CSO - Do you think data breaches are up or down in 2011 compared to 2007 or 2008? The official answer may surprise you. According to DatalossDB and the 2011 Data Breach Investigations Report [PDF link] by Verizon, the number of records compromised per year has been decreasing since its 2008 peak. But these reports are missing something very important. It all comes down to what is reported. Last year I met with more than 450 CIOs and CSOs, and almost all of them said that incidents are way up. New breaches are constantly making headlines, so why is there a discrepancy between our perception and what these reports are finding?
Many industry reports focus on the never-ending stream of leaked or stolen personally identifiable information (PII). Most laws and industry standards, such as PCI DSS, also concentrate on PII. But there is something that could be more dangerous to lose than PII and that isn't getting enough attention in data breach reports--intellectual property (IP).
As records show, stealing PII (credit cards, social security numbers, and so on) used to be big business for cybercriminals. Then it started to get a bit harder for hackers to get PII because overall awareness increased as more regulations were passed and organizations started to invest in information security solutions. Verizon's Data Breach Investigations Report states, "Our leading hypothesis is that the successful identification, prosecution, and incarceration of the perpetrators of many of the largest breaches in recent history is having a positive effect." Researchers also suggested that there are fewer hackers and the threat they pose is losing prominence. I believe protection enforcement is a factor in the reduction of PII theft, but I don't believe there are fewer bad guys out there. In fact, quite the opposite: The threat has never been greater than it is now.
The next big thing is stealing IP, which includes product designs, secret formulas, and other trade knowledge. It's what organized cybercrime, state governments and hackers are all going after. Why? Mostly because of the value of the data. One stolen manufacturing process can be worth millions in saved development costs or billions in market share.
Not protecting IP is a huge mistake for companies and countries alike. Intellectual property is what makes modern nations competitive in the world economy. It fuels innovation and development, and it keeps you ahead of the competition.
What do CSOs think? More than 70 percent of the CIOs and CSOs I spoke with last year said their IP is under attack. Yet only 30 percent of them have data-loss prevention (DLP) tools in place. And most of them do not have software to protect their data in the cloud or on mobile devices, which are the two big new blind spots that they need to worry about.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- How Blade Centers Impact Data Center Management and Agility
- This paper examines enterprise adoption of blade servers in the US, UK and China; the benefits of blade server use; and the connection...
- Nemertes Research PilotHouse Awards: Server for Virtualization
- The Nemertes Research PilotHouse Awards provide insight on the performance of technology vendors, according to feedback from IT decision makers who use their...
- Gartner Magic Quadrant for Blade Servers
- The market for blade servers is becoming ever more complex and diverse due to the convergence of related modular form factors, a fast-growing...
- Real Fabrics for a Virtual World
- Many factors influence what "ideal" approach organizations should take when planning to implement a fabric-based infrastructure policy. This presentation charts the likely evolution...
- Picking the Right Server solution to solve your Space, Power and Cooling problems
- The type of server you install in a data center can have a big impact -- positive or negative -- on the space,... All Cybercrime and Hacking White Papers
- Today's NAS: A Solution Beyond Old Limits
- Date: Tuesday, July 17, 2012 2:00 PM EDT
Traditional NAS systems don't scale beyond fixed limits. Proliferation of NAS systems leads to management... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
- Oracle Database Appliance Best Practices
- Business users increasingly demand 24x7 availability of their data while IT departments face the challenge of ensuring maximum availability while operating with limited...
- Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - BMC Control-M - Single Point of Control Demo
- With BMC Control-M, you schedule and manage everything - down to the very last platform and application - from one simple interface. It's... All Cybercrime and Hacking Webcasts