Organizations
that oversee sensitive information remain woefully unprepared to fend off
increasingly clever and sophisticated data raiders, according to a new study.
A
report issued Tuesday by Silicon Valley security software firm FireEye Inc.
Data breach victims took a median of 205 days – almost seven months – to
realize they had had been hit, giving “attackers a free rein in breached
environments far too long before being detected,” the report said, while
“run-of-the-mill cyber criminals” out to steal credit-card data are becoming
harder to distinguish from state-sponsored attackers due to advanced camouflaging
tools and tactics.
Despite
increasing awareness of cyberthreats and investments to protect sensitive data,
including personal customer information and corporate secrets, corporations
appear to be falling behind in their efforts to counter hackers. Many companies
are better prepared for fires, floods and ice storms than data breaches, which
“are more likely, and likelier to have a more significant business impact” than
other emergencies, said John Proctor, vice-president of global cybersecurity
with Montreal information technology services firm CGI Group Inc.
At
the same time, corporations increasingly realize there is little they can do to
stop data raiders from penetrating their firewalls and getting past their
anti-virus software. Leading cybersecurity providers are more focused on
containing malicious software programs that have already entered corporate
servers and constantly monitoring networks to prevent the invaders from
uploading data to anonymous cybercriminals located around the world.