Midsize Companies Are Becoming Hacker Targets

Midsize companies reported an increase in cyber-threats this past year but are still freezing their IT security budgets, according to a report released by McAfee.

According to the company’s “The Security Paradox” study, more than half of surveyed midsize companies have seen more security incidents in the past year, from mid-2009 to mid-2010. Of those who’d been hacked, 16 percent reported it took them more than a week to recover from the damage.

No Hiding In The Cloud

About one-third of the organisations were attacked repeatedly and more than half of those incidents were serious enough to take up to five hours to investigate and fix, the survey said.

“Keeping up with security threats is a significant distraction from running a midsize business,” said Alex Thurber, senior vice president of worldwide channel operations for McAfee, in a statement.

In the United States, the average number of cyber-attacks against midsize organisations more than quadrupled from mid-2008 to mid-2009, McAfee said.

In Europe, the results are similar and even going to the cloud may not remove the security risk, according to the study. A number of respondents, mainly in Europe, Middle East and Africa, saw up to 10 cloud computing incidents in the past year, and “we would expect to see a growth in incidents in this area,” the researchers wrote.

Threats are up and growing in severity, but IT security budgets are way down. This is a problem, as more than half, or 58 percent, of organisations spent less than three hours per week working on, evaluating and researching IT security options, according to the survey results. It’s better than last year’s 65 percent, but it’s still a distressing number considering the escalation.

“While the threats have grown, these companies’ resources to fight them have declined, creating a paradox,” Thurber said.

Taking full advantage of this paradox are cyber-criminals and disgruntled employees, who attack networks and systems, and steal sensitive information, McAfee said.

Worldwide, three-quarters of the companies reported either flat or declining security spending, said Darrell Rodenbaugh, senior vice president of global midmarket for McAfee. The country-breakdowns showed similar patterns to the United States and Canada, with only a quarter of the organisations reporting increased security spending, according to Rodenbaugh.

Over half of the surveyed organisations also admitted to knowing less than three-quarters of the regulatory and compliance requirements pertinent to their organisation or industry, said McAfee.

One possible reason for the paradox may be because IT managers still think hackers prefer to target larger enterprises. Last year, nearly half of the respondents said companies with more than 500 employees are the most vulnerable. This year’s report indicates managers are beginning to revisit that assumption, with only 21 percent thinking so.

One in five surveyed organisations had a security incident that directly affected revenue. On average, companies lost $41,000. The number jumped dramatically in China, with more than one-third of the companies reporting an average loss of $85,000.

According to the survey, the most common result of a security attack was data loss, usually private information of customers, employees and partners. Nearly half of all reported intellectual property losses were from companies based in Europe, Middle East and Africa.

About 75 percent said a serious data breach could put them out of business, according to the survey. About, 40 percent of the organisations reported a data breach, a 13 percent increase from last year.

More than 83 percent of the respondents said they were ‘concerned’ or ‘very concerned’ about being the target of an intentional and malicious attack. In contrast, 88 percent worried about non-malicious or inadvertent security incidents.

Non-malicious or inadvertent incidents include accidentally losing a laptop with sensitive corporate data or sending an email attachment to the wrong person, according to the survey methodology. The most prevalent malicious attack was malware, followed by Website threats, including phishing, hacking and software exploits.

The report, in its third year, examined midsize companies’ attitudes toward security and compares them with current security trends. More than 1,100 IT managers were surveyed across companies with between 51 to 1,000 employees. The worldwide survey included companies in Australia, Brazil, Canada, China, France, Germany, India, Japan, Mexico, Netherlands, Spain, the United Kingdom, and the United States.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Intel To Invest More Than $28 Billion In Ohio Chip Factories – Report

Troubled chip giant Intel will invest more than $28 billion to construct two new chip…

2 days ago

Apple Returns To Top 5 Smartphone Ranks In China, Amid Tim Cook Visit

In Q3 Apple rejoins ranks of top five smartphone makers in China, as government welcomes…

2 days ago

Apple Cuts Orders iPhone 16, Says Analyst

Industry supply chain analyst says Apple cut orders for the iPhone 16 for Q4 2024…

2 days ago

LinkedIn Fined €310m By Irish Data Protection Commission

Heavy fine for LinkedIn, after Irish data protection watchdog cites GDPR violations with people's personal…

3 days ago

CMA Begins Probe Into Alphabet Partnership With Anthropic

UK competition regulator begins phase one investigation into Alphabet's partnership with AI startup Anthropic

3 days ago