ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Access hacks hit UK Plc

Matt Loney ZDNet.co.uk

Published: 11 Mar 2004 10:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

One in five of the UK's larger companies suffered security breaches of their IT systems in the past year because of weaknesses in their approach to identity management, according to the preliminary findings of a survey to be published next month.

For one in ten, the breach was significant, and half of all those affected said the breach was more serious than virus incidents, found the Information Security Breaches Survey, conducted by a consortium led by PricewaterhouseCoopers for the DTI, and covering more than 1,000 UK companies.

Unauthorised access to IT systems caused significant business disruption, lasting more than a month in 15 percent of the cases, and took on average 10 to 20 days to investigate. These breaches also incurred the biggest direct cash cost of any security incident -- more than £100,000 in legal fees, investigation costs and fines in 15 percent of cases.

Companies' access controls are failing to prevent these incidents, the survey found. "The first root cause is that often the sheer number of users and systems puts user administration processes under strain," write the authors. To counter this, companies are increasingly automating their processes for granting access to systems. Sixteen percent of all companies and 31 percent of large ones do this. Automating user provisioning appears to work. None of the respondents that had done this had suffered financial frauds or systems penetration from outside in the past year.

The second root cause is over-reliance on passwords to check users' identity. Some 87 percent of all companies rely solely on user IDs and passwords, and 7 percent have no controls at all. Businesses that adopt single sign-on without strong authentication had a higher-than-average incidence of unauthorised access.

Tokens, smart cards and biometrics are only used in 6 percent of companies. This rises to roughly a quarter for large businesses. The latter seem to be reaping the benefit with just 3 percent suffering from an unauthorised access breach, compared to 20 percent for those that haven't adopted these levels of authentication.

The report is sponsored by Entrust, which produces identity and access-management solutions that include tokens and smart cards.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 144 people found this useful


Full Talkback thread

0 comments

Related Jobs

Test Analyst, Experienced Agile, Luton - 36,000+

Manage and perform testing, recording results and where appropriate performing initial root cause investigation. Defect tracking and management, ...

Lead Technician- Windows (MCP, MCSE, MCSA)

Lead Technicians have an extensive knowledge of Windows hosting technologies and assist in; - Troubleshooting, maintaining, scaling ...

Security/Quality Analyst-00055189

Ensure that security incidents raised against Accenture are investigated promptly and reported back to the management team where required. Experience ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment