Feeds

UK.plc struggles to eradicate viral infection

Malware remains top security nuisance

Build a business case: developing custom apps

Viral infection was the biggest single cause of security incidents over the last two years, according to a DTI-backed study published on Tuesday.

The DTI's biennial Information Security Breaches survey found that viral infection caused roughly half of security incidents reported. Two in five viral infestations were said to have caused a serious impact on the organisations affected.

The study also found that viruses were more likely to cause service disruptions than other security breaches. While interruptions generally had minimal impact, a quarter of firms that blamed viral infestation for the worst security incident had major problems, such as losing important services (for example email), for more than a day.

Almost all the 1,000 UK companies that participated in the survey use anti-virus software. Although malware continues to be a problem for UK plc infection rates, the survey says it has dropped by roughly a third since two years ago.

However, on a less encouraging note, 20 per cent of firms questioned said they do not update signature files (used to protect against viruses) within a day.

Two years ago, a small number of viruses were the root of business concerns, but last year attacks featuring Trojans and botnet clients became a bigger problem. The study found that viral infections tend to take more work to resolve than other incidents. One such incident took a company 50 days to fix.

The telephone survey also found that around a quarter of UK businesses are not protecting themselves against spyware.

Meanwhile, patching practices are slowly improving. Nearly nine in ten UK businesses (88 per cent) apply new operating system security updates within a week of their release, compared with 79 per cent of businesses in 2004. Firms that install patches within a day, unsurprisingly, suffered fewer viral infections than those that wait even a week.

A consortium led by PricewaterhouseCoopers LLP managed the 2006 Information Security Breaches survey. Other lead sponsors are Microsoft, Symantec, Entrust and Clearswift. Input has also come from the National Hi-Tech Crime Unit, Royal Holloway, University of London and the Information Security Forum.

Chris Potter, the partner from management consultancy PricewaterhouseCoopers leading the survey, said: "It's very encouraging to see the progress that UK companies have made in installing anti-virus software and patching their systems. However, there's a danger of fighting yesterday's battle. Past viruses were designed to cause large amounts of indiscriminate damage typically by taking down targets' networks. Cyber-criminals now use virus infections to get in under the radar of businesses and steal confidential data."

The full results of the survey will be published at the Infosecurity Europe exhibition and conference in London, which takes place between 25 and 27 April. ®

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Know what Ferguson city needs right now? It's not Anonymous doxing random people
U-turn on vow to identify killer cop after fingering wrong bloke
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.