07 Jul 2008
Data leaks are catching up with viruses as the worst IT headache for companies in the US, UK, Germany and Japan, new research claimed today.
A Trend Micro poll of 1,600 corporate end users revealed the loss of proprietary company data and information as the second most serious threat at work after viruses.
While six per cent of end users admitted to having leaked company information, 16 per cent believe that other employees caused data leaks.
End users in the US, UK and Germany are more likely to admit to leaking company data, either intentionally or accidentally, than end users in Japan.
Respondents in the US perceive themselves as slightly savvier when it comes to confidentiality.
Some 74 per cent of US respondents said that they know what type of company data is confidential and proprietary, compared to 67 per cent in the UK, 68 per cent in Germany and only 40 per cent in Japan.
On the other hand, end users at large companies in Japan are more aware of what type of company data is confidential compared to end users at smaller organisations.
Mobile users are also more confident. In the US, for example, 79 per cent of mobile end users said that they know what is classified information, compared to 69 per cent of desktop computer users.
The study also found that 46 per cent of companies do not currently have a policy to prevent data leaks.
Companies in Germany and Japan are more likely than their UK counterparts to implement data leak prevention policies.
In all countries surveyed, large organisations are more likely to have preventative policies in place than small companies.
Among end users whose company currently has a policy to prevent data leakage, 70 per cent of US end users have received training compared to 57 per cent in the UK.
In all countries surveyed, installation and use of security software are the most common actions taken to combat data leakage.
"The survey highlights some key challenges, including user education, inadequate security policies and the broad brush access rights typical in many enterprises today," said Rik Ferguson, solutions architect at Trend Micro.
"All too often employees simply do not know which information is confidential, within the remit of public domain or of restricted distribution.
"Even if the regulations were clear, employees are often unaware of the corporate policy around such information."
Ferguson added that the majority of data leaks happen from within, either by accident or design, by valid users who have access to the data within a corporate network.
"This can trigger fines, litigation, brand damage and bad press, so it is no surprise that data leaks are becoming such an important issue for companies."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client a leading company in the education and qualification...
Incident Manager - Investment banking Fantastic opportunity...
Senior Product Manager - Broadband Zen Internet...
Senior C# Developer - Reigate: £60,000 to £80,000 + benefits...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
data leaks
This exposure has been growing over the last 10 years and most organisations fail to recognise that the main risk comes from the human interface with data and data storage. Implementing 'off the shelf' software and hardware remedies only solves part of the problem, it is far better to undertake a true risk assessment before mitigation and not waste your time, effort and MONEY!
Posted by: Ernie Pallett 02 Dec 2008
False Positive Rate
This article points out the need for a DLP system, however this system MUST have a "false positive rate" of virtual zero; or you would have wasted your company's time and money while putting them at risk of a breach.
Posted by: Tony D. 10 Jul 2008