FBI: Computer crime costs US firms $67bn

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Dealing with viruses, spyware, PC theft and other computer-related crimes costs US businesses a staggering $67.2bn (£38.2bn) a year, according to the FBI.

The FBI calculated the price tag by extrapolating results from a survey of 2,066 organisations. The survey, released on Thursday, found that 1,324 respondents, or 64 percent, suffered a financial loss from computer security incidents over a 12-month period.

The average cost per company was more than $24,000, with the total cost reaching $32m for those surveyed.

Often survey results can be skewed, because poll respondents are more likely to answer when they have experienced a problem. So, when extrapolating the survey results to estimate the national cost, the FBI reduced the estimated number of affected organisations from 64 percent to a more conservative 20 percent.

"This would be 2.8 million US organisations experiencing at least one computer security incident," according to the 2005 FBI Computer Crime Survey. "With each of these 2.8 million organisations incurring a $24,000 average loss, this would total $67.2bn per year."

By comparison, telecommunication fraud losses are about only $1bn a year, according to the US Secret Service. Also, the overall cost to Americans of identity fraud reached $52.6bn in 2004, according to Javelin Strategy & Research.

Other surveys have attempted to put a dollar amount on cybersecurity damages in the past, but the FBI believes its estimate is the most accurate because of the large number of respondents, said Bruce Verduyn, the special agent who managed the survey project.

"The data set is three or four times larger than in past surveys," he said. "It is obviously a staggering number, but that is the reality of what we see."

Responding to worms, viruses and Trojan horses was most costly, followed by computer theft, financial fraud and network intrusion, according to the survey. Respondents spent nearly $12m to deal with virus-type incidents, $3.2m on theft, $2.8m on financial fraud and $2.7m on network intrusions.

These figures do not include much of the staff, technology, time and software employed to prevent security incidents, Verduyn said. Also, losses to individuals who are victims of computer crime or victims in other countries are not included, he said.

The FBI's next fiscal year, for which budgets must be reviewed and approved, begins 1 October. Protecting the US against high technology crimes is third on the agency's list of priorities.

Defences in place
Survey respondents use a variety of security products for protection. Antivirus software is almost universally used, with 98.2 percent of respondents stating they use it. Firewalls follow in second place, with 90.7 percent, and anti-spyware and anti-spam software are each used by about three-quarters of respondents, according to the survey.

The results mean that close to one in 10 organisations does not have a hardware or software firewall. Or perhaps they don't know they have one — the Windows Firewall in Windows XP, for example. "Some are very small businesses that should have that technology, but they don't," Verduyn explained.

Biometrics and smart cards — both relatively new security technologies — were used only by 4 percent and 7 percent of survey respondents, respectively. Intrusion prevention or detection systems were used by 23 percent and VPNs by 46 percent.

Organisations were attacked despite use of security products, with nine out of 10 respondents saying they experienced a security incident. In fact, the most common attacks aligned with the most commonly used defences. Computer viruses, worms or Trojan horses plagued 84 percent of respondents, 80 percent reported spyware trouble, and 32.9 percent said attackers were probing their systems using network port scans.

Not all threats came from outside the organisation. More than 44 percent of the survey respondents reported intrusions from within the company. "Companies may be unaware of the internal potential for computer security incidents," Verduyn said. He recommends applying policies and procedures to thwart attacks from the inside.

The FBI surveyed companies in Iowa, Nebraska, New York and Texas. Companies older than three years, with more than five employees and with more than $1m in revenue were asked to participate. Survey participants were asked to provide their responses by the end of July 2005, with their answers covering the previous 12-month period.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

48 minutes ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

4 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

5 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

11 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

13 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

13 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

15 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

15 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

16 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

17 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

18 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

18 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

18 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

18 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

18 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

21 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA