跳到主体内容

The Threat Within: 3 Out Of 4 Companies Affected By Internal Information Security Incidents

2015年11月16日

According to a joint study conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents, and the largest single cause of confidential data losses are employees (42%)

According to a joint study1 conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents, and the largest single cause of confidential data losses are employees (42%). The average damage caused by leaks in small and medium-sized businesses amounted to $80,000.

As a company’s IT infrastructure expands, so does the threat landscape. New components add new vulnerabilities. The situation is aggravated by the fact that not all employees – especially those with no specialist IT knowledge – can keep pace with a rapidly changing IT environment. As a result, the company is exposed to not only external threats but also internal threats that come from employees.

This was confirmed by a recent survey of businesses that found 21% of companies affected by internal threats lost valuable data that subsequently had an effect on their business.

It is worth mentioning that the study reported cases of accidental data leaks (28%) and intentional leaks of valuable company data (14%).

Average financial losses incurred by small and medium businesses as a result of data leaks amounted to $80,000 – $33,000 from accidental leaks and $47,000 from intentional leaks. The figures for enterprises were $1.29 million, $544,000 and $748,000 respectively.

In addition to data leaks, internal threats include the loss and theft of employees’ mobile devices. 19% of respondents confirmed that they lost a mobile device containing corporate data at least once a year.

Another important factor is that of staff fraud. 15% of those surveyed encountered situations when company resources, including finances, were used by employees for their own purposes. The percentage may be low, but the losses caused by these incidents exceeded the damage caused by confidential data leaks for enterprises. Small and medium businesses lose up to $40,000 on average from fraudulent activity by employees, while the figure for enterprises exceeds $1.3 million.

"It's no secret that a security solution alone is not enough to protect a company’s data. And the results of this study confirm that,” comments Konstantin Voronkov, Head of Endpoint Product Management, Kaspersky Lab. “What’s required is an integrated multi-level approach powered by security intelligence and other supplementary measures. These measures may include the use of specialized solutions and the introduction of security policies, such as restricting access rights."

Kaspersky Lab recommends that the issue of comprehensive security should not be neglected, as reliable multi-level protection can prevent a company from incurring additional costs not only from external but also internal security incidents. In particular, technology that protects against DDoS and phishing attacks, encryption, protection of mobile devices, virtual infrastructures and financial transactions all provide reliable targeted security for the individual nodes of a corporate IT infrastructure, and datacenters. And the implementation of various security policies together with specialist services such as incident investigations, independent evaluations of a company’s IT infrastructure and staff training will minimize the risk of threats.


1The information security of businesses - Kaspersky Lab and B2B International, 2015. Over 5,500 IT specialists were surveyed from more than 25 countries around the world.

The Threat Within: 3 Out Of 4 Companies Affected By Internal Information Security Incidents

According to a joint study conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents, and the largest single cause of confidential data losses are employees (42%)
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基以“网络免疫”理念引领行业创新,致力于保护消费者、企业、关键基础设施和政府机构免受网络威胁,迄今为止已保护超过 10 亿台设备。

卡巴斯基秉持“Cybersecurity True to Business”的理念,专注于交付明确成果、保障营收、减轻团队负担并避免业务中断。卡巴斯基深厚的威胁情报和安全专业知识不断转化为创新解决方案和服务,服务于从小型企业到大型集团等各种规模的组织,将成熟的 AI 驱动型保护技术与简洁高效的管理和专家支持相结合。

卡巴斯基的解决方案经独立测试认可,深受全球数百万个人用户及近 20 万家企业的信赖,帮助客户更早识别威胁、更快速响应,以更强的信心与自由空间开展业务,保护对客户至关重要的资产。了解更多详情,请访问 www.kaspersky.com.cn

相关文章 企业新闻