{"id":30761,"date":"2019-06-10T11:09:11","date_gmt":"2019-06-10T10:09:11","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=30761"},"modified":"2019-06-11T08:29:26","modified_gmt":"2019-06-11T07:29:26","slug":"64-of-businesses-have-suffered-insider-breach-beyondtrust-reveals","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/06\/10\/64-of-businesses-have-suffered-insider-breach-beyondtrust-reveals\/","title":{"rendered":"64% of businesses have suffered insider breach, BeyondTrust reveals"},"content":{"rendered":"<p>BeyondTrust, a global leader in privileged access management, has released the <em>2019 Privileged Access Threat Report<\/em>.<\/p>\n<p>In its fourth edition, the global survey explores the visibility, control and management that IT organisations across the globe \u2013 including the United Arab Emirates (UAE) and Saudi Arabia \u2013 have over employees, contractors and third-party vendors with privileged access to their IT networks.<\/p>\n<p>According to the report, 64% believe they\u2019ve likely had either a direct or indirect breach due to misused or abused employee access in the last 12 months and 62% believe they\u2019ve had a breach due to compromised vendor access.<\/p>\n<p>Poor security hygiene by employees continues to be a challenge for most organisations. Writing down passwords, for example, was cited as a problem by 60% of organisations, while colleagues telling each other passwords was also an issue for 58% of organisations, a steady increase from 2018\u2019s statistics.<\/p>\n<p>The report also highlighted regional differences, with only 28% of Middle East businesses expressing worries about employees downloading data onto a memory stick, while 42% see this as an issue in APAC.<\/p>\n<p>Ultimately, 71% of organisations agree that they would be more secure if they restricted employee device access. However, this isn\u2019t usually realistic, let alone conducive to productivity.<\/p>\n<p>\u201cBoth internal employees and third-party vendors need privileged access to be able to do their jobs effectively, but need this access granted in a way that doesn\u2019t compromise security or impede productivity,\u201d commented Morey Haber, CTO and CISO of BeyondTrust.<\/p>\n<p>\u201cIn the face of growing threats, there has never been a greater need to implement organisation-wide strategies and solutions to manage and control privileged access in a way that fits the needs of the user.\u201d<\/p>\n<p>The businesses surveyed reported an average of 182 vendors logging in to their systems every week. At organisations with 5,000+ employees, 23% say they have more than 500 vendors logging in regularly, highlighting the sheer scope of the risk exposure.<\/p>\n<p>This year\u2019s report uncovered that trust in vendor access is now lower than trust in employee access, with only one in four (25%) saying they completely trust vendors, in comparison to 37% of employees.<\/p>\n<p>This is a stark comparison to last year\u2019s report, where 72% of businesses admitted that they have cultures that are too trusting of third parties. In an age where data breaches have immense financial and reputational implications for businesses, it\u2019s a positive step that these organisations are now assessing the level of trust they place in their third-party vendors.<\/p>\n<p>The report also delves into the threats posed by emerging technologies. The risks associated with the Internet of Things (IoT) posed a big concern for the professionals surveyed, with the visibility of logins from IoT devices revealed as the most pressing issue.<\/p>\n<p>Three quarters (76%) are confident they know how many IoT devices are accessing their systems, while four in five are confident they know how many individual logins can be attributed to these devices.<\/p>\n<p>At the same time, 57% of security decision makers perceive at least a moderate risk from Bring Your Own Device (BYOD) policies.<\/p>\n<p>The report did show that some organisations are managing these risks with a privileged access management (PAM) solution. From the research, these same organisations experience less severe security breaches and have better visibility and control than those who use manual solutions or no solution at all.<\/p>\n<p>In fact, 90% of those with fully integrated PAM tools are confident they can identify specific threats from employees with privileged access.<\/p>\n<p>\u201cAs the vendor ecosystem grows, the threat landscape evolves and users should be granted specific role-based privileges. Organisations need to accept that the way to mitigate risks is by managing privileged accounts through integrated technology and automated processes that not only save time, but also provide visibility across the environment,\u201d Haber added.<\/p>\n<p>\u201cBy implementing cybersecurity policies and solutions that also speed business efficiency, versus putting roadblocks in users\u2019 way, organisations can begin to seriously tackle the privileged access problem.\u201d<\/p>\n<figure id=\"attachment_30833\" aria-describedby=\"caption-attachment-30833\" style=\"width: 1700px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-30833 size-full\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/06\/BeyondTrust-2019-PATR-infographic.pdf.jpg\" alt=\"\" width=\"1700\" height=\"5348\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/06\/BeyondTrust-2019-PATR-infographic.pdf.jpg 1700w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/06\/BeyondTrust-2019-PATR-infographic.pdf-95x300.jpg 95w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/06\/BeyondTrust-2019-PATR-infographic.pdf-768x2416.jpg 768w\" sizes=\"auto, (max-width: 1700px) 100vw, 1700px\" \/><figcaption id=\"caption-attachment-30833\" class=\"wp-caption-text\">BeyondTrust has released its <em><strong>Privileged Access Threat Report 2019<\/strong><\/em><\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>BeyondTrust, a global leader in privileged access management, has released the 2019 Privileged Access Threat Report. In its fourth edition, the global survey explores the visibility, control and management that IT organisations across the globe \u2013 including the United Arab Emirates (UAE) and Saudi Arabia \u2013 have over employees, contractors and third-party vendors with privileged [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":30834,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,171,6617,93],"tags":[6287,961,12421,564,2978,12422,139,28,7363,6621,7454,7453,9467,12423],"class_list":["post-30761","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-infographics","category-research","category-top-stories","tag-bring-your-own-device","tag-byod","tag-cto-and-ciso-of-beyondtrust","tag-cybersecurity","tag-data-breaches","tag-employee","tag-internet-of-things","tag-iot","tag-middle-east","tag-morey-haber","tag-pam","tag-privileged-access-management","tag-saudi-arabia","tag-united-arab-emirates-uae"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/30761","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=30761"}],"version-history":[{"count":22,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/30761\/revisions"}],"predecessor-version":[{"id":30836,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/30761\/revisions\/30836"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/30834"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=30761"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=30761"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=30761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}