20170510-2017_Data_Breach_Investigations_Report_76页_2mb
报告摘要
2017 Data Breach Investigations Report Summary
Core Content
The 2017 Data Breach Investigations Report (DBIR) is the 10th edition, highlighting trends and patterns in data breaches and security incidents across various industries. The report emphasizes the importance of combining real-world data with organizational knowledge to enhance information security practices.
Main Findings
-
Breach Statistics:
- 75% of breaches were perpetrated by outsiders.
- 25% involved internal actors.
- 18% were conducted by state-affiliated actors.
- 3% featured multiple parties.
- 51% were financially motivated.
- 21% were related to espionage.
- 27% of breaches were discovered by third parties.
-
Tactics Used:
- 62% of breaches featured hacking.
- 51% of breaches included malware.
- 81% of hacking-related breaches used stolen or weak passwords.
- 43% were social attacks.
- 14% were due to errors or privilege misuse.
- 8% involved physical actions.
-
Victims:
- 24% of breaches affected financial organizations.
- 15% involved healthcare organizations.
- 12% were public sector entities.
- 15% were in retail and accommodation combined.
-
Breach Discovery:
- 2016 saw a significant drop in breaches discovered through law enforcement due to the Dridex botnet takedown.
- Employee notifications were the most common internal discovery method.
- Third-party disclosure increased due to more breaches being reported by customers or threat actors.
-
Breach Timeline:
- 98% of breaches were detected within minutes or less.
- Breaches taking months to discover were likely related to Point of Sale Intrusions, Privilege Misuse, Everything Else, or Cyber-Espionage.
Key Trends
-
Shift in Threat Actor Categories:
- A downtick in breaches involving external actors led to an increase in internal actors, but the absolute number of internal breaches remained relatively constant.
- The convergence in threat actor categories in 2016 was due to a decrease in botnet and POS-related breaches.
-
Threat Motives:
- Financial and espionage motives combined for 93% of breaches.
- FIG (Fun, Ideology, Grudge) motives and activist groups were a smaller but growing portion.
- Ransomware was used by organized criminal groups, but not always resulting in confirmed data disclosure.
-
Data Types Compromised:
- Personal data and credentials were the most frequently compromised data types, often in the billions.
- These data types are frequently stored in bulk and are highly valuable to cybercriminals.
Industry-Specific Analysis
The report includes detailed industry-specific findings, focusing on the most relevant sectors:
-
Accommodation and Food Services:
- 96% of breaches were external.
- Top patterns: Point of Sale Intrusions, Everything Else, and Privilege Misuse.
- 99% of breaches were financially motivated.
-
Education:
- 455 incidents and 73 breaches reported.
- Breach patterns: Miscellaneous Errors, Point of Sale Intrusions, and Privilege Misuse.
-
Finance:
- 998 incidents and 471 breaches reported.
- Breach patterns: Miscellaneous Errors, Point of Sale Intrusions, and Privilege Misuse.
-
Healthcare:
- 458 incidents and 296 breaches reported.
- Breach patterns: Miscellaneous Errors, Privilege Misuse, and Cyber-Espionage.
-
Information:
- 717 incidents and 113 breaches reported.
- Breach patterns: Miscellaneous Errors, Privilege Misuse, and Cyber-Espionage.
- The Information industry was the most affected by data breaches involving personal data and credentials.
-
Retail:
- 326 incidents and 93 breaches reported.
- Breach patterns: Miscellaneous Errors, Point of Sale Intrusions, and Privilege Misuse.
-
Other Industries:
- The report also touches on industries such as Manufacturing, Public Administration, and Utilities, highlighting their unique breach patterns and vulnerabilities.
Incident Classification Patterns
- The report introduces nine incident classification patterns, which help in understanding the nature of breaches and how they can be mitigated.
- These patterns are mapped against industry-specific data to provide actionable insights.
Methodology and Data Sources
- The report uses real-world data breaches and security incidents, either investigated by Verizon or provided by data contributors.
- Data is analyzed and normalized to ensure relevance and comparability.
- The VERIS Community Database and other resources are provided for deeper analysis.
Conclusion
The DBIR serves as a valuable resource for security professionals, offering a comprehensive view of the current threat landscape and helping organizations understand the tactics, motives, and patterns behind data breaches. It encourages a proactive approach to information security, emphasizing the importance of continuous monitoring and improvement.
试读结束,高清完整版pdf/doc/ppt,请点下载