DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Verizon releases it 2013 Data Breach Investigations Report

Posted on April 23, 2013 by Dissent

Verizon has released  the Verizon Data Breach Investigations Report (DBIR).  You can download the Executive Summary here and the full report here.

The DBIR analyzes data from 19 organizations — covering more than 47,000 reported security incidents and 621 confirmed data breaches from the past year. Because VZ has the cooperation of so many organizations, it provides a unique opportunity to analyze data. Although we do not know what percent of the incidents in their analyses overlap with the more than 1200 incidents compiled by DataLossDB.org for 2012, I find it fascinating to look at where the two organizations’ reports agree, and they do agree on numerous key findings – including the fact that most incidents involve external agents, not insiders, that over half of incidents involve hacking, and that breaches from the healthcare sector, while garnering much media attention, account for only about 1% of breaches. Their report is also consistent with RBS/OSF’s report indicating that most incidents do not involve particularly sophisticated attacks and most could be easily prevented. Verizon’s report, however, gives us a first harder look at state-sponsored attacks and other factors that RBS/OSF’s report does not address, such as their finding that approximately two-thirds of confirmed breaches involved data at rest or data being processed – and not data in transit. Worryingly, the majority of breaches take months to detect (and the problem got worse in 2013 compared to their 2012 data), and most breaches are not detected by the entity’s IT personnel.

So… how many times do we have to tell people to purge data that’s no longer really needed and to monitor to ensure that if you have policies in place to protect data on mobile devices, those policies are being implemented? DBIR notes – and most of us would agree, I think – that there is no one-size fits all in terms of protecting assets. Knowing the risks for your industry and type of data is critical.

Read their report for more details, and kudos to them for another fine report.

Category: Commentaries and Analyses

Post navigation

← What healthcare CIOs need to know from Verizon data breach report
UK: Personal data breach by police to G4S →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.