|
Nearly 40 Percent of Large Organizations Don't Monitor Databases for Suspicious Activity – Or Don’t Know If They Do
Customer and employee data remain at greatest risk; IT is mobilizing against this threat, but competing corporate priorities fuel epidemic of data theft and misuse
GARTNER IT SECURITY SUMMIT, WASHINGTON, DC – June 4, 2007 – Application Security, Inc., today announced the results of a Ponemon Institute survey (click here to download) that underscores the serious challenges large organizations face in securing sensitive data. With more than 150 million data records exposed in just the past two years, the survey also highlights an organizational disconnect between the realization of the threat and the urgency in addressing it.
Conducted by one of the world’s foremost authorities on data security and privacy, the Ponemon Institute surveyed 649 respondents in corporate information technology (IT) departments worldwide. Respondents averaged more than 7 years of experience in the information security field; more than 60 percent work within corporate CIO or CTO departments.
In what’s an increasingly precarious balancing act, organizations are wrestling with how to protect data from misuse by external and internal forces, while expanding access to the same data to drive business initiatives. Highlighting these challenges, the Ponemon Institute/AppSecInc survey reveals that: 0
- Forty percent said their organizations don’t monitor their databases for suspicious activity, or don’t know if such monitoring occurs. Notably, more than half of these organizations have 500 or more databases – and the number of databases is growing.
- “Trusted” insiders’ ability to compromise critical data was cited as the most serious concern – with 57 percent perceiving inadequate protection against malicious insiders and 55 percent for “data loss” by internal entities.
- Seventy-eight percent believe that databases are either critical or important to their business. Customer data represents the most common data type contained within these databases.
- Customer/consumer and employee data ranks 3rd and 4th respectively in regard to organizations’ prioritization of what must be protected.
“Data can be monetized quickly and the bad guys know it,” said Larry Ponemon, chairman and founder of the Ponemon Institute. “Organizations that fail to protect their data effectively are proving easy targets – often left to contend with considerable damage to their reputations and financial results.”
“Unless organizations directly protect their databases, everything else they’re doing for data security is on shaky ground,” said Toby Weiss, president and CEO of AppSecInc. “As States and the Federal government grapple with how to compel organizations to protect consumer privacy, leading organizations are looking inward to protect data where it lives. Responsible organizations are increasingly seeking to enhance security, mitigate risk and address key compliance concerns as part of a comprehensive approach to addressing data governance within their existing IT infrastructure.”
NOTE TO EDITORS: Application Security, Inc. and Ponemon executives are available to discuss the data and the market trends in play.
About Application Security, Inc.
Application Security, Inc. is the leading global provider of database security solutions for the enterprise. Application Security, Inc.’s products – the industry’s only complete database security solution – proactively secure database applications across databases around the world. Our security experts, combined with our strong support team, deliver up-to-date database protection that minimizes risk and allows organizations to confidently connect with customers, partners, and suppliers.
Please contact us at 1-866-927-7732 to learn more, or visit us on the Web at www.appsecinc.com.
###
Contact:
Christine Meyers
Application Security, Inc.
cmeyers@appsecinc.com
781-687-1034
Bryan Grillo
CHEN PR, Inc.
bgrillo@chenpr.com
781-672-3129
|