Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Bigger isn't better when it comes to social engineering attacks

When it comes to social engineering attacks, larger companies attract more of them, and when they are victimized it costs more per incident, according to a survey sponsored by Check Point.

The result comes from "The Risk of Social Engineering on Information Security", a poll conducted by Dimensional Research, which surveyed 853 IT professionals from the U.S., U.K., Canada, Australia, New Zealand and Germany.

Of the entire group 322 say they were victims of social engineering attacks and they tracked how often they occurred. The companies with 5,000 or more employees were hit the most, with 48% saying they suffered 25 or more attacks. When size was not taken into consideration, just 32% reported 25 or more attacks.

MORE SECURITY: Cyber-attack: A big one is coming says US Cyber Command General

The cost of attacks were higher for larger companies, too, with 30% of those with 5,000 and more employees suffering $100,000 per incident. Just 19% of the entire survey group suffered losses that large.

A large segment of those polled, 43%, say they know their organizations were targeted by social engineering attacks. An almost equal number, 41%, say they aren't aware of such attacks, but can't say for sure they weren't victims. "This response implies a potential risk that businesses and IT teams are not dealing with," the survey says.

The companies polled also apparently fall down on training. New employees are most likely (60%) to fall for the attacks, yet only 26% of all those surveyed actively train employees in how to avoid social engineering. Written security policies for 40% include directions for avoiding social engineering.

After new employees, the most risky groups are contractors with 44%, executive assistants (38%), human resources (33%) and business leaders (32%). IT professionals were least likely to be victimized, with 77% either low risk or no risk.

Phishing emails (47%) and social networking sites (39%) were cited the most as the common source of social engineering threats.

When analyzed by market segment, the results show that energy and utility companies are hit most commonly (61%) and non-profits hit the least (24%).

Those respondents who were victims of the attacks say they think the top three motivations for the attacks are financial gain, access to proprietary information and competitive advantage.

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Check Point, LAN
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: anti-malware, cybercrime, legal, security, social engineering
Latest Blog Posts
Whitepapers
  • IDC Whitepaper: Generating Proven Business Value with EMC Next-Generation Backup and Recovery
    IDC interviewd ten companies that have deployed EMC backup and recovery solutions, including EMC Data Domain and EMC Avamar. Some of the customers also had EMC NetWorker. The purpose was to identify and quantify the resulting business value of each project, in order to calculate a cumulative return on investment. Read on.
    Learn more »
  • Managing Trust - Data protection and compliance for financial services
    If it’s becoming something of a cliché that the financial services industry is one of the world’s most heavily regulated, that’s largely because it’s true. Data retention and archiving, authentication and authorisation, data loss prevention and privacy regulations compete with demands for transparency and accountability, while market imperatives calling for multiple service channels delivered over a broad spread of technologies add to the pressure. Read on.
    Learn more »
  • Lost USB keys have 66% chance of malware
    Sophos studied 50 USB keys bought at RailCorp's 2011 Lost Property auction in Sydney. The study revealed that two-thirds were infected by malware, and quickly uncovered information about many of the former owners of the devices, their family, friends and colleagues. Disturbingly, none of the owners had used any sort of encryption to secure their files against unauthorised snoopers.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments