Viruses cause most security breaches

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Viruses remain the biggest cyberthreat to businesses, according to a government report to be released soon which will also warn that the threat of spyware is growing, .

The Department of Trade and Industry (DTI) report into information security breaches found that approximately half of businesses said their worst security incidents over the past two years has been caused by virus infections, rather than other threats such as hacking or phishing.

The survey, which will be launched at Infosecurity Europe 2006 in London in April, showed that virus infections were also more likely to have caused serious service interruption than other incidents.

"Usually the disruption was minor, but roughly a quarter of companies questioned who reported a virus as their worst incident had major disruption, with important services such as email down for more than a day," the authors of the survey said in a statement.

The report found that the threat from spyware is also increasing. A quarter of UK businesses are not protected against the threat caused by spyware, said the report, while spyware caused one in seven of the security incidents reported.

"Of external threats, malicious software was the most significant, while the threat from spyware grew the most. Spyware was the hardest threat to detect, and the one UK businesses were least prepared for," Chris Potter, co-author of the report and partner at PricewaterhouseCoopers, told ZDNet UK.

Companies are relying too much on antivirus software, according to the report.

"It's clear that the old model of 'all I need is antivirus software on my email gateway' just doesn't cut it any more," said Potter. "Ninety-five to ninety-eight percent of businesses have antivirus software deployed, yet thirty-five percent have had virus infections in the past year."

Spyware was increasingly being used by organised criminals because it is more difficult to detect and easier to profit from, said Potter.

"Old style attacks just caused indiscriminate damage, like a plane dropping bombs. Now it tends to be a mass of guerrillas attacking organisations to take confidential information, which is much more subtle and insidious," said Potter.

Most malicious attacks involved the exploitation of weak patches, according to Potter, and most were targeted against machines running Microsoft software.

"It's clear that there are a huge number of Microsoft computers, and it's likely they are targeted more by virus writers because that will result in more infections," said Potter. "However Microsoft, through XP Service Pack 2, has made the patching process much easier. Most companies are now deploying patches within a week."

Companies could not just rely on antivirus software to prevent the threat of malware, said Potter, but needed to deploy a range of in-depth protection.

"Each discipline — updating antivirus software, installing patches, installing intrusion-prevention or intrusion-detection systems — each contributed to the likelihood of reducing infections, but none of them alone eliminated the risk. The implication is to have multi-level protection. If businesses have all three elements with a patch auditing process, that will stand you in good stead," said Potter.

The report also found that businesses need to educate their staff about computer infections and their symptoms.

"It's absolutely critical that people make sure they have antivirus software, but stuff is always going to slip through. Businesses need to educate their staff about malware, so people stay alert for the symptoms of infection like a slow machine," said Potter.

Potter said that Internet telephony and instant messaging (IM) are emerging as potential means of attack, although most threats still came through Web downloads, and worms and other Trojans spreading across networks by email.

"VoIP and IM certainly are new attack vectors. Virus writers expend most effort on established technology, but IM is a potential threat. Roughly 42 percent of UK businesses allow their employees to use IM through AOL, MSN, or Yahoo, while more than half of those have no controls over its use. This potentially opens companies to exploits further down the road, although we've seen none yet," said Potter.

Talkback

Windows virus you mean.

via Facebook 1 March, 2006 10:15
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

5 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

7 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

7 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

9 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

11 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

12 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

13 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

14 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

16 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

21 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

23 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

24 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?