22 Apr 2008
The total cost of information security breaches to UK plc fell 35 per cent from some £10bn in 2006 to about £6bn in 2007, according to government-sponsored research.
The drop was thanks to improved security processes in business, says the 2008 Information Security Breaches survey by PricewaterhouseCoopers (PwC) for the Department for Business, Enterprise and Regulatory Reform (BERR).
But many firms are still wary about security as successful attacks are inflicting more and more damage on companies, said Andrew Beard of PwC.
"The seriousness of incidents is as bad as they have ever been - the worst incidents last year were the most expensive we have ever seen," he said.
The rash of new types of phishing that target senior executives - described as "whaling" - means attacks are less frequent but more damaging if succesful.
The survey found that 60 per cent fewer companies reported malware attacks than in the previous year but almost all (96 per cent) of very large companies had some kind of security incident.
The survey also says that over half of companies (54 per cent) allow their staff to access networks remotely, but the security of the access has been improved, with 94 per cent encrypting wireless networks, up from 48 per cent a year ago.
However, half (52 per cent) of firms are still not carrying out any formal risk assessment, and two thirds (67 per cent) do not do anything to prevent information leaving a company on portable media - the cause of most high profile data loss incidents.
Have your say on this article
Newsletters
Latest stories from Security Technology
Latest videos
You may also like
Security Technology jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?