At the last ISSA meeting in Des Moines, we reviewed the 2010 Data Breach Investigations Report published by the Verison RISK Team in cooperation with the US Secret Service (USSS).  This was the first year the USSS provided data for the report.  The additional information expands the scope of the report and only helps to add credibility.  Not that the report wasn't credible in the past, but Verizon's client base is going to favor those larger clients who can pay for their services.  The USSS data helps to broaden the scope.

Two things caught my eye this year.  The first was the 26% increase in breaches caused by insiders.  The addition of USSS data helps reveal what we've known for a long time.  Inside threats are very real and we must be prepared to prevent or detect them. 
The second interesting fact was that 96% of all breaches were avoidable through simple or intermediate contols.  This means it's not difficult or expensive to stop this epidemic.  Why does it continue?

I believe the biggest reason is risk management.  IT leaders are not proving their case well enough. When asking for budgets to mitigate risk we're not providing the detail or clearly communicating the risk.  I'll bet if you asked every executive involved in that 96% of breaches if they would rather have paid for the controls up front you'd get a 100% affirmation rate.

This week make a concerted effort to ensure you are clearly communicating risk to the organization.  Don't pull a "chicken little" routine but spend the time to have facts and numbers which show the entire picture to your management.  You might be surprised how quickly they respond.

I'll add some additional thoughts on the report next week.  If you are local to central Iowa and are interested in joining us at the next ISSA meeting, plesae check out our website at www.issa-desmoines.org