SUBSCRIBE

One in five Canuck firms report security violations

On the heels of the federal privacy commissionerโ€™s scathing report on corporate data security, a new national survey of Canadian IT security executives has found that the loss of confidential information and intellectual property has doubled over the past two years.

The survey, commissioned by CA Canada, indicated that more than 20 per cent of enterprises reported a loss of private data as a result of security attacks and breaches, up from 10 per cent two years ago. The proportion of companies reporting loss of intellectual property also rose, from eight per cent in 2006 to 16 per cent in 2008. The report polled 200 senior IT executives in a random sample of major Canadian enterprises.

More in ComputerWorld Canada

Many Canadian firms still not compliant with privacy laws, report shows

Renee LaLonde, regional vice-president at CA Canada, called the findings alarming; despite the fact that many high-profile data breaches have made headlines over the last several years. The most surprising finding, she said, was that one-third of survey respondents cited internal security breaches as the biggest threat โ€“ compared with less than five per cent in 2003. โ€œThreats and security breaches are evolving and itโ€™s to the point where internal breaches constitute the biggest concern,โ€ LaLonde said. โ€œFor the most part, enterprises have the right tools for virus attacks, network attacks, and keylogging, but the internal breaches need to be tackled.โ€

James Quin, senior security analyst at London, Ont.-based Info-Tech Research Group, said he was unsurprised at the survey findings and attributed the results to the increasing sophistication of the cyber criminal community. He also said that, unlike several years ago, companies have begun classifying internal security lapses as a data breach in itself.

โ€œVirus and malware are tailing off in severity, whereas the more targeted attacks are increasing in severity,โ€ he said. โ€œAs for internal security breaches, itโ€™s important to note that it isnโ€™t always a malicious action and in most cases is a result of human error. Previously, organizations would only look at classifying breaches as a result of a malicious attack, but now they are beginning to realize that when Bob from accounting loses a disk drive, itโ€™s a data breach that needs to be reported.โ€

More in ComputerWorld Canada

Privacy commissioner probes cloud computing

Tech Jobs

Categories