인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Cisco Releases '2016 Annual Security Report'

Google 우선 소스Published2016.01.26 22:25
Only 45% of companies expressed confidence in their security.

According to the 'Cisco 2016 Annual Security Report,' which analyzes global cybersecurity trends and issues, cyber attacks are becoming increasingly sophisticated and taking the form of persistent attacks using various methods, while only 45% of companies expressed confidence in their security systems.

In this report, Cisco highlighted the challenges facing businesses due to rapidly evolving cyberattacks and the lack of adequate responses. It emphasized that strengthening security against cyberattacks is essential in an era of the Internet of Things and the digitalization of various industries, and that this requires increased collaboration and investment in technology, infrastructure, processes, and personnel. Notably, 92% of corporate executives agreed that regulators and investors expect companies to possess high security capabilities to prepare for cyberattacks.
(Photo: Cisco website)

Malicious browser extensions, often overlooked by corporate security departments, have been found to affect over 85% of companies as a potential cause of serious data breaches. It was warned that aging corporate infrastructure would become a target for hackers, putting companies at risk, and outdated corporate structures and practices were also identified as factors hindering the ability to detect, mitigate, and recover from cyber attacks. In the case of ransomware attacks, which generate $34 million in annual revenue per attack for hackers, attack methods are expected to become even more sophisticated.

Hackers generate $34 million in annual revenue per attack from ransomware attacks

In addition, Cisco proposed reducing Time-to-detection (TTD) as a solution to minimize corporate damage from cyberattacks. In fact, following the release of its mid-term security report in July 2015, the risk detection time was reduced by 62% from 46 hours to 17.5 hours, which was found to be effective in reducing risk and damage to corporate infrastructure.

John N. Stewart, Senior Vice President and Chief Security Officer at Cisco, stated, “Security must be based on resilience, privacy protection, and transparent trust. As the Internet of Things and digitalization transform every business, technology deployment and operations must be conducted with these security elements in mind.”


In addition, the increase in security service outsourcing by large corporations was cited as a notable change. Many companies recognized the value of security outsourcing services, including consulting, security audits, and incident response, as a solution to their shortage of security personnel, and the percentage of small and medium-sized enterprises improving their security practices by outsourcing some of these services increased from 14% in 2014 to 23% in 2015.

In addition, the key points of the 2016 Annual Security Report released by Cisco are as follows:

Changes in Server Usage: Recent data indicates that attackers are using servers such as social media platforms and WordPress for attacks. The number of WordPress domains used by cyber attackers increased by 221% between February and October 2015.
did.

Browser-based Data Leaks: Malicious browser extensions, often overlooked by corporate security departments, are a potential cause of serious data leaks and affect more than 85% of companies. If software is not updated regularly, data can be leaked through adware, malvertising (using advertising sites to distribute malware), general websites, or obituaries.

DNS Blind Spots: It has been found that approximately 92% of known malicious malware primarily utilizes DNS (Domain Name Service, a network service that resolves domain or host names into numeric IP addresses). However, because security departments and DNS experts typically work in different IT groups within a company and have limited communication, DNS is prone to becoming a security blind spot.

Potential Threats to Small and Medium-sized Enterprises: Many companies reviewed the security status of their business partners and discovered that smaller partners were not using threat defense tools and processes. For example, the number of small and medium-sized enterprises using web security decreased by more than 10% between 2014 and 2015, which can create potential risks for companies due to structural weaknesses.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.