Showing posts with label RSA. Show all posts
Showing posts with label RSA. Show all posts

Thursday, August 11, 2011

Survey: Median Cost of Cybercrime Up 56% in a Year

Cybercrime is expensive, Cost of Cybercrime Soaring!

EMC CFO David Goulden the other day said last month's breach of the system that stores secret codes for RSA's SecurID multifactor authentication tokens cost EMC $66.3 million in the second quarter.

That's well above average, according to a just-released survey by technology provider Hewlett-Packard, conducted by the Ponemon Institute. HP's second annual Cost of Cybercrime Study pegged the median annualized cost of cybercrime incurred by a benchmark sample of organizations at $5.9 million. The survey revealed a range of $1.5 million to $36.5 million, a 56 percent increase from the median cybercrime cost reported in HP's inaugural study published in July 2010.
The battle against cybercrime has gotten much harder in the past year. It takes organizations longer, and costs them more, to resolve cyber attacks.
But, as the study shows, taking the proper preventative measures is a money-saver. Organizations that had deployed security information and event management solutions realized a cost savings of nearly 25 percent over those who didn't.

Still, the survey suggests the battle against cybercrime has gotten much harder in the past year. It takes organizations longer, and costs them more, to resolve cyberattacks. In 2011, the survey shows, the average time to resolve a cyberattack took 18 days, with an average cost to participating organizations of nearly $416,000. That's a nearly 70 percent increase from the estimated $250,000 cost and a 14-day resolution period surmised from last year's study.
And, it's tougher to solve an insider crime than one perpectuated from the outside. A malicious insider attack can take more than 45 days to contain.
Of course, averages can't be applied to all situations. The RSA breached occurred nearly five months ago, and no one knows - or at least no one is saying - who perpetrated that costly cybercrime that not only diminished EMC's coffers but RSA's reputation as well.

Monday, July 11, 2011

Biometrics Seen as SecurID Alternative?

Exploring Multifactor Authentication

RSA customers who feel victimized by last March's breach of the security vendor's computers have viable options that include continued use of the SecurID authentication tokens, those offered by competitors, or something entirely different: biometrics.

In March, RSA revealed intruders broke into its computers, exposing secret codes for its two-factor authentication SecurID token. Since then, RSA has been working closely with its customers to assure the safety of the product.

The proper precautions RSA provides could satisfy many SecurID user but there is an another option of switching to a competitors' product. Still, at the end of the day, the use of these technologies maintains the status quo. They let you do the same-as-usual type of security. If attacked once, and hacked once, it can certainly be done again. Another approach, would be to implement an alternative factor, such as biometrics.

The concept behind multifactor authentication is that the user provides at least two different factors - something the user has, such as a token; something the user knows, such as a password; and something the user is, such as a fingerprint. In the case of tokens such as SecurID, the factors are what the user has and knows. But users jittery about the security of the has factor could substitute it with the is factor, such as an image of the eye's iris or the sound of a voice.

The enterprise security expert points out that many users own smartphones that, with the right, inexpensive software, can scan an iris or record a voice to produce biometrics that can be employed for authentication. It's not something that can be easily copied from a forensic perspective. Biometrics are a strong play, and they're gaining a lot more acceptance in the industry. What do you think?