ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

FBI: Computer crime costs US firms $67bn

Joris Evers CNET News.com

Published: 20 Jan 2006 10:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Dealing with viruses, spyware, PC theft and other computer-related crimes costs US businesses a staggering $67.2bn (£38.2bn) a year, according to the FBI.

The FBI calculated the price tag by extrapolating results from a survey of 2,066 organisations. The survey, released on Thursday, found that 1,324 respondents, or 64 percent, suffered a financial loss from computer security incidents over a 12-month period.

The average cost per company was more than $24,000, with the total cost reaching $32m for those surveyed.

Often survey results can be skewed, because poll respondents are more likely to answer when they have experienced a problem. So, when extrapolating the survey results to estimate the national cost, the FBI reduced the estimated number of affected organisations from 64 percent to a more conservative 20 percent.

"This would be 2.8 million US organisations experiencing at least one computer security incident," according to the 2005 FBI Computer Crime Survey. "With each of these 2.8 million organisations incurring a $24,000 average loss, this would total $67.2bn per year."

By comparison, telecommunication fraud losses are about only $1bn a year, according to the US Secret Service. Also, the overall cost to Americans of identity fraud reached $52.6bn in 2004, according to Javelin Strategy & Research.

Other surveys have attempted to put a dollar amount on cybersecurity damages in the past, but the FBI believes its estimate is the most accurate because of the large number of respondents, said Bruce Verduyn, the special agent who managed the survey project.

"The data set is three or four times larger than in past surveys," he said. "It is obviously a staggering number, but that is the reality of what we see."

Responding to worms, viruses and Trojan horses was most costly, followed by computer theft, financial fraud and network intrusion, according to the survey. Respondents spent nearly $12m to deal with virus-type incidents, $3.2m on theft, $2.8m on financial fraud and $2.7m on network intrusions.

These figures do not include much of the staff, technology, time and software employed to prevent security incidents, Verduyn said. Also, losses to individuals who are victims of computer crime or victims in other countries are not included, he said.

The FBI's next fiscal year, for which budgets must be reviewed and approved, begins 1 October. Protecting the US against high technology crimes is third on the agency's list of priorities.

Defences in place
Survey respondents use a variety of security products for protection. Antivirus software is almost universally used, with 98.2 percent of respondents stating they use it. Firewalls follow in second place, with 90.7 percent, and anti-spyware and anti-spam software are each used by about three-quarters of respondents, according to the survey.

The results mean that close to one in 10 organisations does not have a hardware or software firewall. Or perhaps they don't know they have one — the Windows Firewall in Windows XP, for example. "Some are very small businesses that should have that technology, but they don't," Verduyn explained.

Biometrics and smart cards — both relatively new security technologies — were used only by 4 percent and 7 percent of survey respondents, respectively. Intrusion prevention or detection systems were used by 23 percent and VPNs by 46 percent.

Organisations were attacked despite use of security products, with nine out of 10 respondents saying they experienced a security incident. In fact, the most common attacks aligned with the most commonly used defences. Computer viruses, worms or Trojan horses plagued 84 percent of respondents, 80 percent reported spyware trouble, and 32.9 percent said attackers were probing their systems using network port scans.

Not all threats came from outside the organisation. More than 44 percent of the survey respondents reported intrusions from within the company. "Companies may be unaware of the internal potential for computer security incidents," Verduyn said. He recommends applying policies and procedures to thwart attacks from the inside.

The FBI surveyed companies in Iowa, Nebraska, New York and Texas. Companies older than three years, with more than five employees and with more than $1m in revenue were asked to participate. Survey participants were asked to provide their responses by the end of July 2005, with their answers covering the previous 12-month period.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
119 out of 189 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Service Control Manager

Building and developing a brand new team covering service introduction, change management, problem and incident management, you will champion the ...

Information Security & Compliance Officer : London : Contract : ASAP

Main responsibilities will involve: Promoting the Information Security Policy and providing guidance where necessary Managing security incidents as ...

Helpdesk Support Analyst (1st/2nd Line Support)

Helpdesk Support Analyst (1st/2nd Line Support) to help resolve problems and incidents within our IT Department Helpdesk Desk Team providing a high ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment