Feeds

UK.plc struggles to eradicate viral infection

Malware remains top security nuisance

Internet Security Threat Report 2014

Viral infection was the biggest single cause of security incidents over the last two years, according to a DTI-backed study published on Tuesday.

The DTI's biennial Information Security Breaches survey found that viral infection caused roughly half of security incidents reported. Two in five viral infestations were said to have caused a serious impact on the organisations affected.

The study also found that viruses were more likely to cause service disruptions than other security breaches. While interruptions generally had minimal impact, a quarter of firms that blamed viral infestation for the worst security incident had major problems, such as losing important services (for example email), for more than a day.

Almost all the 1,000 UK companies that participated in the survey use anti-virus software. Although malware continues to be a problem for UK plc infection rates, the survey says it has dropped by roughly a third since two years ago.

However, on a less encouraging note, 20 per cent of firms questioned said they do not update signature files (used to protect against viruses) within a day.

Two years ago, a small number of viruses were the root of business concerns, but last year attacks featuring Trojans and botnet clients became a bigger problem. The study found that viral infections tend to take more work to resolve than other incidents. One such incident took a company 50 days to fix.

The telephone survey also found that around a quarter of UK businesses are not protecting themselves against spyware.

Meanwhile, patching practices are slowly improving. Nearly nine in ten UK businesses (88 per cent) apply new operating system security updates within a week of their release, compared with 79 per cent of businesses in 2004. Firms that install patches within a day, unsurprisingly, suffered fewer viral infections than those that wait even a week.

A consortium led by PricewaterhouseCoopers LLP managed the 2006 Information Security Breaches survey. Other lead sponsors are Microsoft, Symantec, Entrust and Clearswift. Input has also come from the National Hi-Tech Crime Unit, Royal Holloway, University of London and the Information Security Forum.

Chris Potter, the partner from management consultancy PricewaterhouseCoopers leading the survey, said: "It's very encouraging to see the progress that UK companies have made in installing anti-virus software and patching their systems. However, there's a danger of fighting yesterday's battle. Past viruses were designed to cause large amounts of indiscriminate damage typically by taking down targets' networks. Cyber-criminals now use virus infections to get in under the radar of businesses and steal confidential data."

The full results of the survey will be published at the Infosecurity Europe exhibition and conference in London, which takes place between 25 and 27 April. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The hidden costs of self-signed SSL certificates
Exploring the true TCO for self-signed SSL certificates, including a side-by-side comparison of a self-signed architecture versus working with a third-party SSL vendor.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.