Download our ungated guide to high-quality penetration testing.
Every year, Verizon publishes a new version of its Data Breach Investigations Report (DBIR). For its tenth year running, this report provides analysis on trends surrounding hacking and other data breaches during the past year.Many executives and information security professionals try to base their threat management strategy on popular or media conceptions of what data security threats exist. But the annual DBIR is a realistic portrait of the industry, which provides experts with real analyses of real problems. Read on to learn more about the biggest threats this year's DBIR identified for financial and insurance companies, and what they mean for your business.The Most Common Types of AttackDBIR notes several common types of attack and/or data breach attemps against insurance industry. Three of these constitute 88% of all attacks
Breaches From WithinOne of the most prominent types of data breach the DBIR identified were what they described as "privilege misuse." Happily, privilege misuse breaches are easy to prevent.In a privilege misuse breach, employees of financial institutions and insurers used their access to computer systems to illicitly transfer money or steal customers' identifying information. Employees were more likely to steal personal information than money, perhaps because they knew transferring money would tip off their superiors.
So how can your company prevent these common types of data breaches? Verizon recommends the following tactics:
The 2017 DBIR report serves as a stepping-off point for greater understanding of the very real security threats that affect your business. When you familiarize yourself with it, you'll have a better understanding of the tactics hackers use, as well as which threats are most relevant to your company and its industry. Armed with the DBIR report, you're better able to approach others within your company about security liabilities, and you'll find it easier to gain support for real, impactful information security initiatives within your company.
Security news, tips, webinars, and more straight to your inbox.