentage of companies that have yet to implement adequate security

30%
Percentage of companies that spend 5% or less of their IT budget on security for their networks

50%
Source: DataMonitor PLC, New York

[BACK TO TOP]



Who does the best job of protecting data on computers?




Source: Information Technology Association of America, Arlington, Va.

Only 0.4% of a company's revenue, on average, is dedicated to information security in the U.S. By 2011, however, that figure will accelerate tenfold to 4% of revenue for U.S. companies, according to Gartner Inc.'s total cost of ownership model for information security.



U.S. INCIDENT RESPONSE SERVICES EXPENDITURES BY SERVICE ACTIVITY

Key findings include the fact that services will experience growth respective to the number of cyberattacks, and security breaches and individual service activity spending over time will increase or decrease at varying rates, according to incident severity and frequency.

1999 2000 2001 2002
Cyberforensics $14M $24M $36M $45M
Incident-response services $74M $94M $129M $152M
Total $88M $118M $165M $197M
Source: IDC,Framingham, Mass., 2001

[BACK TO TOP]




VIRUS ALERT


Downtime From Viruses
Judging by server downtime, which increased substantially from 1999, viruses are starting to take their toll on network performance:
1999 2000
Servers down for more than one hour 9% 64%
File problems from viruses 50% 66%
Companies with data loss 31% 40%
Source: ICSA Labs, Carlisle, Pa.; ICSA LABS 6th Annual Computer Virus Prevalence Survey 2000

Top 10 Viruses
The most active viruses in the past four weeks, according to MessageLabs Ltd., a U.K.-based virus-detection agency:
Number of Virus Detections in the Past Four Weeks

E-Mail Flu Season
The following graph plots the ratio of viruses to e-mail during the past 12 months. You can see that the ratio varies from one virus in every 1,400 e-mails in September 2000 to one in every 400 in May 2001.
Ratio of Viruses to E-mail From July '00 to June '01
Source: Messagelabs Ltd., Gloucester, U.K.

[BACK TO TOP]




TOP SECURITY JOB MARKETS

Where's the best pay for security pros?
Total compensation amounts for information security professionals, by region (2000).
REGION STATES COMPENSATION
South Atlantic D.C., Del., Fla., Ga., Md., N.C., S.C., Va., W.Va. $82,800
East South Central Ala., Miss., Ky., Tenn. $75,500
East North Central Ill., Ind., Mich., Ohio, Wis. $71,300
National average


$66,300
Pacific Alaska, Calif., Hawaii, Ore., Wash. $64,100
Mountain Ariz., Colo., Idaho, Mont., N.M., Nev., Utah, Wyo. $61,300
New England Conn., Mass., Maine, N.H., R.I., Vt. $58,900
West South Central Ark., La., Okla., Texas $58,400
Middle Atlantic N.J., N.Y., Pa. $58,400
West North Central Iowa, Kan., Minn., Mo., Neb., N.D., S.D. $55,400
Source: Computerworld's 2000 Annual Salary Survey, published Sept. 4
Cashing-in in consulting
Top-paying industries for information security professionals.

RANK

INDUSTRY

COMPENSATION
1 Business services, consulting $76,400
2 Business services, information technology $72,500
3 Government (state and federal) $63,000
National average $66,300
Security at a premium
The salary premiums (additional compensation above base salary) paid to IT professionals with security skills.
RANK TYPE OF TECHNOLOGY SKILL PREMIUM
1 Network development 20%
2 Security 18%
3 E-commerce application development 18%
4 Directories 17.5%
5 Internet application development 17%
6 Enterprise resource planning 17%
7 Data warehousing/data mining 16%
8 Web server administration 16%
9 Customer relationship management 15.5%
10 Online transaction processing 14.5%
Source: Computerworld's 2000 Annual Skills Survey, published Dec. 4

[BACK TO TOP]

Special Report

Security Risk and Reward
Stories in this report:

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs