Countless security reports are released every year, but among the most comprehensive is the annual Verizon Data Breach Investigations Report (2023 DBIR).
The 2023 DBIR was released earlier this week, and it based an analysis of 16,312 security incidents that occurred over the past year. Verizon's report gets data from incidents on its platform as well as from law enforcement and government agencies around the world. Across so many incidents there are a number of recurring patterns that can be discerned and trends that emerge across industries.
Among the primary findings in 2023 DBIR is that ransomware is not slowing down and remains a pervasive threat. According to the report the median loss from ransomware has doubled in the last two years to $26,000.
"One out of every four breaches has a ransomware component and it's really ubiquitous," David Hylender, DBIR co-author and senior manager for Threat Intelligence at Verizon said during a webinar discussing the 2023 DBIR. "It's in large organizations, small to medium businesses, very small organizations, it doesn't matter geographically, it doesn't really matter industry vertical wise, ransomware is a huge threat just across the board for any organization."
Why data breaches continue to occurAmong the most sobering aspects of the 2023 DBIR are the findings on why and how data breaches occur in the first place.
Hyledner noted that 74% of all breaches included the human element. That means people were involved either via error, privilege misuse or stolen credentials that can come via being the victim of social engineering.
Looking specifically at web applications and how they are breached, the 2023 DBIR found that 86% of breaches involved the use of stolen credentials. Only 10% of web application breaches involve the exploitation of an actual software vulnerability.
One of the best practices for any individual or organization to implement to help minimize web application based data breaches is the use of multi-factor authentication (MFA). With MFA instead of an attacker just needing a simple username and password to gain access, they also need a second factor, which could be a code sent via an SMS text message or generated by an MFA application, to gain access.
"Multi-factor authentication is certainly not going to fix all problems, but it would absolutely help," Hyledner said. "We know it's not easy to implement company-wide, but it is certainly necessary."
The key ways in for data breaches and to most any organization continue to be stolen creds fishing and exploitation of vulnerabilities.
So why are breaches continuing to occur and what's the primary motive? The answer is the same as it has been for at least the past decade that Verizon has produced the DBIR.
"The number one motive was financial gain and was the driver of 95% of the attacks," Hyledner said. "That's really nothing new, the money is where it's at, so it's always been and probably is where it always will be."
4 key takeaways from the Verizon Data Breach Investigations Report- Cost per ransomware incident doubled over the past two years, with ransomware accounting for one out of every four breaches.
- Pretexting (business email compromise) has more than doubled since last year.
- The human element is involved in 3 out of 4 breaches.
- Analysis of the Log4j incident illustrates the scale of the incident and the effectiveness of the coordinated response.
Comments